<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2019-10-11" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 https://scap.nist.gov/schema/nvd/nvd-cve-feed_1.2.1.xsd">
  <entry type="CVE" name="CVE-2003-0001" seq="2003-0001" published="2003-01-17" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html">20030110 More information regarding Etherleak</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104222046632243&amp;w=2">20030110 More information regarding Etherleak</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a010603-1.txt" adv="1">A010603-1</ref>
      <ref source="MISC" url="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412115" adv="1">VU#412115</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html">http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-025.html">RHSA-2003:025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-088.html">RHSA-2003:088</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305335/30/26420/threaded">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307564/30/26270/threaded">20030117 Re: More information regarding Etherleak</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1031583">1031583</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040185">1040185</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665">oval:org.mitre.oval:def:2665</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.20"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0002" seq="2003-0002" published="2003-02-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=103417794800719&amp;w=2">20021007 CSS on Microsoft Content Management Server</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10318.php" adv="1" patch="1">mcms-manuallogin-reasontxt-xss (10318)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5922">5922</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-002">MS03-002</ref>
    </refs>
    <vuln_soft>
      <prod name="content_management_server" vendor="microsoft">
        <vers num="2001" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0003" seq="2003-0003" published="2003-02-07" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104394414713415&amp;w=2" adv="1">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104393588232166&amp;w=2" adv="1">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-03.html" adv="1" patch="1">CA-2003-03</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/610986" adv="1" patch="1">VU#610986</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6666" adv="1">6666</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-001">MS03-001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11132" adv="1">win-locator-bo(11132)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A103" adv="1">oval:org.mitre.oval:def:103</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="-" edition="sp3"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:home"/>
        <vers num="-" edition=":64-bit"/>
        <vers num="-" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0004" seq="2003-0004" published="2003-02-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104878038418534&amp;w=2">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11260.php">winxp-windows-redirector-bo(11260)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6778">6778</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-005">MS03-005</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0007" seq="2003-0007" published="2003-02-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/6667">6667</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-003">MS03-003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11133">outlook-v1-certificate-plaintext(11133)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0009" seq="2003-0009" published="2003-03-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104636383018686&amp;w=2">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-047.shtml">N-047</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11425.php" adv="1">winme-hsc-hcp-bo(11425)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/489721">VU#489721</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6966" adv="1" patch="1">6966</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-006">MS03-006</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0010" seq="2003-0010" published="2003-03-24" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html">20030319 Windows Scripting Engine issue</ref>
      <ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26">20030319 Heap Overflow in Windows Script Engine</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104812108307645&amp;w=2">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7146" adv="1" patch="1">7146</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-008">MS03-008</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A134">oval:org.mitre.oval:def:134</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A200">oval:org.mitre.oval:def:200</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A794">oval:org.mitre.oval:def:794</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A795">oval:org.mitre.oval:def:795</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0011" seq="2003-0011" published="2003-03-24" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/7145" adv="1" patch="1">7145</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-009">MS03-009</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0012" seq="2003-0012" published="2003-01-17" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104154319200399&amp;w=2">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-230">DSA-230</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10971.php" adv="1">bugzilla-mining-world-writable(10971)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6502">6502</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0013" seq="2003-0013" published="2003-01-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104154319200399&amp;w=2">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-230" adv="1" patch="1">DSA-230</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10970.php">bugzilla-htaccess-database-password(10970)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6501">6501</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0014" seq="2003-0014" published="2003-01-11" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <sols>
      <sol source="nvd">For the stable distribution this problem has been fixed in version 1.2-14.2. For the unstable distribution this problem has been fixed in version 1.2-17.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" adv="1">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</ref>
      <ref source="BID" url="http://securityfocus.org/bid/12229" adv="1" patch="1">12229</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1012847">1012847</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-633" adv="1">DSA-633</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/18823">bmv-symlink(18823)</ref>
    </refs>
    <vuln_soft>
      <prod name="bmv" vendor="bmv">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0015" seq="2003-0015" published="2003-02-07" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html">20030120 Advisory 01/2003: CVS remote vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104333092200589&amp;w=2">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104342550612736&amp;w=2">20030124 Test program for CVS double-free.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104428571204468&amp;w=2">20030202 Exploit for CVS double free() for Linux pserver</ref>
      <ref source="FREEBSD" url="http://marc.info/?l=bugtraq&amp;m=104438807203491&amp;w=2">FreeBSD-SA-03:01</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-013.html" adv="1" patch="1">RHSA-2003:013</ref>
      <ref source="MISC" url="http://security.e-matters.de/advisories/012003.html" adv="1" patch="1">http://security.e-matters.de/advisories/012003.html</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-02.html">CA-2003-02</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-032.shtml">N-032</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-233">DSA-233</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/650937" adv="1">VU#650937</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009">MDKSA-2003:009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6650">6650</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11108">cvs-doublefree-memory-corruption(11108)</ref>
    </refs>
    <vuln_soft>
      <prod name="cvs" vendor="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.1p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0016" seq="2003-0016" published="2003-02-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/03-01-24#security">http://www.apacheweek.com/issues/03-01-24#security</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/825177">VU#825177</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/979793">VU#979793</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6659">6659</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11124">apache-device-name-dos(11124)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11125">apache-device-code-execution(11125)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0017" seq="2003-0017" published="2003-02-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">http://marc.info/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0018" seq="2003-0018" published="2003-02-19" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11249.php" adv="1">linux-odirect-information-leak(11249)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014">MDKSA-2003:014</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-025.html" adv="1" patch="1">RHSA-2003:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6763">6763</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0019" seq="2003-0019" published="2003-02-19" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-044.shtml">N-044</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11276.php" adv="1" patch="1">linux-umlnet-gain-privileges(11276)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/134025">VU#134025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-056.html" adv="1" patch="1">RHSA-2003:056</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6801">6801</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="8.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0020" seq="2003-0020" published="2003-03-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="APPLE" url="http://marc.info/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11412.php" adv="1">apache-esc-seq-injection(11412)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050">MDKSA-2003:050</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-083.html">RHSA-2003:083</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9930" adv="1" patch="1">9930</ref>
      <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100109">oval:org.mitre.oval:def:100109</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A150">oval:org.mitre.oval:def:150</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4114">oval:org.mitre.oval:def:4114</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0021" seq="2003-0021" published="2003-03-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11413.php" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6936">6936</ref>
    </refs>
    <vuln_soft>
      <prod name="eterm" vendor="michael_jennings">
        <vers num="0.8.10"/>
        <vers num="0.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0022" seq="2003-0022" published="2003-03-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11413.php" adv="1">terminal-emulator-screen-dump(11413)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6938">6938</ref>
    </refs>
    <vuln_soft>
      <prod name="rxvt" vendor="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0023" seq="2003-0023" published="2003-03-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11416.php" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6947">6947</ref>
    </refs>
    <vuln_soft>
      <prod name="rxvt" vendor="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0024" seq="2003-0024" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11416.php" adv="1">terminal-emulator-menu-modification(11416)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6949">6949</ref>
    </refs>
    <vuln_soft>
      <prod name="aterm" vendor="aterm">
        <vers num="0.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0025" seq="2003-0025" published="2003-01-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104204786206563&amp;w=2">20030108 IMP 2.x SQL injection vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-229" adv="1" patch="1">DSA-229</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306268">20030108 Re: IMP 2.x SQL injection vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6559">6559</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005904">1005904</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="horde">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0026" seq="2003-0026" published="2003-01-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562">CLA-2003:562</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-01.html" adv="1" patch="1">CA-2003-01</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-031.shtml">N-031</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-231" adv="1" patch="1">DSA-231</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/284857" adv="1" patch="1">VU#284857</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007">MDKSA-2003:007</ref>
      <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html">OpenPKG-SA-2003.002</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-011.html" adv="1" patch="1">RHSA-2003:011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6627">6627</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005924">1005924</ref>
      <ref source="SUSE" url="http://www.suse.com/de/security/2003_006_dhcp.html">SuSE-SA:2003:006</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11073">dhcpd-minires-multiple-bo(11073)</ref>
    </refs>
    <vuln_soft>
      <prod name="dhcpd" vendor="isc">
        <vers num="3.0"/>
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.1" edition="rc2"/>
        <vers num="3.0.1" edition="rc3"/>
        <vers num="3.0.1" edition="rc4"/>
        <vers num="3.0.1" edition="rc5"/>
        <vers num="3.0.1" edition="rc6"/>
        <vers num="3.0.1" edition="rc7"/>
        <vers num="3.0.1" edition="rc8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0027" seq="2003-0027" published="2003-02-07" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104326556329850&amp;w=2">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104">50104</ref>
      <ref source="MISC" url="http://www.entercept.com/news/uspr/01-22-03.asp" adv="1" patch="1">http://www.entercept.com/news/uspr/01-22-03.asp</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/850785" adv="1" patch="1">VU#850785</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6665">6665</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11129">solaris-kcms-directory-traversal(11129)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A120">oval:org.mitre.oval:def:120</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A195">oval:org.mitre.oval:def:195</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2592">oval:org.mitre.oval:def:2592</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0028" seq="2003-0028" published="2003-03-25" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc">NetBSD-SA2003-008</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html">20030319 EEYE: XDR Integer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104810574423662&amp;w=2">20030319 EEYE: XDR Integer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104811415301340&amp;w=2">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104860855114117&amp;w=2">20030325 GLSA:  glibc (200303-22)</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=104878237121402&amp;w=2">2003-0014</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105362148313082&amp;w=2">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-10.html" adv="1" patch="1">CA-2003-10</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-272">DSA-272</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-282">DSA-282</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20030318.html" adv="1">AD20030318</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/516825">VU#516825</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html">ESA-20030321-010</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037">MDKSA-2003:037</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_027_glibc.html">SuSE-SA:2003:027</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-089.html">RHSA-2003:089</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315638/30/25430/threaded">20030319 RE: EEYE: XDR Integer Overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316931/30/25250/threaded">20030331 GLSA: dietlibc (200303-29)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A230">oval:org.mitre.oval:def:230</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20150122-0002/">https://security.netapp.com/advisory/ntap-20150122-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
      </prod>
      <prod name="openafs" vendor="openafs">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.4a"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.1a"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.2a"/>
        <vers num="1.2.2b"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
      </prod>
      <prod name="unicos" vendor="cray">
        <vers num="6.0"/>
        <vers num="6.0e"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="8.3"/>
        <vers num="9.0"/>
        <vers num="9.0.2.5"/>
        <vers num="9.2"/>
        <vers num="9.2.4"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="stable"/>
        <vers num="5.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod name="hp-ux_series_700" vendor="hp">
        <vers num="10.20"/>
      </prod>
      <prod name="hp-ux_series_800" vendor="hp">
        <vers num="10.20"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.20"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0030" seq="2003-0030" published="2003-03-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104758650516677&amp;w=2">20030313 Protegrity buffer overflow</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/247545" adv="1" patch="1">VU#247545</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7083" adv="1">7083</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7084" adv="1">7084</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7085" adv="1">7085</ref>
    </refs>
    <vuln_soft>
      <prod name="secure.data" vendor="protegrity">
        <vers num="2.2.3.7"/>
        <vers num="2.2.3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0031" seq="2003-0031" published="2003-01-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104162752401212&amp;w=2">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-228" adv="1" patch="1">DSA-228</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6510">6510</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006181">1006181</ref>
    </refs>
    <vuln_soft>
      <prod name="libmcrypt" vendor="mcrypt">
        <vers num="2.5.1_r4"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0032" seq="2003-0032" published="2003-01-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104162752401212&amp;w=2">20030103 Multiple libmcrypt vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-228" adv="1" patch="1">DSA-228</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10988.php" adv="1">libmcrypt-libtool-memory-leak(10988)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6512">6512</ref>
    </refs>
    <vuln_soft>
      <prod name="libmcrypt" vendor="mcrypt">
        <vers num="2.5.1_r4"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0033" seq="2003-0033" published="2003-03-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104673386226064&amp;w=2">20030303 Snort RPC Vulnerability (fwd)</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104716001503409&amp;w=2">GLSA-200303-6.1</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=105154530427824&amp;w=2">GLSA-200304-06</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref>
      <ref source="ISS" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" adv="1" patch="1">20030303 Snort RPC Preprocessing Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10956.php" adv="1" patch="1">snort-rpc-fragment-bo(10956)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/916785" adv="1">VU#916785</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html">ESA-20030307-007</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029">MDKSA-2003:029</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6963" adv="1" patch="1">6963</ref>
    </refs>
    <vuln_soft>
      <prod name="snort" vendor="snort">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0034" seq="2003-0034" published="2003-02-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6656">6656</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
    </refs>
    <vuln_soft>
      <prod name="mtink" vendor="jean-jacques_sarton">
        <vers num="0.9.32"/>
        <vers num="0.9.33"/>
        <vers num="0.9.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0035" seq="2003-0035" published="2003-02-07" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6658">6658</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
    </refs>
    <vuln_soft>
      <prod name="escputil" vendor="robert_krawitz">
        <vers num="1.15.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0036" seq="2003-0036" published="2003-02-07" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
    </refs>
    <vuln_soft>
      <prod name="ml85p" vendor="rildo_pragana">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0037" seq="2003-0037" published="2003-02-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-244" adv="1" patch="1">DSA-244</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6695">6695</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11181">noffle-multiple-bo(11181)</ref>
    </refs>
    <vuln_soft>
      <prod name="noffle" vendor="noffle">
        <vers num="1.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0038" seq="2003-0038" published="2003-02-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104342745916111">20030124 Mailman: cross-site scripting bug</ref>
      <ref source="CONFIRM" url="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt" patch="1">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-436" adv="1" patch="1">DSA-436</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6677">6677</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005987">1005987</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11152">mailman-email-variable-xss(11152)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0039" seq="2003-0039" published="2003-02-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="TURBO" url="http://cc.turbolinux.com/security/TLSA-2003-26.txt">TLSA-2003-26</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616">CLSA-2003:616</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104310927813830&amp;w=2">20030115 DoS against DHCP infrastructure with isc dhcrelay</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-245" adv="1" patch="1">DSA-245</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/149953">VU#149953</ref>
      <ref source="BUGTRAQ" url="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-034.html">RHSA-2003:034</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6628">6628</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11187">dhcp-dhcrelay-dos(11187)</ref>
    </refs>
    <vuln_soft>
      <prod name="dhcpd" vendor="isc">
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.1" edition="rc10"/>
        <vers num="3.0.1" edition="rc2"/>
        <vers num="3.0.1" edition="rc3"/>
        <vers num="3.0.1" edition="rc4"/>
        <vers num="3.0.1" edition="rc5"/>
        <vers num="3.0.1" edition="rc6"/>
        <vers num="3.0.1" edition="rc7"/>
        <vers num="3.0.1" edition="rc8"/>
        <vers num="3.0.1" edition="rc9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0040" seq="2003-0040" published="2003-02-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-247" adv="1" patch="1">DSA-247</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6738" adv="1" patch="1">6738</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11213">courierimap-authmysqllib-sql-injection(11213)</ref>
    </refs>
    <vuln_soft>
      <prod name="courier_mta" vendor="double_precision_incorporated">
        <vers num="0.37.3"/>
      </prod>
      <prod name="courier-imap" vendor="inter7">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0041" seq="2003-0041" published="2003-02-19" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html">20030128 MIT Kerberos FTP client remote shell commands execution</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021">MDKSA-2003:021</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-020.html" adv="1" patch="1">RHSA-2003:020</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos_ftp_client" vendor="mit">
        <vers num=""/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":i386"/>
        <vers num="7.0" edition=":i386"/>
        <vers num="7.1" edition=":i386"/>
        <vers num="7.2" edition=":i386"/>
        <vers num="7.2" edition=":ia64"/>
        <vers num="7.3" edition=":i386"/>
        <vers num="8.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0042" seq="2003-0042" published="2003-02-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104394568616290&amp;w=2">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-246" adv="1" patch="1">DSA-246</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6721">6721</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11194">tomcat-null-directory-listing(11194)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0043" seq="2003-0043" published="2003-02-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-246">DSA-246</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6722">6722</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11195">tomcat-webxml-read-files(11195)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0044" seq="2003-0044" published="2003-02-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-246" adv="1" patch="1">DSA-246</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6720">6720</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11196">tomcat-web-app-xss(11196)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0045" seq="2003-0045" published="2003-02-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12102">jakarta-tomcat-msdos-dos(12102)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0046" seq="2003-0046" published="2003-02-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref source="CONFIRM" url="http://www.celestialsoftware.net/telnet/beta_software.html" adv="1">http://www.celestialsoftware.net/telnet/beta_software.html</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6725">6725</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006013">1006013</ref>
    </refs>
    <vuln_soft>
      <prod name="absolutetelnet" vendor="celestial_software">
        <vers num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0047" seq="2003-0047" published="2003-02-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6726">6726</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6727">6727</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6728">6728</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006010">1006010</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006011">1006011</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006012">1006012</ref>
    </refs>
    <vuln_soft>
      <prod name="entunnel" vendor="van_dyke_technologies">
        <vers num="1.0.2" prev="1"/>
      </prod>
      <prod name="securecrt" vendor="van_dyke_technologies">
        <vers num="3.4.7"/>
        <vers num="4.0.2"/>
      </prod>
      <prod name="securefx" vendor="van_dyke_technologies">
        <vers num="2.0.4"/>
        <vers num="2.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0048" seq="2003-0048" published="2003-02-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6724">6724</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006014">1006014</ref>
    </refs>
    <vuln_soft>
      <prod name="putty" vendor="putty">
        <vers num="0.48"/>
        <vers num="0.49"/>
        <vers num="0.53"/>
        <vers num="0.53b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0049" seq="2003-0049" published="2003-03-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006107">1006107</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11333.php" adv="1">macos-afp-unauthorized-access(11333)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6860">6860</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0050" seq="2003-0050" published="2003-03-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11401.php" adv="1">quicktime-darwin-command-execution(11401)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6954">6954</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0051" seq="2003-0051" published="2003-03-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11402.php" adv="1">quicktime-darwin-path-disclosure(11402)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6956">6956</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0052" seq="2003-0052" published="2003-03-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11403.php" adv="1">quicktime-darwin-directory-disclosure(11403)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6955">6955</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0053" seq="2003-0053" published="2003-03-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11404.php" adv="1">quicktime-darwin-parsexml-xss(11404)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6958">6958</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0054" seq="2003-0054" published="2003-03-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11405.php" adv="1">quicktime-darwin-describe-xss(11405)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6960">6960</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0055" seq="2003-0055" published="2003-03-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104618904330226&amp;w=2">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11406.php" adv="1">quicktime-darwin-mp3-bo(11406)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6957">6957</ref>
    </refs>
    <vuln_soft>
      <prod name="quicktime_darwin_mp3_broadcaster" vendor="apple">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0056" seq="2003-0056" published="2003-02-19" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt">CSSA-2003-009.0</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104342864418213&amp;w=2">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104348607205691&amp;w=2">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104428624705363&amp;w=2">20030202 GLSA:  slocate</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-041.html">RHSA-2004:041</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-252" adv="1" patch="1">DSA-252</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015">MDKSA-2003:015</ref>
      <ref source="CONECTIVA" url="http://www.net-security.org/advisory.php?id=2010">CLA-2003:643</ref>
      <ref source="MISC" url="http://www.usg.org.uk/advisories/2003.001.txt" adv="1">http://www.usg.org.uk/advisories/2003.001.txt</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11369">oval:org.mitre.oval:def:11369</ref>
    </refs>
    <vuln_soft>
      <prod name="slocate" vendor="slocate">
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0057" seq="2003-0057" published="2003-02-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html">20030126 Hypermail buffer overflows</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104369136703903&amp;w=2">20030127 Hypermail buffer overflows</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-248">DSA-248</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6689">6689</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6690">6690</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11157">hypermail-mail-attachment-bo(11157)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11158">hypermail-long-hostname-bo(11158)</ref>
    </refs>
    <vuln_soft>
      <prod name="hypermail" vendor="hypermail">
        <vers num="2.0b25"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0058" seq="2003-0058" published="2003-02-19" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142">50142</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/661243" adv="1" patch="1">VU#661243</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6683" adv="1" patch="1">6683</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10099">kerberos-kdc-null-pointer-dos(10099)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1110">oval:org.mitre.oval:def:1110</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
      </prod>
      <prod name="enterprise_authentication_mechanism" vendor="sun">
        <vers num="1.0"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0059" seq="2003-0059" published="2003-02-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/684563" adv="1" patch="1">VU#684563</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6714" adv="1" patch="1">6714</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11188">kerberos-kdc-user-spoofing(11188)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0060" seq="2003-0060" published="2003-02-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/787523" adv="1" patch="1">VU#787523</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6712" adv="1" patch="1">6712</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11189">kerberos-kdc-format-string(11189)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0061" seq="2003-0061" published="2002-01-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0062" seq="2003-0062" published="2003-02-19" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104490777824360&amp;w=2">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/02.10.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/02.10.03.txt</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11282.php" adv="1">nod32-pathname-bo(11282)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6803">6803</ref>
    </refs>
    <vuln_soft>
      <prod name="nod32_antivirus" vendor="eset_software">
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0063" seq="2003-0063" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6940">6940</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0064" seq="2003-0064" published="2003-03-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/6236">HPSBUX0401-309</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6942">6942</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0065" seq="2003-0065" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6945">6945</ref>
    </refs>
    <vuln_soft>
      <prod name="uxterm" vendor="national_university_of_singapore">
        <vers num="2.3"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0066" seq="2003-0066" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003">MDKSA-2003:003</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
      <ref source="GENTOO" url="http://www.securityfocus.com/advisories/5137">200303-16</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6953">6953</ref>
    </refs>
    <vuln_soft>
      <prod name="rxvt" vendor="rxvt">
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0067" seq="2003-0067" published="2003-03-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
    </refs>
    <vuln_soft>
      <prod name="aterm" vendor="aterm">
        <vers num="0.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0068" seq="2003-0068" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-496">DSA-496</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10237">10237</ref>
    </refs>
    <vuln_soft>
      <prod name="eterm" vendor="michael_jennings">
        <vers num="0.8.10"/>
        <vers num="0.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0069" seq="2003-0069" published="2003-03-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
    </refs>
    <vuln_soft>
      <prod name="putty" vendor="putty">
        <vers num="0.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0070" seq="2003-0070" published="2003-03-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/77.html

'CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="GENTOO" url="http://seclists.org/lists/bugtraq/2003/Mar/0010.html">GLSA-200303-2</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-053.html">RHSA-2003:053</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome-terminal" vendor="gnome">
        <vers num="2.0"/>
        <vers num="2.2"/>
      </prod>
      <prod name="vte" vendor="nalin_dahyabhai">
        <vers num="0.11.21"/>
        <vers num="0.12.2"/>
        <vers num="0.14.2"/>
        <vers num="0.15.0"/>
        <vers num="0.16.14"/>
        <vers num="0.17.4"/>
        <vers num="0.20.5"/>
        <vers num="0.22.5"/>
        <vers num="0.24.3"/>
        <vers num="0.25.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0071" seq="2003-0071" published="2003-03-03" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11415.php" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6950">6950</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0072" seq="2003-0072" published="2003-04-02" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266" adv="1" patch="1">DSA-266</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7184">7184</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="1.0"/>
        <vers num="1.2.2.beta1"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
        <vers num="5-1.3" edition="alpha1"/>
        <vers num="5_1.0.6"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0073" seq="2003-0073" published="2003-02-19" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104385719107879&amp;w=2">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-303" adv="1" patch="1">DSA-303</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11199.php">mysql-mysqlchangeuser-doublefree-dos(11199)</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html">ESA-20030220-004</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013">MDKSA-2003:013</ref>
      <ref source="CONFIRM" url="http://www.mysql.com/doc/en/News-3.23.55.html" adv="1">http://www.mysql.com/doc/en/News-3.23.55.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-094.html">RHSA-2003:094</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-166.html">RHSA-2003:166</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6718">6718</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A436">oval:org.mitre.oval:def:436</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.31"/>
        <vers num="3.23.36"/>
        <vers num="3.23.41"/>
        <vers num="3.23.47"/>
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0074" seq="2003-0074" published="2003-02-19" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104385772908969&amp;w=2">20030129 Local root vuln in SuSE 8.0 plptools package</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104386699725019&amp;w=2">20030129 Re: Local root vuln in SuSE 8.0 plptools package</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11193.php">plptools-plpnsfd-format-string(11193)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6715" adv="1" patch="1">6715</ref>
    </refs>
    <vuln_soft>
      <prod name="plptools" vendor="plptools">
        <vers num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0075" seq="2003-0075" published="2003-02-19" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104428700106672&amp;w=2">20030202 Bladeenc 0.94.2 code execution</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104446346127432&amp;w=2">GLSA-200302-04</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11227.php" adv="1">bladeenc-myfseek-code-execution(11227)</ref>
      <ref source="MISC" url="http://www.pivx.com/luigi/adv/blade942-adv.txt" adv="1" patch="1">http://www.pivx.com/luigi/adv/blade942-adv.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6745" adv="1" patch="1">6745</ref>
    </refs>
    <vuln_soft>
      <prod name="bladeenc" vendor="bladeenc">
        <vers num="0.92.7"/>
        <vers num="0.93.10"/>
        <vers num="0.94.0"/>
        <vers num="0.94.1"/>
        <vers num="0.94.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0076" seq="2003-0076" published="2003-02-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" adv="1">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104437720116243&amp;w=2">20030204 GLSA:  qt-dcgui</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11246.php" adv="1">qtdcgui-directory-download-files(11246)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcgui" vendor="dcgui">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
      </prod>
      <prod name="qt-dcgui" vendor="qt-dcgui">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0077" seq="2003-0077" published="2003-03-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref>
    </refs>
    <vuln_soft>
      <prod name="hanterm-xf" vendor="hanterm">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0078" seq="2003-0078" published="2003-03-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc">NetBSD-SA2003-001</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570">CLSA-2003:570</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104567627211904&amp;w=2">20030219 OpenSSL 0.9.7a and 0.9.6i released</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104568426824439&amp;w=2">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104577183206905&amp;w=2">GLSA-200302-10</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-051.shtml">N-051</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-253" adv="1">DSA-253</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11369.php" adv="1">ssl-cbc-information-leak(11369)</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html">ESA-20030220-005</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020">MDKSA-2003:020</ref>
      <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030219.txt" adv="1" patch="1">http://www.openssl.org/news/secadv_20030219.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-062.html">RHSA-2003:062</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-063.html">RHSA-2003:063</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-205.html">RHSA-2003:205</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6884">6884</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2003/0005">2003-0005</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.1c"/>
        <vers num="0.9.2b"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.5a"/>
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="5.0"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0079" seq="2003-0079" published="2003-03-03" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11415.php" adv="1">terminal-emulator-dec-udk(11415)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6944">6944</ref>
    </refs>
    <vuln_soft>
      <prod name="hanterm-xf" vendor="hanterm">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0080" seq="2003-0080" published="2003-03-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-072.html" adv="1" patch="1">RHSA-2003:072</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7128" adv="1" patch="1">7128</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11552">gnomelokkit-forward-bypass-firewall(11552)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome-lokkit" vendor="gnome">
        <vers num="0.50_21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0081" seq="2003-0081" published="2003-03-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627">CLSA-2003:627</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref>
      <ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html">20030308 Ethereal format string bug, yet still ethereal much better than windows</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-258" adv="1" patch="1">DSA-258</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref source="MISC" url="http://www.guninski.com/etherre.html" adv="1" patch="1">http://www.guninski.com/etherre.html</ref>
      <ref source="GENTOO" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html">GLSA-200303-10</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-076.html">RHSA-2003:076</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7049" adv="1" patch="1">7049</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11497">ethereal-socks-format-string(11497)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A54">oval:org.mitre.oval:def:54</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.8.18"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0082" seq="2003-0082" published="2003-04-02" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266" adv="1" patch="1">DSA-266</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7185">7185</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A244">oval:org.mitre.oval:def:244</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2536">oval:org.mitre.oval:def:2536</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4430">oval:org.mitre.oval:def:4430</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="1.0"/>
        <vers num="1.2.2.beta1"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
        <vers num="5-1.3" edition="alpha1"/>
        <vers num="5_1.0.6"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0083" seq="2003-0083" published="2003-04-02" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" adv="1">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</ref>
      <ref source="CONFIRM" url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108024081011678&amp;w=2">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108034113406858&amp;w=2">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html" adv="1" patch="1">RHSA-2003:139</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A151">oval:org.mitre.oval:def:151</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0084" seq="2003-0084" published="2003-05-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-114.html" adv="1" patch="1">RHSA-2003:114</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-090.shtml">N-090</ref>
      <ref source="CONFIRM" url="http://www.itlab.musc.edu/webNIS/mod_auth_any.html">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-113.html">RHSA-2003:113</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7448" adv="1" patch="1">7448</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11893">modauthany-command-execution(11893)</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_auth_any" vendor="mod_auth_any">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0085" seq="2003-0085" published="2003-03-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792646416629&amp;w=2">20030317 GLSA:  samba (200303-11)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792723017768&amp;w=2">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-262" adv="1" patch="1">DSA-262</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/298233">VU#298233</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/archive/1/317145/30/25220/threaded">IMNX-2003-7+-003-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7106" adv="1" patch="1">7106</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A552">oval:org.mitre.oval:def:552</ref>
    </refs>
    <vuln_soft>
      <prod name="cifs-9000_server" vendor="hp">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
      </prod>
      <prod name="samba" vendor="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0086" seq="2003-0086" published="2003-03-31" modified="2018-10-19" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792646416629&amp;w=2">20030317 GLSA:  samba (200303-11)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-262" adv="1" patch="1">DSA-262</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7107" adv="1" patch="1">7107</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A554">oval:org.mitre.oval:def:554</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0087" seq="2003-0087" published="2003-03-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104508375107938&amp;w=2">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104508833214691&amp;w=2">20030212 libIM.a buffer overflow vulnerability</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/02.12.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/02.12.03.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6840">6840</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only">IY40307</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only">IY40317</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only">IY40320</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11309">aix-aixterm-libim-bo(11309)</ref>
    </refs>
    <vuln_soft>
      <prod name="libim" vendor="national_language_support">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0088" seq="2003-0088" published="2003-03-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a021403-1.txt" adv="1" patch="1">A021403-1</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11332.php" adv="1">macos-trublueenvironment-gain-privileges(11332)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6859">6859</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0089" seq="2003-0089" published="2003-12-15" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0038.html">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106873965001431&amp;w=2">20031113 NSFOCUS SA2003-07: HP-UX Software Distributor Buffer Overflow Vulnerability</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/6030" adv="1" patch="1">HPSBUX0311-293</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8986" adv="1" patch="1">8986</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13623">hp-sd-utilities-bo(13623)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5466">oval:org.mitre.oval:def:5466</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0090" seq="2003-0090" published="2003-12-15" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2000-0844.  Reason: This candidate is a duplicate of CVE-2000-0844.  Notes: All CVE users should reference CVE-2000-0844 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0091" seq="2003-0091" published="2003-04-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" adv="1" patch="1">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref source="MISC" url="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1">52443</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-068.shtml">N-068</ref>
      <ref source="MISC" url="http://www.nsfocus.com/english/homepage/sa2003-02.htm">http://www.nsfocus.com/english/homepage/sa2003-02.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316957/30/25250/threaded">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4383">oval:org.mitre.oval:def:4383</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0092" seq="2003-0092" published="2003-04-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" adv="1" patch="1">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1">52388</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316948/30/25250/threaded">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7240">7240</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1905">oval:org.mitre.oval:def:1905</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0093" seq="2003-0093" published="2003-03-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-033.html">RHSA-2003:033</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11324">tcpdump-radius-decoder-dos(11324)</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.4"/>
        <vers num="3.4a6"/>
        <vers num="3.5"/>
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0094" seq="2003-0094" published="2003-03-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016">MDKSA-2003:016</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6855">6855</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11318">utillinux-mcookie-cookie-predictable(11318)</ref>
    </refs>
    <vuln_soft>
      <prod name="util-linux" vendor="andries_brouwer">
        <vers num="2.11n"/>
        <vers num="2.11u"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0095" seq="2003-0095" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104549693426042&amp;w=2">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html" adv="1">CA-2003-05</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11328.php" adv="1">oracle-username-bo(11328)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953746">VU#953746</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6849">6849</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0.6"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0096" seq="2003-0096" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104549743326864&amp;w=2">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104549782327321&amp;w=2">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550346303295&amp;w=2">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html">CA-2003-05</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11325.php">oracle-bfilename-directory-bo(11325)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11326.php">oracle-tzoffset-bo(11326)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11327.php" adv="1">oracle-totimestamptz-bo(11327)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/663786">VU#663786</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/743954">VU#743954</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/840666" adv="1">VU#840666</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-bfilebo.txt">http://www.nextgenss.com/advisories/ora-bfilebo.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-tzofstbo.txt">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6847">6847</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6848">6848</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6850">6850</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0.6"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0097" seq="2003-0097" published="2003-03-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550977011668&amp;w=2">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104567042700840&amp;w=2">GLSA-200302-09</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104567137502557&amp;w=2">GLSA-200302-09.1</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11343.php" adv="1">php-cgi-sapi-access(11343)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6875">6875</ref>
      <ref source="CONFIRM" url="http://www.slackware.com/changelog/current.php?cpu=i386">http://www.slackware.com/changelog/current.php?cpu=i386</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0098" seq="2003-0098" published="2003-03-03" modified="2018-09-26" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref>
      <ref source="CONFIRM" url="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" adv="1">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</ref>
      <ref source="MISC" url="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006108" adv="1">1006108</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137900">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-277" adv="1" patch="1">DSA-277</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11334.php">apcupsd-logevent-format-string(11334)</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018" adv="1">MDKSA-2003:018</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6828" adv="1">6828</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7200" adv="1">7200</ref>
    </refs>
    <vuln_soft>
      <prod name="apcupsd" vendor="apcupsd">
        <vers num="0.3.91_5"/>
        <vers num="3.8.5"/>
        <vers num="3.10.0"/>
        <vers num="3.10.1"/>
        <vers num="3.10.2"/>
        <vers num="3.10.3"/>
        <vers num="3.10.4"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0099" seq="2003-0099" published="2003-03-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006108">1006108</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137892">http://sourceforge.net/project/shownotes.php?release_id=137892</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137900" adv="1">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-277" adv="1" patch="1">DSA-277</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11491.php" adv="1">apcupsd-vsprintf-multiple-bo(11491)</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7200">7200</ref>
    </refs>
    <vuln_soft>
      <prod name="apcupsd" vendor="apc">
        <vers num="3.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0100" seq="2003-0100" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104576100719090&amp;w=2">20030220 Cisco IOS OSPF exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104587206702715&amp;w=2">20030221 Re: Cisco IOS OSPF exploit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11373.php" adv="1">cisco-ios-ospf-bo(11373)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6895">6895</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.1"/>
        <vers num="11.1(7)aa"/>
        <vers num="11.1(7)ca"/>
        <vers num="11.1(9)ia"/>
        <vers num="11.1(13)"/>
        <vers num="11.1(13)aa"/>
        <vers num="11.1(13)ca"/>
        <vers num="11.1(13)ia"/>
        <vers num="11.1(15)aa"/>
        <vers num="11.1(15)ca"/>
        <vers num="11.1(15)ia"/>
        <vers num="11.1(16)aa"/>
        <vers num="11.1(16)ia"/>
        <vers num="11.1(17)cc"/>
        <vers num="11.1(17)ct"/>
        <vers num="11.1(20)aa4"/>
        <vers num="11.1(24a)"/>
        <vers num="11.1(24b)"/>
        <vers num="11.1(28a)ct"/>
        <vers num="11.1(28a)ia"/>
        <vers num="11.1(36)ca2"/>
        <vers num="11.1(36)cc2"/>
        <vers num="11.1(36)cc4"/>
        <vers num="11.1aa"/>
        <vers num="11.1ca"/>
        <vers num="11.1cc"/>
        <vers num="11.1ct"/>
        <vers num="11.1ia"/>
        <vers num="11.2"/>
        <vers num="11.2(4)"/>
        <vers num="11.2(4)f"/>
        <vers num="11.2(4)f1"/>
        <vers num="11.2(4)xa"/>
        <vers num="11.2(4)xaf"/>
        <vers num="11.2(8)p"/>
        <vers num="11.2(8)sa1"/>
        <vers num="11.2(8)sa3"/>
        <vers num="11.2(8)sa5"/>
        <vers num="11.2(8.9)sa6"/>
        <vers num="11.2(9)p"/>
        <vers num="11.2(9)xa"/>
        <vers num="11.2(10)bc"/>
        <vers num="11.2(11b)t2"/>
        <vers num="11.2(17)"/>
        <vers num="11.2(19)gs0.2"/>
        <vers num="11.2(19a)gs6"/>
        <vers num="11.2(23a)bc1"/>
        <vers num="11.2(26)p2"/>
        <vers num="11.2(26a)"/>
        <vers num="11.2(26b)"/>
        <vers num="11.2bc"/>
        <vers num="11.2f"/>
        <vers num="11.2gs"/>
        <vers num="11.2p"/>
        <vers num="11.2sa"/>
        <vers num="11.2wa3"/>
        <vers num="11.2wa4"/>
        <vers num="11.2xa"/>
        <vers num="11.3"/>
        <vers num="11.3(1)ed"/>
        <vers num="11.3(1)t"/>
        <vers num="11.3(2)xa"/>
        <vers num="11.3(7)db1"/>
        <vers num="11.3(8)db2"/>
        <vers num="11.3(11)b"/>
        <vers num="11.3(11b)"/>
        <vers num="11.3(11b)t2"/>
        <vers num="11.3(11c)"/>
        <vers num="11.3aa"/>
        <vers num="11.3da"/>
        <vers num="11.3db"/>
        <vers num="11.3ha"/>
        <vers num="11.3ma"/>
        <vers num="11.3na"/>
        <vers num="11.3t"/>
        <vers num="11.3wa4"/>
        <vers num="11.3xa"/>
        <vers num="12.0"/>
        <vers num="12.0(1)"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xe"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(2b)"/>
        <vers num="12.0(3)"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(3d)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(4)xe"/>
        <vers num="12.0(4)xe1"/>
        <vers num="12.0(4)xm"/>
        <vers num="12.0(4)xm1"/>
        <vers num="12.0(5)t"/>
        <vers num="12.0(5)t1"/>
        <vers num="12.0(5)wc"/>
        <vers num="12.0(5)wc2"/>
        <vers num="12.0(5)wc2b"/>
        <vers num="12.0(5)wc3"/>
        <vers num="12.0(5)wc3b"/>
        <vers num="12.0(5)wx"/>
        <vers num="12.0(5)xe"/>
        <vers num="12.0(5)xk"/>
        <vers num="12.0(5)xk2"/>
        <vers num="12.0(5)xn"/>
        <vers num="12.0(5)xn1"/>
        <vers num="12.0(5)xs"/>
        <vers num="12.0(5)xu"/>
        <vers num="12.0(5)yb4"/>
        <vers num="12.0(5.1)xp"/>
        <vers num="12.0(5.2)xu"/>
        <vers num="12.0(5.3)wc1"/>
        <vers num="12.0(5.4)wc1"/>
        <vers num="12.0(6b)"/>
        <vers num="12.0(7)db2"/>
        <vers num="12.0(7)dc1"/>
        <vers num="12.0(7)s1"/>
        <vers num="12.0(7)sc"/>
        <vers num="12.0(7)t"/>
        <vers num="12.0(7)t2"/>
        <vers num="12.0(7)wx5(15a)"/>
        <vers num="12.0(7)xe"/>
        <vers num="12.0(7)xe2"/>
        <vers num="12.0(7)xf"/>
        <vers num="12.0(7)xf1"/>
        <vers num="12.0(7)xk"/>
        <vers num="12.0(7)xk3"/>
        <vers num="12.0(7)xv"/>
        <vers num="12.0(7.4)s"/>
        <vers num="12.0(7a)"/>
        <vers num="12.0(8)"/>
        <vers num="12.0(8)s1"/>
        <vers num="12.0(8.0.2)s"/>
        <vers num="12.0(8.3)sc"/>
        <vers num="12.0(8a)"/>
        <vers num="12.0(9)"/>
        <vers num="12.0(9)s"/>
        <vers num="12.0(9)s8"/>
        <vers num="12.0(9a)"/>
        <vers num="12.0(10)s7"/>
        <vers num="12.0(10)w5"/>
        <vers num="12.0(10)w5(18f)"/>
        <vers num="12.0(10)w5(18g)"/>
        <vers num="12.0(10a)"/>
        <vers num="12.0(11)s6"/>
        <vers num="12.0(11)st4"/>
        <vers num="12.0(11a)"/>
        <vers num="12.0(12)s3"/>
        <vers num="12.0(12a)"/>
        <vers num="12.0(13)s6"/>
        <vers num="12.0(13)w5(19c)"/>
        <vers num="12.0(13)wt6(1)"/>
        <vers num="12.0(13a)"/>
        <vers num="12.0(14)s7"/>
        <vers num="12.0(14)st"/>
        <vers num="12.0(14)st3"/>
        <vers num="12.0(14)w5(20)"/>
        <vers num="12.0(14a)"/>
        <vers num="12.0(15)s3"/>
        <vers num="12.0(15)s6"/>
        <vers num="12.0(15a)"/>
        <vers num="12.0(16)s8"/>
        <vers num="12.0(16)sc3"/>
        <vers num="12.0(16)st1"/>
        <vers num="12.0(16)w5(21)"/>
        <vers num="12.0(16.06)s"/>
        <vers num="12.0(16a)"/>
        <vers num="12.0(17)"/>
        <vers num="12.0(17)s"/>
        <vers num="12.0(17)s4"/>
        <vers num="12.0(17)sl2"/>
        <vers num="12.0(17)sl6"/>
        <vers num="12.0(17)st1"/>
        <vers num="12.0(17)st5"/>
        <vers num="12.0(17a)"/>
        <vers num="12.0(18)s"/>
        <vers num="12.0(18)s5"/>
        <vers num="12.0(18)st1"/>
        <vers num="12.0(18)w5(22b)"/>
        <vers num="12.0(18b)"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0wx"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0101" seq="2003-0101" published="2003-03-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I">20030602-01-I</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html">HPSBUX0303-250</ref>
      <ref source="ENGARDE" url="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html">ESA-20030225-006</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610245624895&amp;w=2">20030224 Webmin 1.050 - 1.060 remote exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610300325629&amp;w=2">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610336226274&amp;w=2">20030224 GLSA:  usermin (200302-14)</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=webmin-announce&amp;m=104587858408101&amp;w=2">http://marc.info/?l=webmin-announce&amp;m=104587858408101&amp;w=2</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-058.shtml">N-058</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-319">DSA-319</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11390.php" adv="1">webmin-usermin-root-access(11390)</ref>
      <ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/62_e.html">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</ref>
      <ref source="CONFIRM" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025">MDKSA-2003:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6915">6915</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006160">1006160</ref>
    </refs>
    <vuln_soft>
      <prod name="guardian_digital_webtool" vendor="engardelinux">
        <vers num="1.2"/>
      </prod>
      <prod name="usermin" vendor="usermin">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.91"/>
        <vers num="0.92"/>
        <vers num="0.93"/>
        <vers num="0.94"/>
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.97"/>
        <vers num="0.98"/>
        <vers num="0.99"/>
      </prod>
      <prod name="webmin" vendor="webmin">
        <vers num="1.0.50"/>
        <vers num="1.0.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0102" seq="2003-0102" published="2003-03-18" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc">NetBSD-SA2003-003</ref>
      <ref source="IMMUNIX" url="http://lwn.net/Alerts/34908/">IMNX-2003-7+-012-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104680706201721&amp;w=2">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-260">DSA-260</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/03.04.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/03.04.03.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/611865">VU#611865</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030">MDKSA-2003:030</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_017_file.html">SuSE-SA:2003:017</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-086.html">RHSA-2003:086</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-087.html">RHSA-2003:087</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7008" adv="1" patch="1">7008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11469">file-afctr-read-bo(11469)</ref>
    </refs>
    <vuln_soft>
      <prod name="file" vendor="file">
        <vers num="3.28"/>
        <vers num="3.30"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="3.37"/>
        <vers num="3.39"/>
        <vers num="3.40"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0103" seq="2003-0103" published="2003-03-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11421.php">nokia-6210-vcard-dos(11421)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6952" adv="1">6952</ref>
    </refs>
    <vuln_soft>
      <prod name="6210_handset" vendor="nokia">
        <vers num="5.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0104" seq="2003-0104" published="2003-03-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" adv="1" patch="1">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10962.php" adv="1" patch="1">peoplesoft-schedulertransfer-create-files(10962)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7053" adv="1" patch="1">7053</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0105" seq="2003-0105" published="2004-09-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109215441332682&amp;w=2">20040810 Corsaire Security Advisory - Port80 Software ServerMask inconsistencies</ref>
      <ref source="MISC" url="http://www.corsaire.com/advisories/c030224-001.txt" adv="1">http://www.corsaire.com/advisories/c030224-001.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16947">servermask-header-obtain-info(16947)</ref>
    </refs>
    <vuln_soft>
      <prod name="servermask" vendor="port80_software">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0106" seq="2003-0106" published="2003-04-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104869513822233&amp;w=2">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104868285106289&amp;w=2">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
      <ref source="CONFIRM" url="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" adv="1" patch="1">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7196" adv="1">7196</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_firewall" vendor="symantec">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0107" seq="2003-0107" published="2003-03-07" modified="2017-01-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt">CSSA-2003-011.0</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc">NetBSD-SA2003-004</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619">CLSA-2003:619</ref>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN78689801/index.html">JVN#78689801</ref>
      <ref source="JVNDB" url="http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000066.html">JVNDB-2015-000066</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610337726297&amp;w=2">20030223 poc zlib sploit just for fun :)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610536129508&amp;w=2">20030224 Re: buffer overrun in zlib 1.1.4</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104620610427210&amp;w=2">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104887247624907&amp;w=2">GLSA-200303-25</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/312869">20030222 buffer overrun in zlib 1.1.4</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405">57405</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11381.php" adv="1">zlib-gzprintf-bo(11381)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/142121">VU#142121</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033">MDKSA-2003:033</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-079.html">RHSA-2003:079</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-081.html">RHSA-2003:081</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6913">6913</ref>
    </refs>
    <vuln_soft>
      <prod name="zlib" vendor="gnu">
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0108" seq="2003-0108" published="2003-03-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629">CLA-2003:629</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104637420104189&amp;w=2">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104678787109030&amp;w=2">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-255" adv="1" patch="1">DSA-255</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/02.27.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/02.27.03.txt</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11434.php" adv="1">tcpdump-isakmp-dos(11434)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html">SuSE-SA:2003:0015</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-085.html">RHSA-2003:085</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6974" adv="1" patch="1">6974</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0109" seq="2003-0109" published="2003-03-31" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104826476427372&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104861839130254&amp;w=2">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104869293619064&amp;w=2">20030326 WebDAV exploit: using wide character decoder scheme</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104887148323552&amp;w=2">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105768156625699&amp;w=2">20030708 WDAV exploit without netcat and with pretty magic number</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104826785731151&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
      <ref source="CONFIRM" url="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q815021">Q815021</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-09.html" adv="1" patch="1">CA-2003-09</ref>
      <ref source="ISS" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" adv="1" patch="1">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11533.php" adv="1" patch="1">http-webdav-long-request(11533)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/117394">VU#117394</ref>
      <ref source="MISC" url="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7116" adv="1" patch="1">7116</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-007">MS03-007</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A109">oval:org.mitre.oval:def:109</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0110" seq="2003-0110" published="2003-05-05" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104994487012027&amp;w=2">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/04.09.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/04.09.03.txt</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-012">MS03-012</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A406">oval:org.mitre.oval:def:406</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000" edition="fp1"/>
        <vers num="2000" edition="sp1"/>
      </prod>
      <prod name="proxy_server" vendor="microsoft">
        <vers num="2.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0111" seq="2003-0111" published="2003-05-05" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11751.php" adv="1" patch="1">msvm-bytecode-improper-validation(11751)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/447569" adv="1" patch="1">VU#447569</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-011">MS03-011</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A136">oval:org.mitre.oval:def:136</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_machine" vendor="microsoft">
        <vers num="3802"/>
        <vers num="3805"/>
        <vers num="3809"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0112" seq="2003-0112" published="2003-05-12" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/446338">VU#446338</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7370" adv="1" patch="1">7370</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-013">MS03-013</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11803">win-kernel-lpcrequestwaitreplyport-bo(11803)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1264">oval:org.mitre.oval:def:1264</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A142">oval:org.mitre.oval:def:142</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2022">oval:org.mitre.oval:def:2022</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2265">oval:org.mitre.oval:def:2265</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A262">oval:org.mitre.oval:def:262</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3145">oval:org.mitre.oval:def:3145</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A779">oval:org.mitre.oval:def:779</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0113" seq="2003-0113" published="2003-05-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105138417416900&amp;w=2">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105718285107246&amp;w=2">20030701 URLMON.DLL buffer overflow - technical details</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/169753">VU#169753</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015">MS03-015</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A926">oval:org.mitre.oval:def:926</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0114" seq="2003-0114" published="2003-05-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104429340817718&amp;w=2">20030203 internet explorer local file reading</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015">MS03-015</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A963">oval:org.mitre.oval:def:963</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0115" seq="2003-0115" published="2003-05-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11848.php" adv="1">ie-improper-thirdparty-rendering(11848)</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015">MS03-015</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0116" seq="2003-0116" published="2003-05-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/244729">VU#244729</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/301945">20021203 Poisonous Style for Dialog window turns the zone off.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6306" adv="1" patch="1">6306</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015">MS03-015</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0117" seq="2003-0117" published="2003-05-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216866132289&amp;w=2">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-016">MS03-016</ref>
    </refs>
    <vuln_soft>
      <prod name="biztalk_server" vendor="microsoft">
        <vers num="2002" edition=":developer"/>
        <vers num="2002" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0118" seq="2003-0118" published="2003-05-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216839231951&amp;w=2">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-016">MS03-016</ref>
    </refs>
    <vuln_soft>
      <prod name="biztalk_server" vendor="microsoft">
        <vers num="2000" edition=":developer"/>
        <vers num="2000" edition=":enterprise"/>
        <vers num="2000" edition=":standard"/>
        <vers num="2000" edition="sp1a:developer"/>
        <vers num="2000" edition="sp1a:enterprise"/>
        <vers num="2000" edition="sp1a:standard"/>
        <vers num="2000" edition="sp2:developer"/>
        <vers num="2000" edition="sp2:enterprise"/>
        <vers num="2000" edition="sp2:standard"/>
        <vers num="2002" edition=":developer"/>
        <vers num="2002" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0119" seq="2003-0119" published="2004-02-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/624713" adv="1" patch="1">VU#624713</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7264" adv="1" patch="1">7264</ref>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/4699c03b46f2d4f68525678c006d45ae/85256a3400529a8685256cde0008ddde?OpenDocument">MSS-OAR-E01-2003:0245.1</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0120" seq="2003-0120" published="2003-03-07" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-256" adv="1" patch="1">DSA-256</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11439.php">mhc-adb2mhc-insecure-tmp(11439)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6978">6978</ref>
    </refs>
    <vuln_soft>
      <prod name="mhc-utils" vendor="mhc-utils">
        <vers num="0.25_snap2001-06-25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0121" seq="2003-0121" published="2003-03-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104716030503607&amp;w=2">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316311">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7044" adv="1" patch="1">7044</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0122" seq="2003-0122" published="2003-03-18" modified="2017-12-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html" adv="1">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104757319829443&amp;w=2" adv="1">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1">CA-2003-11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433489" adv="1">VU#433489</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0010.html">http://www.rapid7.com/advisories/R7-0010.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7037" adv="1" patch="1">7037</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11526" adv="1">lotus-nrpc-bo(11526)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino" vendor="ibm">
        <vers num="4.6.1"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8"/>
        <vers num="5.0.8a"/>
        <vers num="5.0.9"/>
        <vers num="5.0.9a"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
      </prod>
      <prod name="lotus_notes_client" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.9a"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0123" seq="2003-0123" published="2003-03-18" modified="2017-11-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104757545500368&amp;w=2" adv="1">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1">CA-2003-11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/411489" adv="1">VU#411489</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0011.html">http://www.rapid7.com/advisories/R7-0011.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7038" adv="1">7038</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" adv="1" patch="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11525" adv="1">lotus-web-retriever-bo(11525)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino" vendor="ibm">
        <vers num="4.6.1"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8"/>
        <vers num="5.0.8a"/>
        <vers num="5.0.9"/>
        <vers num="5.0.9a"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
      </prod>
      <prod name="lotus_notes_client" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.9a"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0124" seq="2003-0124" published="2003-03-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620">CLSA-2003:620</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104740927915154&amp;w=2">20030311 Vulnerability in man &lt; 1.5l</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104802285112752&amp;w=2">GLSA-200303-13</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-133.html">RHSA-2003:133</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-134.html">RHSA-2003:134</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7066" adv="1" patch="1">7066</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11512">man-myxsprintf-code-execution(11512)</ref>
    </refs>
    <vuln_soft>
      <prod name="man" vendor="andries_brouwer">
        <vers num="1.5h1"/>
        <vers num="1.5i"/>
        <vers num="1.5i2"/>
        <vers num="1.5j"/>
        <vers num="1.5k"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0125" seq="2003-0125" published="2003-03-18" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" adv="1">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</ref>
      <ref source="MISC" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" adv="1" patch="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7067">7067</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11514">routefinder-vpn-options-bo(11514)</ref>
    </refs>
    <vuln_soft>
      <prod name="routefinder_550_vpn" vendor="multitech">
        <vers num="4.63" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0126" seq="2003-0126" published="2003-03-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" adv="1" patch="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="routefinder_550_vpn" vendor="multitech">
        <vers num="4.63" prev="1"/>
        <vers num="4.64_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0127" seq="2003-0127" published="2003-03-31" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt">CSSA-2003-020.0</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html">20030317 Fwd: Ptrace hole / Linux 2.2.25</ref>
      <ref source="ENGARDE" url="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-088.html">RHSA-2003:088</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-098.html" adv="1" patch="1">RHSA-2003:098</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200303-17.xml">GLSA-200303-17</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-270">DSA-270</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-276">DSA-276</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/628849" adv="1">VU#628849</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038">MDKSA-2003:038</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039">MDKSA-2003:039</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-103.html">RHSA-2003:103</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-145.html">RHSA-2003:145</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254">oval:org.mitre.oval:def:254</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0128" seq="2003-0128" published="2003-03-24" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2">20030321 GLSA:  evolution (200303-18)</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7117" adv="1" patch="1">7117</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A107">oval:org.mitre.oval:def:107</ref>
    </refs>
    <vuln_soft>
      <prod name="evolution" vendor="ximian">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0129" seq="2003-0129" published="2003-03-24" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2">20030321 GLSA:  evolution (200303-18)</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7118" adv="1" patch="1">7118</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A108">oval:org.mitre.oval:def:108</ref>
    </refs>
    <vuln_soft>
      <prod name="evolution" vendor="ximian">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0130" seq="2003-0130" published="2003-03-24" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104826470527308&amp;w=2">20030321 GLSA:  evolution (200303-18)</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7119" adv="1" patch="1">7119</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A111">oval:org.mitre.oval:def:111</ref>
    </refs>
    <vuln_soft>
      <prod name="evolution" vendor="ximian">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0131" seq="2003-0131" published="2003-03-24" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc">NetBSD-SA2003-007</ref>
      <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref>
      <ref source="MISC" url="http://eprint.iacr.org/2003/052/" adv="1">http://eprint.iacr.org/2003/052/</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104811162730834&amp;w=2">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104852637112330&amp;w=2">20030324 GLSA:  openssl (200303-20)</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=104878215721135&amp;w=2">2003-0013</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml">GLSA-200303-20</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/888801" adv="1">VU#888801</ref>
      <ref source="MISC" url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035">MDKSA-2003:035</ref>
      <ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html">OpenPKG-SA-2003.026</ref>
      <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030319.txt">http://www.openssl.org/news/secadv_20030319.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/archive/1/316577/30/25310/threaded">IMNX-2003-7+-001-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7148" adv="1" patch="1">7148</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11586">ssl-premaster-information-leak(11586)</ref>
      <ref source="SUSE" url="https://lists.opensuse.org/opensuse-security-announce/2003-04/msg00005.html">SuSE-SA:2003:024</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A461">oval:org.mitre.oval:def:461</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0132" seq="2003-0132" published="2003-04-11" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104931360606484&amp;w=2">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104982175321731&amp;w=2">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104994239010517&amp;w=2">20030409 GLSA:  apache (200304-01)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104994309010974&amp;w=2">20030408 Exploit Code Released for Apache 2.x Memory Leak</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105001663120995&amp;w=2">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105013378320711&amp;w=2">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</ref>
      <ref source="MISC" url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/04.08.03.txt">http://www.idefense.com/advisory/04.08.03.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206537">VU#206537</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1233">ADV-2009-1233</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A156">oval:org.mitre.oval:def:156</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.9"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0133" seq="2003-0133" published="2003-05-05" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737">CLA-2003:737</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046">MDKSA-2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-126.html" adv="1" patch="1">RHSA-2003:126</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A138">oval:org.mitre.oval:def:138</ref>
    </refs>
    <vuln_soft>
      <prod name="gtkhtml" vendor="gnome">
        <vers num="1.1.9"/>
        <vers num="1.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0134" seq="2003-0134" published="2003-04-11" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35" patch="1">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104931360606484&amp;w=2">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.9"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0135" seq="2003-0135" published="2003-04-11" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-084.html" adv="1" patch="1">RHSA-2003:084</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7253" adv="1" patch="1">7253</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A634">oval:org.mitre.oval:def:634</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0136" seq="2003-0136" published="2003-05-05" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-285" adv="1" patch="1">DSA-285</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-142.html" adv="1" patch="1">RHSA-2003:142</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A423">oval:org.mitre.oval:def:423</ref>
    </refs>
    <vuln_soft>
      <prod name="lprng" vendor="astart_technologies">
        <vers num="3.7.4"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10.1"/>
        <vers num="3.8.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0137" seq="2003-0137" published="2003-03-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a031303-2.txt" adv="1">A031303-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sgsn_dx200" vendor="nokia">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0138" seq="2003-0138" published="2003-03-24" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104791775804776&amp;w=2">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266" adv="1" patch="1">DSA-266</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-269">DSA-269</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/623217" adv="1" patch="1">VU#623217</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7113">7113</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A248">oval:org.mitre.oval:def:248</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0139" seq="2003-0139" published="2003-03-24" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104791775804776&amp;w=2">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/442569" adv="1" patch="1">VU#442569</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317130/30/25250/threaded">20030330 GLSA: openafs (200303-26)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A250">oval:org.mitre.oval:def:250</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0140" seq="2003-0140" published="2003-03-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626">CLA-2003:626</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630">CLA-2003:630</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104817995421439&amp;w=2">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104818814931378&amp;w=2">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104852190605988&amp;w=2">20030322 GLSA:  mutt (200303-19)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105171507629573&amp;w=2">20030430 GLSA:  balsa (200304-10)</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-268">DSA-268</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml">GLSA-200303-19</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041">MDKSA-2003:041</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_020_mutt.html">SuSE-SA:2003:020</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-109.html">RHSA-2003:109</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315679" adv="1">20030319 mutt-1.4.1 fixes a buffer overflow.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7120" adv="1" patch="1">7120</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11583">mutt-folder-name-bo(11583)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2">oval:org.mitre.oval:def:2</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A434">oval:org.mitre.oval:def:434</ref>
    </refs>
    <vuln_soft>
      <prod name="mutt" vendor="mutt">
        <vers num="1.3.12"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.22"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.27"/>
        <vers num="1.4.0"/>
        <vers num="1.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0141" seq="2003-0141" published="2003-04-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104887465427579&amp;w=2">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/705761" adv="1">VU#705761</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7177" adv="1" patch="1">7177</ref>
    </refs>
    <vuln_soft>
      <prod name="realone_enterprise_desktop" vendor="realnetworks">
        <vers num="6.0.11.774"/>
      </prod>
      <prod name="realone_player" vendor="realnetworks">
        <vers num="2.0"/>
        <vers num="6.0.10.505" edition="gold"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
        <vers num="9.0.0.288"/>
        <vers num="9.0.0.297"/>
      </prod>
      <prod name="realplayer" vendor="realnetworks">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0142" seq="2003-0142" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/689835">VU#689835</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/328224" adv="1">20030708 Adobe Acrobat and PDF security: no improvements for 2 years</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0143" seq="2003-0143" published="2003-03-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104739841223916&amp;w=2">20030310 QPopper 4.0.x buffer overflow vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104748775900481&amp;w=2">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104768137314397&amp;w=2">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104792541215354&amp;w=2">GLSA-200303-12</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-259" adv="1" patch="1">DSA-259</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html">SuSE-SA:2003:018</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7058" adv="1" patch="1">7058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11516">qpopper-popmsg-macroname-bo(11516)</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0144" seq="2003-0144" published="2003-03-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P">20030406-02-P</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104690434504429&amp;w=2">20030305 potential buffer overflow in lprm (fwd)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104714441925019&amp;w=2">20030308 OpenBSD lprm(1) exploit</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-267">DSA-267</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-275">DSA-275</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059">MDKSA-2003:059</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_014_lprold.html">SuSE-SA:2003:0014</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7025" adv="1" patch="1">7025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11473">lprm-bo(11473)</ref>
    </refs>
    <vuln_soft>
      <prod name="lprold" vendor="lprold">
        <vers num="3.0.48"/>
      </prod>
      <prod name="lpr" vendor="bsd">
        <vers num="0.48"/>
        <vers num="2000-05-07"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0145" seq="2003-0145" published="2003-03-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-151.html">RHSA-2003:151</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
      <ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt" adv="1">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11857">tcpdump-radius-attribute-dos(11857)</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0146" seq="2003-0146" published="2003-03-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656">CLSA-2003:656</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104644687816522&amp;w=2">20030228 NetPBM, multiple vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-263" adv="1" patch="1">DSA-263</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/630433">VU#630433</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-060.html">RHSA-2003:060</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6979">6979</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11463">netpbm-multiple-bo(11463)</ref>
    </refs>
    <vuln_soft>
      <prod name="netpbm" vendor="netpbm">
        <vers num="9.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0147" seq="2003-0147" published="2003-03-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" adv="1">20030313 OpenSSL Private Key Disclosure</ref>
      <ref source="MISC" url="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104766550528628&amp;w=2">20030313 Vulnerability in OpenSSL</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792570615648&amp;w=2">20030317 [ADVISORY] Timing Attack on OpenSSL</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104819602408063&amp;w=2">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104829040921835&amp;w=2">GLSA-200303-15</ref>
      <ref source="GENTOO" url="http://marc.info/?l=bugtraq&amp;m=104861762028637&amp;w=2">GLSA-200303-24</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml">GLSA-200303-23</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/997481" adv="1">VU#997481</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035">MDKSA-2003:035</ref>
      <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html">OpenPKG-SA-2003.019</ref>
      <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030317.txt">http://www.openssl.org/news/secadv_20030317.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/archive/1/316577/30/25310/threaded">IMNX-2003-7+-001-01</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A466">oval:org.mitre.oval:def:466</ref>
    </refs>
    <vuln_soft>
      <prod name="openpkg" vendor="openpkg">
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
      </prod>
      <prod name="stunnel" vendor="stunnel">
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="4.02"/>
        <vers num="4.03"/>
        <vers num="4.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0148" seq="2003-0148" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" adv="1" patch="1">A073103-1</ref>
      <ref source="CONFIRM" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" adv="1" patch="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="epolicy_orchestrator" vendor="mcafee">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0149" seq="2003-0149" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a073103-1.txt" adv="1" patch="1">A073103-1</ref>
      <ref source="CONFIRM" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" adv="1" patch="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="epolicy_orchestrator" vendor="mcafee">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0150" seq="2003-0150" published="2003-03-24" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104715840202315&amp;w=2">20030308 MySQL_user_can_be_changed_to_root?</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104739810523433&amp;w=2">20030310 Re: MySQL user can be changed to root</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104800948128630&amp;w=2">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104802285012750&amp;w=2">20030318 GLSA:  mysql (200303-14)</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-094.html">RHSA-2003:094</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-303">DSA-303</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203897">VU#203897</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html">ESA-20030324-012</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057">MDKSA-2003:057</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7052" adv="1" patch="1">7052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11510">mysql-datadir-root-privileges(11510)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442">oval:org.mitre.oval:def:442</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.53a"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
        <vers num="3.23.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0151" seq="2003-0151" published="2003-03-24" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792477914620&amp;w=2">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104792544515384&amp;w=2">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</ref>
      <ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-011-en.txt">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7122">7122</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7124">7124</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="6.0" edition=":express"/>
        <vers num="6.0" edition="sp1:express"/>
        <vers num="6.0" edition="sp2:express"/>
        <vers num="6.1" edition=":express"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0152" seq="2003-0152" published="2003-04-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-265" adv="1" patch="1">DSA-265</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7162" adv="1" patch="1">7162</ref>
    </refs>
    <vuln_soft>
      <prod name="bonsai" vendor="mozilla">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0153" seq="2003-0153" published="2003-04-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=187230">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=102980129101054&amp;w=2">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-265" adv="1" patch="1">DSA-265</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5517">5517</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/9921">bonsai-path-disclosure(9921)</ref>
    </refs>
    <vuln_soft>
      <prod name="bonsai" vendor="mozilla">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0154" seq="2003-0154" published="2003-04-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</ref>
      <ref source="MISC" url="http://bugzilla.mozilla.org/show_bug.cgi?id=146244">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=163573">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=102980129101054&amp;w=2">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-265" adv="1" patch="1">DSA-265</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/9920.php">bonsai-error-message-xss(9920)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5516" adv="1" patch="1">5516</ref>
    </refs>
    <vuln_soft>
      <prod name="bonsai" vendor="mozilla">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0155" seq="2003-0155" published="2003-04-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-265" adv="1" patch="1">DSA-265</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7163" adv="1" patch="1">7163</ref>
    </refs>
    <vuln_soft>
      <prod name="bonsai" vendor="mozilla">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0156" seq="2003-0156" published="2003-03-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104739747222492&amp;w=2">20030311 Cross-Referencing Linux vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-264" adv="1" patch="1">DSA-264</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7062" adv="1" patch="1">7062</ref>
    </refs>
    <vuln_soft>
      <prod name="lxr" vendor="cross_referencer">
        <vers num="0.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0157" seq="2003-0157" published="2003-03-24" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0158" seq="2003-0158" published="2003-03-24" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0159" seq="2003-0159" published="2003-04-02" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104741640924709&amp;w=2">20030309 GLSA:  ethereal (200303-10)</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7050" adv="1" patch="1">7050</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A55">oval:org.mitre.oval:def:55</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.8.18"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0160" seq="2003-0160" published="2003-04-02" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988" patch="1">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-112.html">RHSA-2003:112</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A614">oval:org.mitre.oval:def:614</ref>
    </refs>
    <vuln_soft>
      <prod name="squirrelmail" vendor="squirrelmail">
        <vers num="1.2.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0161" seq="2003-0161" published="2003-04-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt">CSSA-2003-016.0</ref>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc">FreeBSD-SA-03:07</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt">SCOSA-2004.11</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P">20030401-01-P</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614">CLA-2003:614</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html">20030329 Sendmail: -1 gone wild</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104896621106790&amp;w=2">20030329 sendmail 8.12.9 available</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104897487512238&amp;w=2">20030329 Sendmail: -1 gone wild</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104914999806315&amp;w=2">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1">52620</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1">52700</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001088.1-1">1001088</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-12.html" adv="1" patch="1">CA-2003-12</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-278">DSA-278</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-290">DSA-290</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml">GLSA-200303-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/897604">VU#897604</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-120.html" adv="1" patch="1">RHSA-2003:120</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-121.html">RHSA-2003:121</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316961/30/25250/threaded">20030331 GLSA: sendmail (200303-27)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317135/30/25220/threaded">20030401 Immunix Secured OS 7+ openssl update</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321997">20030520 [Fwd: 127 Research and Development: 127 Day!]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7230" adv="1" patch="1">7230</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="8.9.0"/>
        <vers num="8.9.1"/>
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.11.4"/>
        <vers num="8.11.5"/>
        <vers num="8.11.6"/>
        <vers num="8.12" edition="beta10"/>
        <vers num="8.12" edition="beta12"/>
        <vers num="8.12" edition="beta16"/>
        <vers num="8.12" edition="beta5"/>
        <vers num="8.12" edition="beta7"/>
        <vers num="8.12.0"/>
        <vers num="8.12.1"/>
        <vers num="8.12.2"/>
        <vers num="8.12.3"/>
        <vers num="8.12.4"/>
        <vers num="8.12.5"/>
        <vers num="8.12.6"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
      </prod>
      <prod name="sendmail_switch" vendor="sendmail">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod name="hp-ux_series_700" vendor="hp">
        <vers num="10.20"/>
      </prod>
      <prod name="hp-ux_series_800" vendor="hp">
        <vers num="10.20"/>
      </prod>
      <prod name="sis" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0162" seq="2003-0162" published="2003-04-02" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104636153214262&amp;w=2">20030227 Ecardis Password Reseting Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104673407728323&amp;w=2">20030303 Re: Ecardis Password Reseting Vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-271">DSA-271</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6971" adv="1" patch="1">6971</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11431">ecartis-password-reset(11431)</ref>
    </refs>
    <vuln_soft>
      <prod name="ecartis" vendor="ecartis">
        <vers num="1.0.0_snapshot_2002-10-13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0163" seq="2003-0163" published="2003-05-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105013281120352&amp;w=2">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0013.html" adv="1" patch="1">http://www.rapid7.com/advisories/R7-0013.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7182" adv="1" patch="1">7182</ref>
    </refs>
    <vuln_soft>
      <prod name="gaim-encryption" vendor="gaim-encryption">
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0165" seq="2003-0165" published="2003-04-02" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html">20030328 Vulnerability in GNOME's Eye of Gnome</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104887189724146&amp;w=2">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/363001">VU#363001</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048">MDKSA-2003:048</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-128.html" adv="1" patch="1">RHSA-2003:128</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7121" adv="1" patch="1">7121</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A52">oval:org.mitre.oval:def:52</ref>
    </refs>
    <vuln_soft>
      <prod name="eog" vendor="gnome">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0166" seq="2003-0166" published="2003-04-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691">CLSA-2003:691</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104869828526885&amp;w=2">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104878100719467&amp;w=2">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7197" adv="1">7197</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7198" adv="1">7198</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0167" seq="2003-0167" published="2003-04-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-274" adv="1" patch="1">DSA-274</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-300">DSA-300</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7229" adv="1" patch="1">7229</ref>
    </refs>
    <vuln_soft>
      <prod name="mutt" vendor="mutt">
        <vers num="1.3.12"/>
        <vers num="1.3.12.1"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.22"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0168" seq="2003-0168" published="2003-04-02" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" adv="1">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00027.html">http://lists.apple.com/mhonarc/security-announce/msg00027.html</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/03.31.03.txt">http://www.idefense.com/advisory/03.31.03.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/112553">VU#112553</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317141/30/25220/threaded">20030401 Fwd: QuickTime 6.1 for Windows is available</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317148/30/25220/threaded">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7247">7247</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11671">quicktime-url-bo(11671)</ref>
    </refs>
    <vuln_soft>
      <prod name="quicktime" vendor="apple">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0169" seq="2003-0169" published="2003-04-11" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" adv="1" patch="1">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104914959705949&amp;w=2">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7246" adv="1" patch="1">7246</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_toptools" vendor="hp">
        <vers num="5.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0170" seq="2003-0170" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/7346" adv="1" patch="1">7346</ref>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0469.1">MSS-OAR-E01-2003.0469.1</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY42424" adv="1" patch="1">IY42424</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11823">aix-ftpd-gain-access(11823)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0171" seq="2003-0171" published="2003-05-05" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a041003-1.txt" adv="1">A041003-1</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0172" seq="2003-0172" published="2003-04-02" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104878149020152&amp;w=2">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316583">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/385238">20041222 PHP v4.3.x exploit for Windows.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7210" adv="1" patch="1">7210</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11637">php-openlog-stack-bo(11637)</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0173" seq="2003-0173" published="2003-05-05" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" adv="1" patch="1">20030404-01-P</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-283" adv="1" patch="1">DSA-283</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/111673">VU#111673</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047">MDKSA-2003:047</ref>
    </refs>
    <vuln_soft>
      <prod name="xfsdump" vendor="xfsdump">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0174" seq="2003-0174" published="2003-05-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" adv="1" patch="1">20030407-01-P</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-084.shtml">N-084</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7442" adv="1" patch="1">7442</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11860">irix-ldap-authentication-bypass(11860)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0175" seq="2003-0175" published="2004-02-03" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P" adv="1" patch="1">20030603-01-P</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/142228" adv="1" patch="1">VU#142228</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7868" adv="1" patch="1">7868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008770">1008770</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12241">irix-piocswatch-ioctl-dos(12241)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0176" seq="2003-0176" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" adv="1" patch="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0177" seq="2003-0177" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" adv="1" patch="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0178" seq="2003-0178" published="2003-04-02" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550063431461&amp;w=2">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550063431463&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104558777331345&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104558777531350&amp;w=2">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206361">VU#206361</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/542873">VU#542873</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/772817" adv="1" patch="1">VU#772817</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6870">6870</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6871" adv="1" patch="1">6871</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11336">lotus-domino-inotes-bo(11336)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11337">lotus-domino-hostname-bo(11337)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_web_server" vendor="ibm">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0179" seq="2003-0179" published="2003-04-02" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550124032513&amp;w=2">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104558778131373&amp;w=2">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/571297" adv="1" patch="1">VU#571297</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6872" adv="1" patch="1">6872</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104543">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11339">lotus-notes-activex-bo(11339)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_web_server" vendor="ibm">
        <vers num="6.0"/>
      </prod>
      <prod name="lotus_notes_client" vendor="ibm">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0180" seq="2003-0180" published="2003-04-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1" patch="1">CA-2003-11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/355169" adv="1" patch="1">VU#355169</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-60dos.txt" adv="1" patch="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11360">lotus-incomplete-post-dos(11360)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_web_server" vendor="ibm">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0181" seq="2003-0181" published="2003-04-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1" patch="1">CA-2003-11</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-60dos.txt" adv="1" patch="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11361">lotus-invalid-field-dos(11361)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_web_server" vendor="ibm">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0187" seq="2003-0187" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105986028426824&amp;w=2">20030802 [SECURITY] Netfilter Security Advisory: Conntrack list_del() DoS</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A260">oval:org.mitre.oval:def:260</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0188" seq="2003-0188" published="2003-06-09" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-304" adv="1" patch="1">DSA-304</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-167.html">RHSA-2003:167</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-169.html" adv="1" patch="1">RHSA-2003:169</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-35.txt">TLSA-2003-35</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A430">oval:org.mitre.oval:def:430</ref>
    </refs>
    <vuln_soft>
      <prod name="lv" vendor="lv">
        <vers num="4.49.1"/>
        <vers num="4.49.2"/>
        <vers num="4.49.3"/>
        <vers num="4.49.4"/>
      </prod>
      <prod name="lv" vendor="redhat">
        <vers num="4.49.4-1" edition=":i386"/>
        <vers num="4.49.4-3" edition=":i386"/>
        <vers num="4.49.4-7" edition=":i386"/>
        <vers num="4.49.4-9" edition=":i386"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0189" seq="2003-0189" published="2003-06-09" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661">CLA-2003:661</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/Announcement2.html" adv="1" patch="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/479268">VU#479268</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-186.html" adv="1" patch="1">RHSA-2003:186</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7725">7725</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12091">apache-aprpasswordvalidate-dos(12091)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0190" seq="2003-0190" published="2003-05-12" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lab.mediaservice.net/advisory/2003-01-openssh.txt">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105172058404810&amp;w=2">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106018677302607&amp;w=2">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-222.html">RHSA-2003:222</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-224.html">RHSA-2003:224</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7467" adv="1" patch="1">7467</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-31.txt">TLSA-2003-31</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A445">oval:org.mitre.oval:def:445</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.4p1"/>
        <vers num="3.6.1p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0192" seq="2003-0192" published="2003-08-18" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt">SCOSA-2004.6</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-240.html" adv="1" patch="1">RHSA-2003:240</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A169">oval:org.mitre.oval:def:169</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0193" seq="2003-0193" published="2004-08-18" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=183525</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-575">DSA-575</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/11560">11560</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16335">catdoc-xlsview-symlink(16335)</ref>
    </refs>
    <vuln_soft>
      <prod name="catdoc" vendor="catdoc">
        <vers num="0.91" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0194" seq="2003-0194" published="2003-06-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">tcpdump does not properly drop privileges to the pcap user when starting up.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-151.html">RHSA-2003:151</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-174.html" adv="1" patch="1">RHSA-2003:174</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="redhat">
        <vers num="3.4-39" edition=":i386"/>
        <vers num="3.6.2-9" edition=":i386"/>
        <vers num="3.6.2-9" edition=":ia64"/>
        <vers num="3.6.2-12" edition=":i386"/>
        <vers num="3.6.3-3" edition=":i386"/>
        <vers num="3.7.2-1" edition=":i386"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0195" seq="2003-0195" published="2003-06-16" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000678">CLSA-2003:678</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105427288724449&amp;w=2">20030529 [slackware-security]  CUPS DoS vulnerability fixed (SSA:2003-149-01)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-317" adv="1" patch="1">DSA-317</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:062">MDKSA-2003:062</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_028.html">SuSE-SA:2003:028</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-171.html" adv="1" patch="1">RHSA-2003:171</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7637">7637</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-33.txt">TLSA-2003-33</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6">oval:org.mitre.oval:def:6</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="8.1"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0196" seq="2003-0196" published="2003-05-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104973186901597&amp;w=2">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-280" adv="1" patch="1">DSA-280</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-137.html" adv="1" patch="1">RHSA-2003:137</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A564">oval:org.mitre.oval:def:564</ref>
    </refs>
    <vuln_soft>
      <prod name="cifs-9000_server" vendor="hp">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
        <vers num="a.01.09.02"/>
      </prod>
      <prod name="samba" vendor="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
      </prod>
      <prod name="samba-tng" vendor="samba-tng">
        <vers num="0.3"/>
        <vers num="0.3.1"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0197" seq="2003-0197" published="2003-04-11" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104940730819887&amp;w=2">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" adv="1" patch="1">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="interbase" vendor="borland_software">
        <vers num="6.0"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
      <prod name="firebird" vendor="firebirdsql">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0198" seq="2003-0198" published="2003-05-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0199" seq="2003-0199" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0200" seq="2003-0200" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0201" seq="2003-0201" published="2003-05-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P">20030403-01-P</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624">CLA-2003:624</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104972664226781&amp;w=2">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104981682014565&amp;w=2">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104994564212488&amp;w=2">20030409 GLSA:  samba (200304-02)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-280" adv="1" patch="1">DSA-280</ref>
      <ref source="MISC" url="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/267873">VU#267873</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_025_samba.html">SuSE-SA:2003:025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-137.html">RHSA-2003:137</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7294" adv="1" patch="1">7294</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2163">oval:org.mitre.oval:def:2163</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A567">oval:org.mitre.oval:def:567</ref>
    </refs>
    <vuln_soft>
      <prod name="cifs-9000_server" vendor="hp">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
        <vers num="a.01.07"/>
        <vers num="a.01.08"/>
        <vers num="a.01.08.01"/>
        <vers num="a.01.09"/>
        <vers num="a.01.09.01"/>
        <vers num="a.01.09.02"/>
      </prod>
      <prod name="samba" vendor="samba">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
      </prod>
      <prod name="samba-tng" vendor="samba-tng">
        <vers num="0.3"/>
        <vers num="0.3.1"/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0b"/>
        <vers num="4.0d"/>
        <vers num="4.0d_pk9_bl17"/>
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="5.0"/>
        <vers num="5.0_pk4_bl17"/>
        <vers num="5.0_pk4_bl18"/>
        <vers num="5.0a"/>
        <vers num="5.0a_pk3_bl17"/>
        <vers num="5.0f"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
        <vers num="9.0" edition="x86_update_2"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0202" seq="2003-0202" published="2004-04-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-279" adv="1" patch="1">DSA-279</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7293" adv="1">7293</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11734">metrics-tmpfile-symlink(11734)</ref>
    </refs>
    <vuln_soft>
      <prod name="metrics" vendor="brian_renaud">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0203" seq="2003-0203" published="2003-04-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104610380126860&amp;w=2">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-281">DSA-281</ref>
      <ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html">20030223 moxftp arbitrary code execution poc/advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6921" adv="1" patch="1">6921</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006156">1006156</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11399">moxftp-welcome-banner-bo(11399)</ref>
    </refs>
    <vuln_soft>
      <prod name="moxftp" vendor="moxftp">
        <vers num="2.2"/>
      </prod>
      <prod name="xftp" vendor="xftp">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0204" seq="2003-0204" published="2003-05-05" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=53343">http://bugs.kde.org/show_bug.cgi?id=53343</ref>
      <ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=56808">http://bugs.kde.org/show_bug.cgi?id=56808</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668">CLA-2003:668</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105001557020141&amp;w=2">20030410 GLSA:  kde-3.x (200304-04)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105012994719099&amp;w=2">20030411 GLSA:  kde-2.x (200304-05)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105017403010459&amp;w=2">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105034222521369&amp;w=2">20030414 GLSA:  kde-2.x (200304-05.1)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-284" adv="1" patch="1">DSA-284</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-293">DSA-293</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-296">DSA-296</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20030409-1.txt" adv="1" patch="1">http://www.kde.org/info/security/advisory-20030409-1.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049">MDKSA-2003:049</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-002.html">RHSA-2003:002</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3a"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5a"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0205" seq="2003-0205" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105111327000755&amp;w=2">20030423 Security problems in gkrellm-newsticker</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-294" adv="1" patch="1">DSA-294</ref>
    </refs>
    <vuln_soft>
      <prod name="gkrellm_newsticker" vendor="gkrellm_newsticker">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0206" seq="2003-0206" published="2003-05-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105111327000755&amp;w=2">20030423 Security problems in gkrellm-newsticker</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-294" adv="1" patch="1">DSA-294</ref>
    </refs>
    <vuln_soft>
      <prod name="gkrellm_newsticker" vendor="gkrellm_newsticker">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0207" seq="2003-0207" published="2003-05-05" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-286" adv="1" patch="1">DSA-286</ref>
    </refs>
    <vuln_soft>
      <prod name="gs-common" vendor="gs-common">
        <vers num="0.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0208" seq="2003-0208" published="2003-05-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105033712615013&amp;w=2">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" adv="1" patch="1">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" adv="1" patch="1">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</ref>
    </refs>
    <vuln_soft>
      <prod name="flash" vendor="macromedia">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0209" seq="2003-0209" published="2003-05-05" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105043563016235&amp;w=2">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105103586927007&amp;w=2">20030422 GLSA:  snort (200304-05)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105111217731583&amp;w=2">20030423 Snort &lt;=1.9.1 exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105154530427824&amp;w=2">20030428 GLSA:  snort (200304-06)</ref>
      <ref source="ENGARDE" url="http://marc.info/?l=bugtraq&amp;m=105172790914107&amp;w=2">ESA-20030430-013</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139129" adv="1">VU#139129</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052">MDKSA-2003:052</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7178" adv="1" patch="1">7178</ref>
    </refs>
    <vuln_soft>
      <prod name="smoothwall" vendor="smoothwall">
        <vers num="2.0_beta_4"/>
      </prod>
      <prod name="snort" vendor="sourcefire">
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.9"/>
        <vers num="1.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0210" seq="2003-0210" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105120066126196&amp;w=2">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105118056332344&amp;w=2">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" adv="1" patch="1">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/697049">VU#697049</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_access_control_server" vendor="cisco">
        <vers num="2.1"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.3"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0211" seq="2003-0211" published="2003-05-05" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782">CLA-2003:782</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105068673220605&amp;w=2">20030418 Xinetd 2.3.10 Memory Leaks</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056">MDKSA-2003:056</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-160.html">RHSA-2003:160</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A657">oval:org.mitre.oval:def:657</ref>
    </refs>
    <vuln_soft>
      <prod name="xinetd" vendor="xinetd">
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0212" seq="2003-0212" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105059298502830&amp;w=2">20030417 Vulnerability in rinetd</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-289" adv="1" patch="1">DSA-289</ref>
    </refs>
    <vuln_soft>
      <prod name="rinetd" vendor="rinetd">
        <vers num="0.52"/>
        <vers num="0.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0213" seq="2003-0213" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105068728421160&amp;w=2">20030418 Exploit for PoPToP PPTP server</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105154539727967&amp;w=2">20030428 GLSA:  pptpd (200304-08)</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=138437">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-295" adv="1" patch="1">DSA-295</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/673993">VU#673993</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_029.html">SuSE-SA:2003:029</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317995" adv="1" patch="1">20030409 PoPToP PPTP server remotely exploitable buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319428">20030422 Re: Exploit for PoPToP PPTP server - Linux version</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7316" adv="1" patch="1">7316</ref>
    </refs>
    <vuln_soft>
      <prod name="pptp_server" vendor="poptop">
        <vers num="1.0.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.3_2002-10-09"/>
        <vers num="1.1.4b1"/>
        <vers num="1.1.4b2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0214" seq="2003-0214" published="2003-05-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-292" adv="1" patch="1">DSA-292</ref>
    </refs>
    <vuln_soft>
      <prod name="mime-support" vendor="debian">
        <vers num="3.9"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0215" seq="2003-0215" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105120052725940&amp;w=2">20030424 SQL injection in BttlxeForum</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006632">1006632</ref>
      <ref source="CONFIRM" url="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" adv="1" patch="1">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</ref>
    </refs>
    <vuln_soft>
      <prod name="bttlxeforum" vendor="battleaxe_software">
        <vers num="2.0_beta_3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0216" seq="2003-0216" published="2003-05-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml.">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443257">VU#443257</ref>
    </refs>
    <vuln_soft>
      <prod name="catos" vendor="cisco">
        <vers num="7.5(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0217" seq="2003-0217" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105283833617480&amp;w=2">20030513 XSS In Neoteris IVE Allows Session Hijacking</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_virtual_extranet" vendor="neoteris">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0218" seq="2003-0218" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" adv="1" patch="1">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105094204204166&amp;w=2">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105154473526898&amp;w=2">20030428 GLSA:  monkeyd (200304-07.1)</ref>
      <ref source="CONFIRM" url="http://monkeyd.sourceforge.net/Changelog.txt">http://monkeyd.sourceforge.net/Changelog.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7202" adv="1" patch="1">7202</ref>
    </refs>
    <vuln_soft>
      <prod name="monkey_http_daemon" vendor="monkey-project">
        <vers num="0.1.1"/>
        <vers num="0.5.2"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0219" seq="2003-0219" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641012">VU#641012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7179">7179</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_firewall_2" vendor="kerio">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0220" seq="2003-0220" published="2003-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" adv="1" patch="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/454716">VU#454716</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7180">7180</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_firewall_2" vendor="kerio">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0221" seq="2003-0221" published="2003-05-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.ciac.org/ciac/bulletins/n-086.shtml">SSRT3471</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7452">7452</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11892">tru64-dupatch-setld-symlink(11892)</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="hp">
        <vers num="5.1b" prev="1" edition="pk1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0222" seq="2003-0222" published="2003-05-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105162831008176&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105163376015735&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-085.shtml">N-085</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7453" adv="1" patch="1">7453</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11885">oracle-database-link-bo(11885)</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.0.5.1"/>
        <vers num="8.0.6"/>
        <vers num="8.1.5"/>
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.0.6"/>
        <vers num="8.0.6.3"/>
        <vers num="8.0x"/>
        <vers num="8.1.5"/>
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
        <vers num="8.1.7.1"/>
        <vers num="8.1.7.4"/>
        <vers num="8.1x"/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.1.2"/>
        <vers num="9.0.1.3"/>
        <vers num="9.0.1.4"/>
        <vers num="9.0.2"/>
        <vers num="9.2.0.1"/>
        <vers num="9.2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0223" seq="2003-0223" published="2003-06-09" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018">MS03-018</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A66">oval:org.mitre.oval:def:66</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0224" seq="2003-0224" published="2003-06-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105431767100944&amp;w=2">20030530 NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018">MS03-018</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483">oval:org.mitre.oval:def:483</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0225" seq="2003-0225" published="2003-06-09" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105110606122772&amp;w=2">20030418 Microsoft Active Server Pages DoS</ref>
      <ref source="MISC" url="http://www.aqtronix.com/Advisories/AQ-2003-01.txt">http://www.aqtronix.com/Advisories/AQ-2003-01.txt</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018">MS03-018</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373">oval:org.mitre.oval:def:373</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0226" seq="2003-0226" published="2003-06-09" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html" adv="1" patch="1">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105427362724860&amp;w=2">20030529 IIS WEBDAV Denial of Service attacks</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105421243732552&amp;w=2">20030528 Internet Information Services 5.0 Denial of service</ref>
      <ref source="MISC" url="http://www.spidynamics.com/iis_alert.html" adv="1" patch="1">http://www.spidynamics.com/iis_alert.html</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018">MS03-018</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A933">oval:org.mitre.oval:def:933</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.1"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0227" seq="2003-0227" published="2003-06-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105427615626177&amp;w=2">20030528 RE: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105421127531558&amp;w=2">20030528 Re: Alert: MS03-019, Microsoft... wrong, again.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105421176432011&amp;w=2">20030528 MS03-019: DoS or Code of Choice</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-019">MS03-019</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A936">oval:org.mitre.oval:def:936</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A966">oval:org.mitre.oval:def:966</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0228" seq="2003-0228" published="2003-05-27" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232913516488&amp;w=2">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105240528419389&amp;w=2">20030508 why i love xs4all + mediaplayer thingie</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105233960728901&amp;w=2">20030507 Windows Media Player directory traversal vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/384932">VU#384932</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7517" adv="1" patch="1">7517</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-017">MS03-017</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11953">mediaplayer-skin-code-execution(11953)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A321">oval:org.mitre.oval:def:321</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="-"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0230" seq="2003-0230" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/556356">VU#556356</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031">MS03-031</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A235">oval:org.mitre.oval:def:235</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0231" seq="2003-0231" published="2003-08-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a072303-2.txt">A072303-2</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/918652">VU#918652</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031">MS03-031</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A299">oval:org.mitre.oval:def:299</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0232" seq="2003-0232" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a072303-3.txt" adv="1" patch="1">A072303-3</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/584868">VU#584868</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031">MS03-031</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A303">oval:org.mitre.oval:def:303</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="2000" edition=":desktop_engine"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sp3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0233" seq="2003-0233" published="2003-05-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105120164927952&amp;w=2">20030424 Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11854.php" adv="1">ie-plugin-load-bo(11854)</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-015">MS03-015</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1094">oval:org.mitre.oval:def:1094</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0235" seq="2003-0235" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7461" adv="1">7461</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11938">icq-pop3-format-string(11938)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0236" seq="2003-0236" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7462" adv="1">7462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7463" adv="1">7463</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11939">icq-pop3-email-bo(11939)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0237" seq="2003-0237" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7464" adv="1" patch="1">7464</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11944">icq-features-no-auth(11944)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0238" seq="2003-0238" published="2003-05-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7465" adv="1">7465</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11947">icq-table-tag-dos(11947)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0239" seq="2003-0239" published="2003-05-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0051.html">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105216842131995&amp;w=2">20030505 CORE-2003-0303: Multiple Vulnerabilities in Mirabilis ICQ client</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=315&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7466" adv="1">7466</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11948">icq-gif89a-header-dos(11948)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
        <vers num="2001b_build3636"/>
        <vers num="2001b_build3638"/>
        <vers num="2001b_build3659"/>
        <vers num="2002a_build3722"/>
        <vers num="2002a_build3727"/>
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0240" seq="2003-0240" published="2003-06-09" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105406374731579&amp;w=2">20030527 CORE-2003-0403: Axis Network Camera HTTP Authentication Bypass</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006854">1006854</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=329&amp;idxseccion=10</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/799060">VU#799060</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7652">7652</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12104">axis-admin-authentication-bypass(12104)</ref>
    </refs>
    <vuln_soft>
      <prod name="2100_network_camera" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2110_network_camera" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2120_network_camera" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2130_ptz_network_camera" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2400_video_server" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2401_video_server" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2420_network_camera" vendor="axis">
        <vers num="2.32" prev="1"/>
      </prod>
      <prod name="2460_network_dvr" vendor="axis">
        <vers num="3.00" prev="1"/>
      </prod>
      <prod name="250s_video_server" vendor="axis">
        <vers num="3.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0241" seq="2003-0241" published="2003-06-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0091.html" adv="1" patch="1">20030528 SECNAP Security Advisory: Invalid HTML processing in GoldMine(tm)</ref>
      <ref source="MISC" url="http://www.secnap.net/security/gm001.html" adv="1" patch="1">http://www.secnap.net/security/gm001.html</ref>
    </refs>
    <vuln_soft>
      <prod name="goldmine" vendor="frontrange">
        <vers num="5.70"/>
        <vers num="6.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0242" seq="2003-0242" published="2003-06-09" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006796">1006796</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869548">VU#869548</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7628">7628</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12027">macos-ipsec-acl-bypass(12027)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0243" seq="2003-0243" published="2003-05-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0058.html">20030507 Happymall E-Commerce Remote Command Execution</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006707">1006707</ref>
    </refs>
    <vuln_soft>
      <prod name="happymall" vendor="happycgi">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0244" seq="2003-0244" published="2003-05-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html">20030517 Algorithmic Complexity Attacks and the Linux Networking Code</ref>
      <ref source="ENGARDE" url="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105595901923063&amp;w=2">20030618 [slackware-security]  2.4.21 kernels available (SSA:2003-168-01)</ref>
      <ref source="MISC" url="http://marc.info/?l=linux-kernel&amp;m=104956079213417">http://marc.info/?l=linux-kernel&amp;m=104956079213417</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311" adv="1" patch="1">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="MISC" url="http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html">http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-145.html" adv="1" patch="1">RHSA-2003:145</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-147.html">RHSA-2003:147</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-172.html">RHSA-2003:172</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7601">7601</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15382">data-algorithmic-complexity-dos(15382)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A261">oval:org.mitre.oval:def:261</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0245" seq="2003-0245" published="2003-06-09" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html">20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000661">CLA-2003:661</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
      <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/Announcement2.html" adv="1" patch="1">http://www.apache.org/dist/httpd/Announcement2.html</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/05.30.03.txt">http://www.idefense.com/advisory/05.30.03.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/757612" adv="1">VU#757612</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:063">MDKSA-2003:063</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-186.html" adv="1" patch="1">RHSA-2003:186</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7723">7723</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12090">apache-aprpsprintf-code-execution(12090)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0246" seq="2003-0246" published="2003-06-16" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0076.html">20030520 Linux 2.4 kernel ioperm vuln</ref>
      <ref source="ENGARDE" url="http://marc.info/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311" adv="1" patch="1">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-147.html">RHSA-2003:147</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-172.html" adv="1" patch="1">RHSA-2003:172</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A278">oval:org.mitre.oval:def:278</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.20"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0247" seq="2003-0247" published="2003-06-16" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311" adv="1" patch="1">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-187.html" adv="1" patch="1">RHSA-2003:187</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-195.html">RHSA-2003:195</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A284">oval:org.mitre.oval:def:284</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0248" seq="2003-0248" published="2003-06-16" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311" adv="1" patch="1">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:066">MDKSA-2003:066</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-187.html" adv="1" patch="1">RHSA-2003:187</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-195.html">RHSA-2003:195</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt">TLSA-2003-41</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A292">oval:org.mitre.oval:def:292</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0249" seq="2003-0249" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">** DISPUTED **  PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive.  NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method.  A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods.  It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=97" adv="1">20030625 PHP/Apache .htaccess Authentication Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0251" seq="2003-0251" published="2003-07-24" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1016517">1016517</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55600&amp;zone_32=category%3Asecurity">55600</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:072">MDKSA-2003:072</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-173.html" adv="1" patch="1">RHSA-2003:173</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-201.html">RHSA-2003:201</ref>
      <ref source="HP" url="http://www.securityfocus.com/archive/1/440454/100/0/threaded">HPSBTU02132</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8031">8031</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-43.txt">TLSA-2003-43</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/2873">ADV-2006-2873</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A667">oval:org.mitre.oval:def:667</ref>
    </refs>
    <vuln_soft>
      <prod name="ypserv_nis_server" vendor="nis">
        <vers num="2.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0252" seq="2003-0252" published="2003-08-18" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html" adv="1">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html" adv="1">20030714 Reality of the rpc.mountd bug</ref>
      <ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt">http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820223707191&amp;w=2">20030714 Linux nfs-utils xlog() off-by-one bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105830921519513&amp;w=2">20030715 [slackware-security]  nfs-utils packages replaced (SSA:2003-195-01b)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839032403325&amp;w=2">20030716 Immunix Secured OS 7+ nfs-utils update -- bugtraq</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007187">1007187</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1">1001262</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-349">DSA-349</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258564">VU#258564</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:076">MDKSA-2003:076</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.html">SuSE-SA:2003:031</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-206.html">RHSA-2003:206</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-207.html">RHSA-2003:207</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8179">8179</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-44.txt">TLSA-2003-44</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12600">nfs-utils-offbyone-bo(12600)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A443">oval:org.mitre.oval:def:443</ref>
    </refs>
    <vuln_soft>
      <prod name="nfs-utils" vendor="nfs">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3.1"/>
        <vers num="0.3.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0253" seq="2003-0253" published="2003-08-18" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-240.html" adv="1" patch="1">RHSA-2003:240</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A173">oval:org.mitre.oval:def:173</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0254" seq="2003-0254" published="2003-08-18" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105776593602600&amp;w=2">20030709 [ANNOUNCE][SECURITY] Apache 2.0.47 released</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:075">MDKSA-2003:075</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-240.html" adv="1" patch="1">RHSA-2003:240</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A183">oval:org.mitre.oval:def:183</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0255" seq="2003-0255" published="2003-05-27" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000694">CLA-2003:694</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105215110111174&amp;w=2">20030504 Key validity bug in GnuPG 1.2.1 and earlier</ref>
      <ref source="ENGARDE" url="http://marc.info/?l=bugtraq&amp;m=105301357425157&amp;w=2">ESA-20030515-016</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105311804129104&amp;w=2">20030516 [OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105362224514081&amp;w=2">20030522 [slackware-security]  GnuPG key validation fix (SSA:2003-141-04)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/397604">VU#397604</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html">20030515-016</ref>
      <ref source="MISC" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html">http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:061">MDKSA-2003:061</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-175.html" adv="1" patch="1">RHSA-2003:175</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-176.html">RHSA-2003:176</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7497">7497</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-34.txt">TLSA200334</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11930">gnupg-invalid-key-acceptance(11930)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135">oval:org.mitre.oval:def:135</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0256" seq="2003-0256" published="2003-05-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000665">CLA-2003:665</ref>
      <ref source="CONFIRM" url="http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2">http://kopete.kde.org/index.php?page=newsstory&amp;news=Kopete_releases_version_0.6.2</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:055">MDKSA-2003:055</ref>
    </refs>
    <vuln_soft>
      <prod name="kopete" vendor="kde">
        <vers num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0257" seq="2003-0257" published="2004-04-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1" adv="1" patch="1">MSS-OAR-E01-2003:0660.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12000">aix-print-format-string(12000)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0258" seq="2003-0258" published="2003-05-27" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" adv="1" patch="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/727780">VU#727780</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11954">cisco-vpn-unauth-access(11954)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn_3002_hardware_client" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3015_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3030_concentator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3060_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3080_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3000_concentrator_series_software" vendor="cisco">
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
        <vers num="3.6.7.a"/>
        <vers num="3.6.7.b"/>
        <vers num="3.6.7.c"/>
        <vers num="3.6.7.d"/>
        <vers num="3.6.7d"/>
        <vers num="4.0"/>
      </prod>
      <prod name="vpn_3005_concentrator_software" vendor="cisco">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0259" seq="2003-0259" published="2003-05-27" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" adv="1" patch="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/317348">VU#317348</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11955">cisco-vpn-ssh-dos(11955)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn_3002_hardware_client" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3015_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3030_concentator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3060_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3080_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3000_concentrator_series_software" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.5.2.a"/>
        <vers num="2.5.2.b"/>
        <vers num="2.5.2.c"/>
        <vers num="2.5.2.d"/>
        <vers num="2.5.2.f"/>
        <vers num="3.0"/>
        <vers num="3.0.3.a"/>
        <vers num="3.0.3.b"/>
        <vers num="3.0.4"/>
        <vers num="3.1"/>
        <vers num="3.1(rel)"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.4"/>
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
        <vers num="3.6.7.a"/>
        <vers num="3.6.7.b"/>
        <vers num="3.6.7.c"/>
        <vers num="3.6.7.d"/>
        <vers num="3.6.7d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0260" seq="2003-0260" published="2003-05-27" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtml" adv="1" patch="1">20030507 Cisco VPN 3000 Concentrator Vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/221164">VU#221164</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11956">cisco-vpn-icmp-dos(11956)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn_3002_hardware_client" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3015_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3030_concentator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3060_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3080_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3000_concentrator_series_software" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.5.2.a"/>
        <vers num="2.5.2.b"/>
        <vers num="2.5.2.c"/>
        <vers num="2.5.2.d"/>
        <vers num="2.5.2.f"/>
        <vers num="3.0"/>
        <vers num="3.0.3.a"/>
        <vers num="3.0.3.b"/>
        <vers num="3.0.4"/>
        <vers num="3.1"/>
        <vers num="3.1(rel)"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.4"/>
        <vers num="3.5(rel)"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.3"/>
        <vers num="3.6.5"/>
        <vers num="3.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0261" seq="2003-0261" published="2003-05-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-302" adv="1" patch="1">DSA-302</ref>
    </refs>
    <vuln_soft>
      <prod name="fuzz" vendor="fuzz">
        <vers num="0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0262" seq="2003-0262" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-299" adv="1" patch="1">DSA-299</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7505">7505</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11945">kataxwr-gain-privileges(11945)</ref>
    </refs>
    <vuln_soft>
      <prod name="leksbot" vendor="leksbot">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0263" seq="2003-0263" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0052.html">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105223471822836&amp;w=2">20030506 Multiple Buffer Overflow Vulnerabilities Found in FTGate Pro Mail Server v. 1.22 (1328)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7506" adv="1" patch="1">7506</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7508" adv="1" patch="1">7508</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11951">ftgate-mailfrom-rcptto-bo(11951)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftgatepro" vendor="floosietek">
        <vers num="1.22_1328"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0264" seq="2003-0264" published="2003-05-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232506011335&amp;w=2">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105233360321895&amp;w=2">20030507 Multiple Buffer Overflow Vulnerabilities in SLMail (#NISR07052003A)</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/slmail-vulns.txt" adv="1" patch="1">http://www.nextgenss.com/advisories/slmail-vulns.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="slmail" vendor="seattle_lab_software">
        <vers num="5.1.0.4420"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0265" seq="2003-0265" published="2003-05-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232424810097&amp;w=2">20030507 SAP database local root vulnerability during installation. (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7421" adv="1" patch="1">7421</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.3.29"/>
        <vers num="7.4.3.7_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0266" seq="2003-0266" published="2003-05-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="slwebmail" vendor="bvrp_software">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0267" seq="2003-0267" published="2003-05-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="slwebmail" vendor="bvrp_software">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0268" seq="2003-0268" published="2003-05-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105232436210273&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105233363721919&amp;w=2">20030507 Multiple Vulnerabilities in SLWebmail</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/slwebmail-vulns.txt" adv="1">http://www.nextgenss.com/advisories/slwebmail-vulns.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="slwebmail" vendor="bvrp_software">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0269" seq="2003-0269" published="2003-05-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0053.html">20030506 youbin local root exploit + advisory</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004892.html">20030506 youbin local root exploit + advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105223947528794&amp;w=2">20030506 youbin local root exploit + advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7503" adv="1">7503</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11949">youbin-home-bo(11949)</ref>
    </refs>
    <vuln_soft>
      <prod name="youbin" vendor="youbin">
        <vers num="2.5"/>
        <vers num="3.0"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0270" seq="2003-0270" published="2003-06-16" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006742">1006742</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a051203-1.txt" adv="1">A051203-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7554" adv="1">7554</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11980">airport-auth-credentials-disclosure(11980)</ref>
    </refs>
    <vuln_soft>
      <prod name="802.11n" vendor="apple">
        <vers num="7.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0271" seq="2003-0271" published="2003-05-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105240469318622&amp;w=2">20030508 Remote Stack Overflow exploit for Personal FTPD</ref>
      <ref source="MISC" url="http://security.nnov.ru/search/document.asp?docid=4309">http://security.nnov.ru/search/document.asp?docid=4309</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316958" adv="1">20030331 Personal FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_ftp_server" vendor="cooolsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0272" seq="2003-0272" published="2003-05-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105240907024660&amp;w=2">20030508 miniPortail (PHP) : Admin Access</ref>
      <ref source="MISC" url="http://www.frog-man.org/tutos/miniPortail.txt">http://www.frog-man.org/tutos/miniPortail.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="miniportal" vendor="miniportal">
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0273" seq="2003-0273" published="2003-05-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html" adv="1">http://lists.fsck.com/pipermail/rt-announce/2003-May/000071.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105240947225275&amp;w=2">20030508 Fw: [rt-users] [rt-announce] RT 1.0.7 vulnerable to Cross Site Scripting attacks</ref>
    </refs>
    <vuln_soft>
      <prod name="request_tracker" vendor="best_practical_solutions">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0274" seq="2003-0274" published="2003-05-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105241224228693&amp;w=2">20030508 SRT2003-05-08-1137 - ListProc mailing list ULISTPROC_UMASK overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="listproc" vendor="cren">
        <vers num="8.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0275" seq="2003-0275" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105249980809988&amp;w=2">20030509 II-Labs Advisory: Remote code execution in YaBBse 1.5.2 (php version)</ref>
    </refs>
    <vuln_soft>
      <prod name="yabb" vendor="yabb">
        <vers num="1.5.2" edition=":second_edition"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0276" seq="2003-0276" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105155818012718&amp;w=2">20030428 Pi3Web 2.0.1 DoS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105275789410250&amp;w=2">20030512 Unix Version of the Pi3web DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7555">7555</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11889">pi3web-get-request-bo(11889)</ref>
    </refs>
    <vuln_soft>
      <prod name="pi3web" vendor="pi3">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0277" seq="2003-0277" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105276130814262&amp;w=2">20030512 One more flaw in Happymall</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7559">7559</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11987">happymall-dotdot-directory-traversal(11987)</ref>
    </refs>
    <vuln_soft>
      <prod name="happymall" vendor="happycgi">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0278" seq="2003-0278" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105276130814262&amp;w=2">20030512 One more flaw in Happymall</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7557">7557</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11988">happymall-normalhtml-xss(11988)</ref>
    </refs>
    <vuln_soft>
      <prod name="happymall" vendor="happycgi.com">
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0279" seq="2003-0279" published="2003-06-16" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105276019312980&amp;w=2">20030512 Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7558">7558</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7588">7588</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11984">phpnuke-web-sql-injection(11984)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0280" seq="2003-0280" published="2003-06-16" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105258772101349&amp;w=2">20030510 Multiple Buffer Overflow Vulnerabilities Found in CMailServer 4.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7547">7547</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7548">7548</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11975">cmailserver-smtp-bo(11975)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmailserver" vendor="youngzsoft">
        <vers num="4.0.2003.23.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0281" seq="2003-0281" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105259012802997&amp;w=2">20030509 Firebird Local exploit</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2002/Jun/0212.html">20020617 Interbase 6.0 malloc() issues</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-18.xml">GLSA-200405-18</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7546">7546</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11977">firebird-interbase-bo(11977)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebird" vendor="firebirdsql">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0282" seq="2003-0282" published="2003-06-16" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-031.0.txt">CSSA-2003-031.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000672">CLA-2003:672</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-017-01">IMNX-2003-7+-017-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105259038503175&amp;w=2">20030509 unzip directory traversal revisited</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105786446329347&amp;w=2">20030710 [OpenPKG-SA-2003.033] OpenPKG Security Advisory (infozip)</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-111.shtml">N-111</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-344">DSA-344</ref>
      <ref source="CONFIRM" url="http://www.info-zip.org/FAQ.html">http://www.info-zip.org/FAQ.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:073">MDKSA-2003:073</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-199.html" adv="1" patch="1">RHSA-2003:199</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-200.html">RHSA-2003:200</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7550" adv="1" patch="1">7550</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-42.txt">TLSA-2003-42</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12004">unzip-dotdot-directory-traversal(12004)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A619">oval:org.mitre.oval:def:619</ref>
    </refs>
    <vuln_soft>
      <prod name="unzip" vendor="info-zip">
        <vers num="5.50"/>
      </prod>
      <prod name="openlinux_server" vendor="sco">
        <vers num="3.1.1"/>
      </prod>
      <prod name="openlinux_workstation" vendor="sco">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0283" seq="2003-0283" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "&lt;&lt;" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105251043821533&amp;w=2">20030509 A Phorum's bug...</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105251421925394&amp;w=2">20030509 Re: A Phorum's bug...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7545">7545</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11974">phorum-message-html-injection(11974)</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0284" seq="2003-0284" published="2003-06-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121" adv="1" patch="1">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/184820" adv="1" patch="1">VU#184820</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0285" seq="2003-0285" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105284689228961&amp;w=2">20030513 AIX sendmail open relay</ref>
      <ref source="MISC" url="http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt" adv="1">http://security.sdsc.edu/advisories/2003.05.13-AIX-sendmail.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/814617">VU#814617</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7580">7580</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11993">aix-sendmail-mail-relay(11993)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0286" seq="2003-0286" published="2003-06-16" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0067.html">20030512 Snitz Forum 3.3.03 Remote Command Execution</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105277599131134&amp;w=2">20030513 Snitz Forum 3.3.03 Remote Command Execution</ref>
      <ref source="MISC" url="http://packetstormsecurity.org/0305-exploits/snitz_exec.txt">http://packetstormsecurity.org/0305-exploits/snitz_exec.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/35764" patch="1">35764</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7549" patch="1">7549</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11981">snitz-register-sql-injection(11981)</ref>
    </refs>
    <vuln_soft>
      <prod name="snitz_forums_2000" vendor="snitz_communications">
        <vers num="3.3.03" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0287" seq="2003-0287" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105276879622636&amp;w=2">20030512 CSS found in Movable Type</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105277690132079&amp;w=2">20030512 Re: CSS found in Movable Type</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105284589927655&amp;w=2">20030513 Re: CSS found in Movable Type -- Nope</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7560">7560</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12003">movable-type-comment-xss(12003)</ref>
    </refs>
    <vuln_soft>
      <prod name="movable_type" vendor="six_apart">
        <vers num="2.6" prev="1"/>
        <vers num="2.63"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0288" seq="2003-0288" published="2003-06-16" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the file &amp; folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105283843417610&amp;w=2">20030513 [SNS Advisory No.64] IP Messenger for Win Buffer Overflow Vulnerability</ref>
      <ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/64_e.html" adv="1" patch="1">http://www.lac.co.jp/security/english/snsadv_e/64_e.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7566">7566</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11986">ip-messenger-filename-bo(11986)</ref>
    </refs>
    <vuln_soft>
      <prod name="ip_messenger" vendor="hiroaki_shirouzu">
        <vers num="2.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0289" seq="2003-0289" published="2003-06-16" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz">ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz</ref>
      <ref source="GENTOO" url="http://forums.gentoo.org/viewtopic.php?t=54904">200305-06</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105285564307225&amp;w=2">20030513 cdrtools2.0 Format String Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105286031812533&amp;w=2">20030513 Cdrecord_local_root_exploit.</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:058">MDKSA-2003:058</ref>
      <ref source="MISC" url="http://www.securiteam.com/exploits/5ZP0C2AAAC.html">http://www.securiteam.com/exploits/5ZP0C2AAAC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7565" adv="1" patch="1">7565</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12007">cdrtools-scsiopen-format-string(12007)</ref>
    </refs>
    <vuln_soft>
      <prod name="cdrecord" vendor="cdrtools">
        <vers num="1.11"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0290" seq="2003-0290" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0064.html">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105284630228137&amp;w=2">20030511 eServ Memory Leak Enables Denial of Service Attacks</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105284631428187&amp;w=2">20030513 eServ Memory Leak Solution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7552">7552</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11973">eserv-multiple-connections-dos(11973)</ref>
    </refs>
    <vuln_soft>
      <prod name="eserv" vendor="etype">
        <vers num="2.9x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0291" seq="2003-0291" published="2003-06-16" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105292451702516&amp;w=2">20030514 Memory leak in 3COM 812 DSL routers</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105301488426951&amp;w=2">20030515 RE : Memory leak in 3COM DSL routers</ref>
      <ref source="MISC" url="http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm" adv="1" patch="1">http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7592">7592</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11999">3com-officeconnect-memory-leak(11999)</ref>
    </refs>
    <vuln_soft>
      <prod name="3cp4144" vendor="3com">
        <vers num="1.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0292" seq="2003-0292" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105292750807005&amp;w=2">20030514 Inktomi Traffic-Server XSS: man-in-the-middle XSS !</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7596">7596</ref>
    </refs>
    <vuln_soft>
      <prod name="inktomi_traffic-server" vendor="inktomi">
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0293" seq="2003-0293" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105293128612131&amp;w=2">20030514 PalmOS ICMP flood DoS.</ref>
    </refs>
    <vuln_soft>
      <prod name="palmos" vendor="palm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0294" seq="2003-0294" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105293834421549&amp;w=2">20030514 php-proxima Remote File Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="php-proxima" vendor="php-proxima">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0295" seq="2003-0295" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105292832607981&amp;w=2">20030514 VBulletin Preview Message - XSS Vuln</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105293890422210&amp;w=2">20030514 Re: VBulletin Preview Message - XSS Vuln</ref>
    </refs>
    <vuln_soft>
      <prod name="vbulletin" vendor="jelsoft">
        <vers num="3.0.0_beta_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0296" seq="2003-0296" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="evolution" vendor="ximian">
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0297" seq="2003-0297" published="2003-06-16" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-015.html">RHSA-2005:015</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-114.html">RHSA-2005:114</ref>
      <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/430302/100/0/threaded">FLSA:184074</ref>
    </refs>
    <vuln_soft>
      <prod name="c-client" vendor="university_of_washington">
        <vers num=""/>
      </prod>
      <prod name="imap-2002b" vendor="university_of_washington">
        <vers num=""/>
      </prod>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0298" seq="2003-0298" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0299" seq="2003-0299" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="mutt" vendor="mutt">
        <vers num="1.4.1"/>
      </prod>
      <prod name="balsa" vendor="stuart_parmenter">
        <vers num="2.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0300" seq="2003-0300" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="6.00.2800.1106"/>
      </prod>
      <prod name="mozilla" vendor="mozilla">
        <vers num="1.3"/>
        <vers num="1.4" edition="alpha"/>
      </prod>
      <prod name="mutt" vendor="mutt">
        <vers num="1.4.1"/>
      </prod>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.2.1"/>
      </prod>
      <prod name="balsa" vendor="stuart_parmenter">
        <vers num="2.0.10"/>
      </prod>
      <prod name="sylpheed_email_client" vendor="sylpheed">
        <vers num="0.8.11"/>
      </prod>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.53"/>
      </prod>
      <prod name="evolution" vendor="ximian">
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0301" seq="2003-0301" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="6.00.2800.1106"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0302" seq="2003-0302" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294024124163&amp;w=2">20030514 Buffer overflows in multiple IMAP clients</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0303" seq="2003-0303" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" adv="1" patch="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105302025601231&amp;w=2">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7609">7609</ref>
    </refs>
    <vuln_soft>
      <prod name="oneorzero_helpdesk" vendor="oneorzero">
        <vers num="1.4_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0304" seq="2003-0304" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html" adv="1" patch="1">20030515 OneOrZero Security Problems (PHP)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105302025601231&amp;w=2">20030515 OneOrZero Security Problems (PHP)</ref>
    </refs>
    <vuln_soft>
      <prod name="oneorzero_helpdesk" vendor="oneorzero">
        <vers num="1.4_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0305" seq="2003-0305" published="2003-06-09" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030515-saa.shtml" adv="1" patch="1">20030515 Cisco Security Advisory: Cisco IOS Software Processing of SAA Packets</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5608">oval:org.mitre.oval:def:5608</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0(15)s"/>
        <vers num="12.0(15)sc"/>
        <vers num="12.0(15)sl"/>
        <vers num="12.0(16)s"/>
        <vers num="12.0(16)sc"/>
        <vers num="12.0(16)st"/>
        <vers num="12.0(17)s"/>
        <vers num="12.0(17)sl"/>
        <vers num="12.0(18)s"/>
        <vers num="12.0(18)sl"/>
        <vers num="12.0(19)s"/>
        <vers num="12.0(19)sl"/>
        <vers num="12.0(19)sp"/>
        <vers num="12.0(20)sl"/>
        <vers num="12.0(20)sp"/>
        <vers num="12.0(21)s"/>
        <vers num="12.0(21)sl"/>
        <vers num="12.0(21)sx"/>
        <vers num="12.1(8)ea"/>
        <vers num="12.1(9)ea"/>
        <vers num="12.1(10)"/>
        <vers num="12.1(10)e"/>
        <vers num="12.1(10)ec"/>
        <vers num="12.1(10)ex"/>
        <vers num="12.1(10)ey"/>
        <vers num="12.1(10.5)ec"/>
        <vers num="12.1(10a)"/>
        <vers num="12.1(11)"/>
        <vers num="12.1(11.5)e"/>
        <vers num="12.1(11a)"/>
        <vers num="12.1(11b)"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.1(12)"/>
        <vers num="12.1(12a)"/>
        <vers num="12.1(12b)"/>
        <vers num="12.1(12c)"/>
        <vers num="12.1(13)"/>
        <vers num="12.1(14)"/>
        <vers num="12.1(14.5)"/>
        <vers num="12.2(6.8a)"/>
        <vers num="12.2(7)"/>
        <vers num="12.2(7)da"/>
        <vers num="12.2(7a)"/>
        <vers num="12.2(7b)"/>
        <vers num="12.2(7c)"/>
        <vers num="12.2(9)s"/>
        <vers num="12.2(9.4)da"/>
        <vers num="12.2(10.5)s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0306" seq="2003-0306" published="2003-06-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105284486526310&amp;w=2">20030511 Detailed analysis: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105301349925036&amp;w=2">20030515 Re[2]: EXPLOIT: Buffer overflow in Explorer.exe on Windows XP SP1</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=105241032526289&amp;w=2">20030507 Buffer overflow in Explorer.exe</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-027">MS03-027</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3095">oval:org.mitre.oval:def:3095</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0307" seq="2003-0307" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105295155004969&amp;w=2">20030514 [VULNERABILITY] PHP 'poster version.two'</ref>
    </refs>
    <vuln_soft>
      <prod name="poster" vendor="poster">
        <vers num="version.two"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0308" seq="2003-0308" published="2003-05-15" modified="2008-11-11" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/496408">http://bugs.debian.org/496408</ref>
      <ref source="CONFIRM" url="http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base">http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-305" patch="1">DSA-305</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/10/30/2">[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire</ref>
      <ref source="CONFIRM" url="https://bugs.gentoo.org/show_bug.cgi?id=235770">https://bugs.gentoo.org/show_bug.cgi?id=235770</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.9.3"/>
        <vers num="8.12.3"/>
        <vers num="8.12.9"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0309" seq="2003-0309" published="2003-06-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105249399103214&amp;w=2">20030508 Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105294081325040&amp;w=2">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105294162726096&amp;w=2">20030513 Flooding Internet Explorer 6.0.2800 (6.x?) security zones  ! - UPDATED</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/251788">VU#251788</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7539">7539</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-020">MS03-020</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12019">ie-frame-restrictions-bypass(12019)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A948">oval:org.mitre.oval:def:948</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0.2800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0310" seq="2003-0310" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105310013606680&amp;w=2">20030516 EzPublish Directory XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="ez_publish" vendor="ez">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0312" seq="2003-0312" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod name="snowblind_web_server" vendor="snowblind.net">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0313" seq="2003-0313" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod name="snowblind_web_server" vendor="snowblind.net">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0314" seq="2003-0314" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "&lt;/" sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod name="snowblind_web_server" vendor="snowblind.net">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0315" seq="2003-0315" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105311719128173&amp;w=2">20030516 Snowblind Web Server: multiple issues</ref>
    </refs>
    <vuln_soft>
      <prod name="snowblind_web_server" vendor="snowblind.net">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0316" seq="2003-0316" published="2003-06-16" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0188.html" adv="1" patch="1">20030516 Venturi Client 2.1 confirmed as open relay [Verizon Wireless Mobile Office]</ref>
      <ref source="MISC" url="http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm" patch="1">http://www.venturiwireless.com/tech_support/Q_and_A/Q_A_09.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="venturi_client" vendor="fourelle_venturi_wireless">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0317" seq="2003-0317" published="2003-12-31" modified="2008-10-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=25">20030522 Authentication Bypass in iisPROTECT</ref>
    </refs>
    <vuln_soft>
      <prod name="iisprotect" vendor="iisprotect">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0318" seq="2003-0318" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105319538308834&amp;w=2">20030517 PHP-Nuke code injection in Yearly Stats at Statistics module</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0319" seq="2003-0319" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0072.html" adv="1" patch="1">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105319299407291&amp;w=2">20030517 Buffer overflow vulnerability found in MailMax version 5</ref>
    </refs>
    <vuln_soft>
      <prod name="mailmax" vendor="smartmax_software">
        <vers num="5.0.10.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0320" seq="2003-0320" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105320172212990&amp;w=2">20030517 Remote code execution in ttCMS &lt;=v2.3</ref>
    </refs>
    <vuln_soft>
      <prod name="ttcms" vendor="andy_prevost">
        <vers num="2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0321" seq="2003-0321" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655">CLA-2003:655</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2">20030313 Buffer overflows in ircII-based clients</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104852615211913&amp;w=2">20030324 GLSA:  bitchx (200303-21)</ref>
      <ref source="MISC" url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-306" adv="1" patch="1">DSA-306</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7096">7096</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7097">7097</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7099">7099</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7100">7100</ref>
    </refs>
    <vuln_soft>
      <prod name="bitchx" vendor="colten_edwards">
        <vers num="1.0.0c19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0322" seq="2003-0322" published="2003-06-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz" patch="1">http://security.debian.org/pool/updates/main/i/ircii-pana/ircii-pana_1.0-0c16-2.1.diff.gz</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-306" adv="1" patch="1">DSA-306</ref>
    </refs>
    <vuln_soft>
      <prod name="bitchx" vendor="colten_edwards">
        <vers num="1.0.0c19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0323" seq="2003-0323" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2">20030313 Buffer overflows in ircII-based clients</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104808915402926&amp;w=2">20030319 [OpenPKG-SA-2003.024] OpenPKG Security Advisory (ircii)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-291" adv="1" patch="1">DSA-291</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-298">DSA-298</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7098">7098</ref>
    </refs>
    <vuln_soft>
      <prod name="ircii" vendor="michael_sandrof">
        <vers num="2002-09-12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0324" seq="2003-0324" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104766521328322&amp;w=2">20030313 Buffer overflows in ircII-based clients</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-287" adv="1" patch="1">DSA-287</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7091">7091</ref>
    </refs>
    <vuln_soft>
      <prod name="epic4" vendor="epic">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0325" seq="2003-0325" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105337792703887&amp;w=2">20030518 Maelstrom Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105344501331344&amp;w=2">20030519 Maelstrom exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105346309123217&amp;w=2">20030520 Maelstrom Local Buffer Overflow Exploit, FreeBSD 4.8 edition</ref>
    </refs>
    <vuln_soft>
      <prod name="maelstrom" vendor="ambrosia_software">
        <vers num="3.0.5" prev="1"/>
        <vers num="3.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0326" seq="2003-0326" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105337692202626&amp;w=2">20030519 bazarr slocate</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7629">7629</ref>
    </refs>
    <vuln_soft>
      <prod name="slocate" vendor="slocate">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0327" seq="2003-0327" published="2003-12-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106936096103805&amp;w=2">20031120 R7-0016: Sybase ASE 12.5 Remote Password Array Denial of Service</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0016.html" adv="1" patch="1">http://www.rapid7.com/advisories/R7-0016.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13800">sybase-passwordarray-bo(13800)</ref>
    </refs>
    <vuln_soft>
      <prod name="adaptive_server_enterprise" vendor="sybase">
        <vers num="12.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0328" seq="2003-0328" published="2003-06-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1" adv="1" patch="1">ftp://ftp.prbh.org/pub/epic/patches/alloca_underrun-patch-1</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-306">DSA-306</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-399">DSA-399</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-342.html">RHSA-2003:342</ref>
    </refs>
    <vuln_soft>
      <prod name="epic4" vendor="epic">
        <vers num="pre2.002"/>
        <vers num="pre2.003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0329" seq="2003-0329" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0074.html" adv="1">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105344578100315&amp;w=2">20030520 Plaintext Password in Settings.ini of CesarFTP</ref>
    </refs>
    <vuln_soft>
      <prod name="cesarftp" vendor="aclogic">
        <vers num="0.99g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0330" seq="2003-0330" published="2003-06-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105344891005369&amp;w=2">20030520 Maelstrom Local Buffer Overflow Exploit</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008832">1008832</ref>
    </refs>
    <vuln_soft>
      <prod name="maelstrom" vendor="ambrosia_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0331" seq="2003-0331" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105345273210334&amp;w=2">20030520 More vulnerabilities in ttForum/ttCMS -> SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod name="ttforum" vendor="ttcms">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0332" seq="2003-0332" published="2003-06-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html" adv="1" patch="1">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105346382524169&amp;w=2">20030520 BadBlue Remote Administrative Interface Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="badblue" vendor="working_resources_inc.">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0333" seq="2003-0333" published="2003-05-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105189670912220&amp;w=2">20030502 HP-UX 11.0 /usr/bin/kermit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105190667523456&amp;w=2">20030502 Re: from bugtraq: HP-UX 11.0 /usr/bin/kermit (fwd)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/971364" adv="1">VU#971364</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7627" adv="1">7627</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11929">hp-ckermit-bo(11929)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0334" seq="2003-0334" published="2003-05-10" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" adv="1" patch="1">CLA-2003:655</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105259643606984&amp;w=2">20030510 BitchX: Crash when channel modes change</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:069">MDKSA-2003:069</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7551">7551</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12008">bitchx-mode-change-dos(12008)</ref>
    </refs>
    <vuln_soft>
      <prod name="bitchx" vendor="colten_edwards">
        <vers num="1.0c20cvs" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0335" seq="2003-0335" published="2003-05-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105361968110719&amp;w=2">20030522 [slackware-security]  quotacheck security fix in rc.M (SSA:2003-141-06)</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0336" seq="2003-0336" published="2003-05-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105362278914731&amp;w=2">20030522 Eudora 5.2.1 attachment spoof</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0337" seq="2003-0337" published="2003-05-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105361879109409&amp;w=2">20030522 Security advisory: LSF 5.1 local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="lsadmin" vendor="platform">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0338" seq="2003-0338" published="2003-05-21" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0077.html" adv="1">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105353168619211&amp;w=2">20030521 [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="wsmp3_daemon" vendor="wsmp3">
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
        <vers num="0.0.10"/>
      </prod>
      <prod name="wsmp3_web_server" vendor="wsmp3">
        <vers num="0.0.1"/>
        <vers num="0.0.2"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0339" seq="2003-0339" published="2003-05-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://marc.info/?l=bugtraq&amp;m=105353178019353&amp;w=2">20030521 Remote Heap Corruption Overflow vulnerability in WsMp3d.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105361764807746&amp;w=2">20030522 WsMp3d remote exploit.</ref>
    </refs>
    <vuln_soft>
      <prod name="wsmp3_daemon" vendor="wsmp3">
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
        <vers num="0.0.10"/>
      </prod>
      <prod name="wsmp3_web_server" vendor="wsmp3">
        <vers num="0.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0340" seq="2003-0340" published="2003-05-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0230.html" adv="1">20030521 Demarc Puresecure v1.6 - Plaintext password issue -</ref>
    </refs>
    <vuln_soft>
      <prod name="puresecure" vendor="demarc_security">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0341" seq="2003-0341" published="2003-05-21" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105353266220520&amp;w=2">20030521 [AP] Owl Intranet Engine CSS Bug</ref>
    </refs>
    <vuln_soft>
      <prod name="owl_intranet_engine" vendor="owl">
        <vers num="0.7"/>
        <vers num="0.71"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0342" seq="2003-0342" published="2003-05-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105353283720837&amp;w=2">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod name="blackmoon_ftp_server" vendor="selom_ofori">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0343" seq="2003-0343" published="2003-05-21" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105353283720837&amp;w=2">20030520 [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords and User enumeration</ref>
    </refs>
    <vuln_soft>
      <prod name="blackmoon_ftp_server" vendor="selom_ofori">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0344" seq="2003-0344" published="2003-06-16" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006401.html">20030709 IE Object Type Overflow Exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105476381609135&amp;w=2">20030604 Internet Explorer Object Type Property Overflow</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20030604.html" adv="1" patch="1">AD20030604</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/679556">VU#679556</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-020">MS03-020</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A922">oval:org.mitre.oval:def:922</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6.0" edition=":windows_server_2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0345" seq="2003-0345" published="2003-08-18" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007154">1007154</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/337764">VU#337764</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8152" adv="1" patch="1">8152</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-024">MS03-024</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12544">win-smb-bo(12544)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A118">oval:org.mitre.oval:def:118</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A146">oval:org.mitre.oval:def:146</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3391">oval:org.mitre.oval:def:3391</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":terminal_server_alpha"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0346" seq="2003-0346" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105899759824008&amp;w=2">20030723 EEYE: Windows MIDI Decoder (QUARTZ.DLL) Heap Corruption</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-18.html" adv="1" patch="1">CA-2003-18</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/265232">VU#265232</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/561284">VU#561284</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-030">MS03-030</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1095">oval:org.mitre.oval:def:1095</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1104">oval:org.mitre.oval:def:1104</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A218">oval:org.mitre.oval:def:218</ref>
    </refs>
    <vuln_soft>
      <prod name="directx" vendor="microsoft">
        <vers num="5.2"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.0a"/>
        <vers num="8.1"/>
        <vers num="9.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0347" seq="2003-0347" published="2003-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0093.html">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106262077829157&amp;w=2">20030903 EEYE: VBE Document Property Buffer Overflow</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/804780">VU#804780</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8534" adv="1" patch="1">8534</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-037">MS03-037</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="xp" edition="sp1"/>
        <vers num="xp" edition="sp2"/>
      </prod>
      <prod name="project" vendor="microsoft">
        <vers num="2000"/>
        <vers num="2002"/>
      </prod>
      <prod name="visio" vendor="microsoft">
        <vers num="2002" edition=":professional"/>
      </prod>
      <prod name="visual_basic" vendor="microsoft">
        <vers num="5.0" edition=":sdk"/>
        <vers num="6.2" edition=":sdk"/>
        <vers num="6.3" edition=":sdk"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0348" seq="2003-0348" published="2003-07-24" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/320516">VU#320516</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8034">8034</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-021">MS03-021</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12440">mediaplayer-activex-obtain-information(12440)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0349" seq="2003-0349" published="2003-07-24" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105665030925504&amp;w=2">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007059">1007059</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/113716">VU#113716</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0306&amp;L=NTBUGTRAQ&amp;P=R4563" adv="1" patch="1">20030626 Windows Media Services Remote Command Execution #2</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-022">MS03-022</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A938">oval:org.mitre.oval:def:938</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0350" seq="2003-0350" published="2003-08-18" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0015.html" adv="1" patch="1">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105777681615939&amp;w=2">20030709 Microsoft Utility Manager Local Privilege Escalation</ref>
      <ref source="MISC" url="http://www.ngssoftware.com/advisories/utilitymanager.txt" adv="1" patch="1">http://www.ngssoftware.com/advisories/utilitymanager.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8154">8154</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-025">MS03-025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12543">win2k-accessibility-gain-privileges(12543)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A451">oval:org.mitre.oval:def:451</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0351" seq="2003-0351" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0306.  Reason: This candidate is a reservation duplicate of CVE-2003-0306.  Notes: All CVE users should reference CVE-2003-0306 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0352" seq="2003-0352" published="2003-08-18" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007079.html">20030726 Re: The French BUGTRAQ (New Win RPC Exploit)</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007357.html">20030730 rpcdcom Universal offsets</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105838687731618&amp;w=2">20030716 [LSD] Critical security vulnerability in Microsoft Operating Systems</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105914789527294&amp;w=2">20030725 The  Analysis  of LSD's Buffer Overrun in Windows RPC Interface(code revised )</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-16.html">CA-2003-16</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-19.html">CA-2003-19</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/568148">VU#568148</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8205" adv="1" patch="1">8205</ref>
      <ref source="MISC" url="http://www.xfocus.org/documents/200307/2.html">http://www.xfocus.org/documents/200307/2.html</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-026">MS03-026</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12629">win-rpc-dcom-bo(12629)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A194">oval:org.mitre.oval:def:194</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2343">oval:org.mitre.oval:def:2343</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A296">oval:org.mitre.oval:def:296</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0353" seq="2003-0353" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106149556627778&amp;w=2">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106251069107953&amp;w=2">20030821 AppSecInc Security Alert: Buffer Overflow in UDP broadcasts for Microsoft SQL Server client utilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8455">8455</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-033">MS03-033</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1039">oval:org.mitre.oval:def:1039</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6954">oval:org.mitre.oval:def:6954</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A961">oval:org.mitre.oval:def:961</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A962">oval:org.mitre.oval:def:962</ref>
    </refs>
    <vuln_soft>
      <prod name="data_access_components" vendor="microsoft">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1.3711.11" edition="ga"/>
        <vers num="2.5" edition="gold"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5" edition="sp2"/>
        <vers num="2.6" edition="gold"/>
        <vers num="2.6" edition="sp1"/>
        <vers num="2.6" edition="sp2"/>
        <vers num="2.7" edition="gold"/>
        <vers num="2.12.4202.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0354" seq="2003-0354" published="2003-06-16" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105465818929172&amp;w=2">20030603 [OpenPKG-SA-2003.030] OpenPKG Security Advisory (ghostscript)</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:065">MDKSA-2003:065</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-181.html" adv="1" patch="1">RHSA-2003:181</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-182.html">RHSA-2003:182</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A133">oval:org.mitre.oval:def:133</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0355" seq="2003-0355" published="2003-06-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320707">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
    </refs>
    <vuln_soft>
      <prod name="safari" vendor="apple">
        <vers num="1.0"/>
      </prod>
      <prod name="konqueror_embedded" vendor="kde">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0356" seq="2003-0356" published="2003-06-09" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-313" adv="1" patch="1">DSA-313</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641013">VU#641013</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067">MDKSA-2003:067</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69">oval:org.mitre.oval:def:69</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0357" seq="2003-0357" published="2003-06-09" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-313" adv="1" patch="1">DSA-313</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00009.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00009.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/232164">VU#232164</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/361700">VU#361700</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:067">MDKSA-2003:067</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7494">7494</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7495">7495</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A73">oval:org.mitre.oval:def:73</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0358" seq="2003-0358" published="2003-06-09" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nethack.sourceforge.net/v340/bugmore/secpatch.txt">http://nethack.sourceforge.net/v340/bugmore/secpatch.txt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-316">DSA-316</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-350">DSA-350</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0">20030209 #!ICadv-02.09.03: nethack 3.4.0 local buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6806">6806</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11283">nethack-s-command-bo(11283)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0359" seq="2003-0359" published="2003-07-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-316" adv="1" patch="1">DSA-316</ref>
    </refs>
    <vuln_soft>
      <prod name="nethack" vendor="stichting_mathematisch_centrum">
        <vers num="3.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0360" seq="2003-0360" published="2003-06-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://gps.seul.org/changelog.html" patch="1">http://gps.seul.org/changelog.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-307" adv="1" patch="1">DSA-307</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0361" seq="2003-0361" published="2003-06-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://gps.seul.org/changelog.html" patch="1">http://gps.seul.org/changelog.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-307" adv="1" patch="1">DSA-307</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0362" seq="2003-0362" published="2003-06-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://gps.seul.org/changelog.html">http://gps.seul.org/changelog.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-307">DSA-307</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="0.9.1" edition=":woody_gps_package"/>
        <vers num="0.9.2" edition=":woody_gps_package"/>
        <vers num="0.9.3" edition=":woody_gps_package"/>
        <vers num="0.9.4" edition=":woody_gps_package"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0363" seq="2003-0363" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf" adv="1">http://csdl.computer.org/comp/proceedings/hicss/2004/2056/09/205690277.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="licq" vendor="licq">
        <vers num="1.0.3"/>
        <vers num="1.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0364" seq="2003-0364" published="2003-06-16" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311" adv="1" patch="1">DSA-311</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-187.html" adv="1" patch="1">RHSA-2003:187</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-195.html">RHSA-2003:195</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-41.txt" adv="1">TLSA-2003-41</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A295">oval:org.mitre.oval:def:295</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0365" seq="2003-0365" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105427404625027&amp;w=2">20030529 ICQLite executable trojaning</ref>
    </refs>
    <vuln_soft>
      <prod name="icqlite" vendor="icq_inc">
        <vers num="2003a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0366" seq="2003-0366" published="2003-07-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-318" adv="1" patch="1">DSA-318</ref>
    </refs>
    <vuln_soft>
      <prod name="lyskom-server" vendor="lysator">
        <vers num="2.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0367" seq="2003-0367" published="2003-07-02" modified="2019-05-23" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308" adv="1" patch="1">DSA-308</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:068" adv="1">MDKSA-2003:068</ref>
      <ref source="CONFIRM" url="http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html" adv="1" patch="1">http://www.openpkg.org/security/OpenPKG-SA-2003.031-gzip.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7872" adv="1">7872</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-38.txt" adv="1" patch="1">TLSA-2003-38</ref>
    </refs>
    <vuln_soft>
      <prod name="gzip" vendor="gnu">
        <vers num="1.3.5" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0368" seq="2003-0368" published="2004-02-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a060903-1.txt">A060903-1</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/924812" adv="1" patch="1">VU#924812</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7854" adv="1">7854</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12221">nokia-ggsn-ip-dos(12221)</ref>
    </refs>
    <vuln_soft>
      <prod name="ggsn" vendor="nokia">
        <vers num="release_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0370" seq="2003-0370" published="2003-06-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/004983.html">20030510 [forward]Apple Safari and Konqueror Embedded Common Name Verification Vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-361">DSA-361</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20030602-1.txt" adv="1" patch="1">http://www.kde.org/info/security/advisory-20030602-1.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-192.html" adv="1" patch="1">RHSA-2003:192</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-193.html">RHSA-2003:193</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320707" adv="1">20030507 Problem: Multiple Web Browsers do not do not validate CN on certificates.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7520">7520</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-36.txt">TLSA-2003-36</ref>
    </refs>
    <vuln_soft>
      <prod name="safari" vendor="apple">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
      </prod>
      <prod name="konqueror_embedded" vendor="kde">
        <vers num="0.1"/>
      </prod>
      <prod name="kde" vendor="kde">
        <vers num="2.2.2" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="turbolinux_server" vendor="turbolinux">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
      <prod name="turbolinux_workstation" vendor="turbolinux">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0371" seq="2003-0371" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105370592729044&amp;w=2">20030522 Prishtina FTP v.1.*: remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="prishtina_ftp" vendor="prishtina_soft">
        <vers num="v.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0372" seq="2003-0372" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2">20030522 Potential security vulnerability in Nessus</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105369506714849&amp;w=2">20030523 nessus NASL scripting engine security issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7664">7664</ref>
    </refs>
    <vuln_soft>
      <prod name="nessus" vendor="nessus">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0373" seq="2003-0373" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2">20030522 Potential security vulnerability in Nessus</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105369506714849&amp;w=2">20030523 nessus NASL scripting engine security issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7664">7664</ref>
    </refs>
    <vuln_soft>
      <prod name="nessus" vendor="nessus">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0374" seq="2003-0374" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105364059803427&amp;w=2">20030522 Potential security vulnerability in Nessus</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7664">7664</ref>
    </refs>
    <vuln_soft>
      <prod name="nessus" vendor="nessus">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0375" seq="2003-0375" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://forums.xmbforum.com/viewthread.php?tid=773046">http://forums.xmbforum.com/viewthread.php?tid=773046</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105363936402228&amp;w=2">20030522 XMB 1.8 Partagium cross site scripting vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7662">7662</ref>
    </refs>
    <vuln_soft>
      <prod name="xmb" vendor="xmb_forum">
        <vers num="1.6"/>
        <vers num="1.8"/>
        <vers num="1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0376" seq="2003-0376" published="2003-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105370625529452&amp;w=2">20030523 Eudora 5.2.1 buffer overflow DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0377" seq="2003-0377" published="2003-06-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105370528728225&amp;w=2">20030523 iisPROTECT SQL injection in admin interface</ref>
    </refs>
    <vuln_soft>
      <prod name="iisprotect" vendor="iisprotect">
        <vers num="2.2_r4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0378" seq="2003-0378" published="2003-06-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=107579">http://docs.info.apple.com/article.html?artnum=107579</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/467828" adv="1" patch="1">VU#467828</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0379" seq="2003-0379" published="2003-07-24" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote attackers to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00030.html" adv="1" patch="1">http://lists.apple.com/mhonarc/security-announce/msg00030.html</ref>
    </refs>
    <vuln_soft>
      <prod name="afp_server" vendor="apple">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0380" seq="2003-0380" published="2003-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0056.html" adv="1" patch="1">20030606 atftpd bug</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-314" adv="1" patch="1">DSA-314</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/323886/2003-06-02/2003-06-08/0" adv="1">20030604 possible remote buffer overflow in atftpd</ref>
    </refs>
    <vuln_soft>
      <prod name="atftpd" vendor="atftpd">
        <vers num="0.6.0"/>
        <vers num="0.6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0381" seq="2003-0381" published="2003-07-24" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-323" adv="1" patch="1">DSA-323</ref>
    </refs>
    <vuln_soft>
      <prod name="noweb" vendor="norman_ramsey">
        <vers num="2.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0382" seq="2003-0382" published="2003-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105427580626001&amp;w=2">20030509 BAZARR CODE NINER PINK TEAM GO GO GO</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-309" adv="1" patch="1">DSA-309</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7708">7708</ref>
    </refs>
    <vuln_soft>
      <prod name="eterm" vendor="michael_jennings">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.3"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0385" seq="2003-0385" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105491469815197&amp;w=2">20030605 BAZARR LOCAL ROOT AGAIN. HI GUYS. DONT READ THIS</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-310" adv="1" patch="1">DSA-310</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0.18" edition=":potato"/>
        <vers num="3.0.23" edition=":woody"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0386" seq="2003-0386" published="2003-07-02" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc">20060703-01-P</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/978316" adv="1" patch="1">VU#978316</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0298.html">RHSA-2006:0298</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0698.html">RHSA-2006:0698</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324016/2003-06-03/2003-06-09/0" adv="1" patch="1">20030605 OpenSSH remote clent address restriction circumvention</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7831">7831</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9894">oval:org.mitre.oval:def:9894</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0388" seq="2003-0388" published="2003-07-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105577915506761&amp;w=2">20030616 FW: iDEFENSE Security Advisory 06.16.03: Linux-PAM getlogin() Spoofing</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/06.16.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/06.16.03.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-304.html">RHSA-2004:304</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_pam" vendor="andrew_morgan">
        <vers num="0.77" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0389" seq="2003-0389" published="2003-07-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0112.html" adv="1" patch="1">20030619 R7-0014: RSA SecurID ACE Agent Cross Site Scripting</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0014.html" adv="1" patch="1">http://www.rapid7.com/advisories/R7-0014.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ace_agent" vendor="rsa">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0390" seq="2003-0390" published="2003-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105121918523320&amp;w=2">20030424 SRT2003-04-24-1532 -  Options Parsing Tool library buffer overflows.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105371246204866&amp;w=2">20030523 Re: Options Parsing Tool library buffer overflows.</ref>
      <ref source="CONFIRM" url="http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz" patch="1">http://nis-www.lanl.gov/~jt/Software/opt/opt-3.19.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="opt" vendor="james_theiler">
        <vers num="3.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0391" seq="2003-0391" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105370528428222&amp;w=2">20030523 Magic Winmail Server</ref>
      <ref source="MISC" url="http://www.magicwinmail.net/changelog.asp">http://www.magicwinmail.net/changelog.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="magic_winmail_server" vendor="amax_information_technologies">
        <vers num="2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0392" seq="2003-0392" published="2003-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105372353017778&amp;w=2">20030523 ST FTP Service v3.0: directory traversal</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_service" vendor="st">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0393" seq="2003-0393" published="2003-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105380229532320&amp;w=2">20030524 Some problems in Privatefirewall 3.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7700">7700</ref>
    </refs>
    <vuln_soft>
      <prod name="privatefirewall" vendor="privacyware">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0394" seq="2003-0394" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105379530927567&amp;w=2">20030524 PHP source code injection in BLNews</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7677">7677</ref>
    </refs>
    <vuln_soft>
      <prod name="blnews" vendor="blnews">
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0395" seq="2003-0395" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://f0kp.iplus.ru/bz/024.en.txt">http://f0kp.iplus.ru/bz/024.en.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105379741528925&amp;w=2">20030524 UPB: Discussion Board/Web-Site Takeover</ref>
    </refs>
    <vuln_soft>
      <prod name="ultimate_php_board_upb" vendor="php_outburst">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0396" seq="2003-0396" published="2003-07-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105154433926396&amp;w=2">20030428 ATM  on Linux Exploit Code Release (les, local)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405560021979&amp;w=2">20030524 ATM on linux Exploit(les,local)</ref>
      <ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=156242" patch="1">http://sourceforge.net/project/shownotes.php?release_id=156242</ref>
      <ref source="MISC" url="http://www.securiteam.com/exploits/5EP0M1P9PO.html">http://www.securiteam.com/exploits/5EP0M1P9PO.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7437">7437</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11903">atmonlinux-les-command-bo(11903)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux-atm" vendor="linux-atm">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0397" seq="2003-0397" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405708923565&amp;w=2">20030526 The PACKET 0' DEATH FastTrack network vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12086.php">fastrack-packet-0-bo(12086)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7680">7680</ref>
    </refs>
    <vuln_soft>
      <prod name="kazaa" vendor="sharman_networks">
        <vers num="v2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0398" seq="2003-0398" published="2003-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405734223874&amp;w=2">20030526 S21SEC-016 - Vignette SSI Injection</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12077.php" adv="1" patch="1">vignette-ssi-command-execution(12077)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-016-en.txt" adv="1" patch="1">http://www.s21sec.com/es/avisos/s21sec-016-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7685" adv="1" patch="1">7685</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0399" seq="2003-0399" published="2003-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405874325673&amp;w=2">20030526 S21SEC-017 - Vignette /vgn/legacy/save SQL access</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12076.php" adv="1" patch="1">vignette-save-obtain-information(12076)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-017-en.txt" adv="1" patch="1">http://www.s21sec.com/es/avisos/s21sec-017-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7683">7683</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0400" seq="2003-0400" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405985126857&amp;w=2">20030526 S21SEC-018 - Vignette memory leak AIX Platform</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12075.php" adv="1" patch="1">vignette-memory-leak(12075)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-018-en.txt" adv="1">http://www.s21sec.com/es/avisos/s21sec-018-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7684" adv="1">7684</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="6.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0401" seq="2003-0401" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405793324661&amp;w=2">20030526 S21SEC-019 - Vignette /vgn/style internal information leak</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12074.php" adv="1">vignette-style-info-disclosure(12074)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-019-en.txt" adv="1">http://www.s21sec.com/es/avisos/s21sec-019-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7688" adv="1">7688</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0402" seq="2003-0402" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405880325755&amp;w=2">20030526 S21SEC-020 - Vignette user enumeration</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12073.php" adv="1">vignette-login-account-bruteforce(12073)</ref>
      <ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-020-en.txt" adv="1" patch="1">http://www.s21sec.com/en/avisos/s21sec-020-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7691" adv="1">7691</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0403" seq="2003-0403" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405789924612&amp;w=2">20030526 S21SEC-021 - Vignette License access and modification</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12072.php" adv="1">vignette-license-modification(12072)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-021-en.txt" adv="1" patch="1">http://www.s21sec.com/es/avisos/s21sec-021-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7694" adv="1">7694</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0404" seq="2003-0404" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105406028027360&amp;w=2">20030526 S21SEC-023 -  Vignette multiple Cross Site Scripting vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12071.php" adv="1">vignette-multiple-xss(12071)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-023-en.txt" adv="1">http://www.s21sec.com/es/avisos/s21sec-023-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7687" adv="1" patch="1">7687</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0405" seq="2003-0405" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405922826197&amp;w=2">20030526 S21SEC-024 - Vignette TCL Injection</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12070.php" adv="1">vignette-tcl-code-execution(12070)</ref>
      <ref source="MISC" url="http://www.s21sec.com/es/avisos/s21sec-024-en.txt" adv="1" patch="1">http://www.s21sec.com/es/avisos/s21sec-024-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7690" adv="1" patch="1">7690</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7692" adv="1" patch="1">7692</ref>
    </refs>
    <vuln_soft>
      <prod name="content_suite" vendor="vignette">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="storyserver" vendor="vignette">
        <vers num="5.0"/>
      </prod>
      <prod name="vignette" vendor="vignette">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0406" seq="2003-0406" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405691423389&amp;w=2">20030526 PalmVNC 1.40 Insecure Records</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12083.php" adv="1">palmvnc-plaintext-passwords(12083)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7696" adv="1">7696</ref>
    </refs>
    <vuln_soft>
      <prod name="palmvnc" vendor="palmvnc">
        <vers num="1.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0407" seq="2003-0407" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405668423102&amp;w=2">20030526 [Priv8security_Advisory]_Batalla_Naval_remote_overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12087.php" adv="1">batalla-naval-bo(12087)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7699" adv="1">7699</ref>
    </refs>
    <vuln_soft>
      <prod name="batalla_naval" vendor="gnome">
        <vers num="1.0_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0408" seq="2003-0408" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405629622652&amp;w=2">20030527 NuxAcid#002 - Buffer Overflow in UpClient</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12131.php" adv="1" patch="1">upclient-command-line-bo(12131)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7703" adv="1" patch="1">7703</ref>
    </refs>
    <vuln_soft>
      <prod name="upclient" vendor="the_uptimes_project">
        <vers num="5.0b7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0409" seq="2003-0409" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105405836025160&amp;w=2">20030527 BRS WebWeaver: POST and HEAD Overflaws</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12107.php" adv="1">webweaver-head-post-bo(12107)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7695" adv="1">7695</ref>
    </refs>
    <vuln_soft>
      <prod name="webweaver" vendor="brs">
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0410" seq="2003-0410" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0082.html" adv="1" patch="1">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105406759403978&amp;w=2">20030526 NII Advisory - Buffer Overflow in Analogx Proxy</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm" adv="1">http://www.analogx.com/contents/download/network/proxy.htm</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12068.php" adv="1" patch="1">analogx-proxy-url-bo(12068)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7681" adv="1" patch="1">7681</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy" vendor="analogx">
        <vers num="4.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0411" seq="2003-0411" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" adv="1" patch="1">55221</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1">1000610</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-103.shtml" adv="1" patch="1">N-103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12093.php" adv="1" patch="1">sunone-jsp-source-disclosure(12093)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7709" adv="1" patch="1">7709</ref>
      <ref source="MISC" url="http://www.spidynamics.com/sunone_alert.html">http://www.spidynamics.com/sunone_alert.html</ref>
    </refs>
    <vuln_soft>
      <prod name="one_application_server" vendor="sun">
        <vers num="7.0" edition=":platform"/>
        <vers num="7.0" edition=":standard"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0412" seq="2003-0412" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" adv="1" patch="1">55221</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1">1000610</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-103.shtml" adv="1" patch="1">N-103</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7711" adv="1" patch="1">7711</ref>
      <ref source="MISC" url="http://www.spidynamics.com/sunone_alert.html">http://www.spidynamics.com/sunone_alert.html</ref>
    </refs>
    <vuln_soft>
      <prod name="one_application_server" vendor="sun">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0413" seq="2003-0413" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" adv="1" patch="1">55221</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57605">57605</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201009-1">201009</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1">1000610</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-103.shtml" adv="1" patch="1">N-103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12095.php" adv="1" patch="1">sunone-http-error-xss(12095)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7710" adv="1" patch="1">7710</ref>
      <ref source="MISC" url="http://www.spidynamics.com/sunone_alert.html">http://www.spidynamics.com/sunone_alert.html</ref>
    </refs>
    <vuln_soft>
      <prod name="one_application_server" vendor="sun">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0414" seq="2003-0414" published="2003-06-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105409846029475&amp;w=2">20030526 Multiple Vulnerabilities in Sun-One Application Server</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&amp;zone_32=category%3Asecurity" adv="1">55221</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1">1000610</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-103.shtml" adv="1">N-103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12096.php" adv="1">sunone-insecure-file-permissions(12096)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7712" adv="1">7712</ref>
      <ref source="MISC" url="http://www.spidynamics.com/sunone_alert.html">http://www.spidynamics.com/sunone_alert.html</ref>
    </refs>
    <vuln_soft>
      <prod name="one_application_server" vendor="sun">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0415" seq="2003-0415" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105417988811698&amp;w=2">20030528 Remote PC Access Server  2.2 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7698" adv="1" patch="1">7698</ref>
      <ref source="MISC" url="http://www.ytech.co.il/advisories/rpca/rpcaccess.htm" adv="1" patch="1">http://www.ytech.co.il/advisories/rpca/rpcaccess.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="remote_pc_access" vendor="access-remote-pc.com">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0416" seq="2003-0416" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105418152212771&amp;w=2">20030528 Bandmin 1.4 XSS Exploit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12108.php" adv="1">bandmin-index-xss(12108)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7729" adv="1">7729</ref>
    </refs>
    <vuln_soft>
      <prod name="bandmin" vendor="bandmin">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0417" seq="2003-0417" published="2003-06-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105417983711685&amp;w=2">20030529 Son hServer v0.2: directory traversal</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/12103.php" adv="1">sonhserver-pipe-directory-traversal(12103)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7717" adv="1">7717</ref>
    </refs>
    <vuln_soft>
      <prod name="son_hserver" vendor="super-m">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0418" seq="2003-0418" published="2003-07-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105519179005065&amp;w=2">20030609 Linux 2.0 remote info leak from too big icmp citation</ref>
      <ref source="MISC" url="http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt" adv="1" patch="1">http://www.cartel-securite.fr/pbiondi/adv/CARTSA-20030314-icmpleak.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/471084" adv="1" patch="1">VU#471084</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0419" seq="2003-0419" published="2003-07-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.idefense.com/advisory/06.11.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/06.11.03.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="barricade_wireless_cable_dsl_broadband_router" vendor="smc_networks">
        <vers num="smc7004vwbr"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0420" seq="2003-0420" published="2003-06-13" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3165" adv="1" patch="1">ESB-2003.0415</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/JPLA-5NTL8E" adv="1" patch="1">http://www.kb.cert.org/vuls/id/JPLA-5NTL8E</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7894" adv="1" patch="1">7894</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12342">macos-dsimportexport-obtain-information(12342)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0421" seq="2003-0421" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0422" seq="2003-0422" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0423" seq="2003-0423" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0424" seq="2003-0424" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0425" seq="2003-0425" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0426" seq="2003-0426" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0427" seq="2003-0427" published="2003-07-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-320" adv="1" patch="1">DSA-320</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-506.html">RHSA-2005:506</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10194">oval:org.mitre.oval:def:10194</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A647">oval:org.mitre.oval:def:647</ref>
    </refs>
    <vuln_soft>
      <prod name="mikmod" vendor="miod_vallat">
        <vers num="3.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0428" seq="2003-0428" published="2003-07-24" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt">CSSA-2003-030.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662">CLA-2003:662</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-324" adv="1" patch="1">DSA-324</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/542540">VU#542540</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A75">oval:org.mitre.oval:def:75</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0429" seq="2003-0429" published="2003-07-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt">CSSA-2003-030.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662">CLA-2003:662</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-324" adv="1" patch="1">DSA-324</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A84">oval:org.mitre.oval:def:84</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0430" seq="2003-0430" published="2003-07-24" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt">CSSA-2003-030.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662">CLA-2003:662</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A88">oval:org.mitre.oval:def:88</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0431" seq="2003-0431" published="2003-07-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt">CSSA-2003-030.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662">CLA-2003:662</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-324" adv="1" patch="1">DSA-324</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A101">oval:org.mitre.oval:def:101</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0432" seq="2003-0432" published="2003-07-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-030.0.txt">CSSA-2003-030.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000662">CLA-2003:662</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-324" adv="1" patch="1">DSA-324</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00010.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00010.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A106">oval:org.mitre.oval:def:106</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0433" seq="2003-0433" published="2003-07-24" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-315" adv="1" patch="1">DSA-315</ref>
    </refs>
    <vuln_soft>
      <prod name="gnocatan" vendor="gnocatan-develop">
        <vers num="0.6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0434" seq="2003-0434" published="2003-07-24" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005719.html">20030613 -10Day CERT Advisory on PDF Files</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105777963019186&amp;w=2">20030709 xpdf vulnerability - CAN-2003-0434</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/200132">VU#200132</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:071">MDKSA-2003:071</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-196.html" adv="1" patch="1">RHSA-2003:196</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-197.html" adv="1" patch="1">RHSA-2003:197</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A664">oval:org.mitre.oval:def:664</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="5.0.6"/>
      </prod>
      <prod name="xpdf" vendor="xpdf">
        <vers num="1.1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="2.1"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":workstation"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_advanced_workstation" vendor="redhat">
        <vers num="2.1" edition=":itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0435" seq="2003-0435" published="2003-07-24" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105553002105111&amp;w=2">20030612 BAZARR THUG LIFE , DONT READ OR VIRUS INFECT YOU</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-322" adv="1" patch="1">DSA-322</ref>
    </refs>
    <vuln_soft>
      <prod name="typespeed" vendor="typespeed">
        <vers num="0.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0436" seq="2003-0436" published="2003-07-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7865" adv="1" patch="1">7865</ref>
    </refs>
    <vuln_soft>
      <prod name="mnogosearch" vendor="mnogosearch">
        <vers num="3.1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0437" seq="2003-0437" published="2003-07-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005543.html">20030610 mnogosearch 3.1.20 and 3.2.10 buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7866" adv="1" patch="1">7866</ref>
    </refs>
    <vuln_soft>
      <prod name="mnogosearch" vendor="mnogosearch">
        <vers num="3.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0438" seq="2003-0438" published="2003-07-24" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-325" adv="1" patch="1">DSA-325</ref>
    </refs>
    <vuln_soft>
      <prod name="eldav" vendor="yuuichi_teranishi">
        <vers num="0.7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0439" seq="2003-0439" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0440" seq="2003-0440" published="2003-08-18" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-339" adv="1" patch="1">DSA-339</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-231.html">RHSA-2003:231</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-234.html" adv="1" patch="1">RHSA-2003:234</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A569">oval:org.mitre.oval:def:569</ref>
    </refs>
    <vuln_soft>
      <prod name="semi" vendor="semi">
        <vers num="1.14.3"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0441" seq="2003-0441" published="2004-03-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-326" adv="1" patch="1">DSA-326</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7988" adv="1" patch="1">7988</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12381">orvillewrite-variables-bo(12381)</ref>
    </refs>
    <vuln_soft>
      <prod name="orville-write" vendor="orville-write">
        <vers num="2.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0442" seq="2003-0442" published="2003-07-24" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691">CLSA-2003:691</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105449314612963&amp;w=2">20030530 PHP Trans SID  XSS (Was: New php release with security fixes)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105760591228031&amp;w=2">20030707 [OpenPKG-SA-2003.032] OpenPKG Security Advisory (php)</ref>
      <ref source="MISC" url="http://shh.thathost.com/secadv/2003-05-11-php.txt" adv="1" patch="1">http://shh.thathost.com/secadv/2003-05-11-php.txt</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-112.shtml">N-112</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-351">DSA-351</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:082">MDKSA-2003:082</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-204.html" adv="1" patch="1">RHSA-2003:204</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7761">7761</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008653">1008653</ref>
      <ref source="TURBO" url="http://www.turbolinux.co.jp/security/2003/TLSA-2003-47j.txt">TLSA-2003-47</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12259">php-session-id-xss(12259)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A485">oval:org.mitre.oval:def:485</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.3.1" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0444" seq="2003-0444" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-337" adv="1" patch="1">DSA-337</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8061" adv="1" patch="1">8061</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12462">gtksee-png-bo(12462)</ref>
    </refs>
    <vuln_soft>
      <prod name="gtksee" vendor="gtksee">
        <vers num="0.5"/>
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0445" seq="2003-0445" published="2003-07-24" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-328" adv="1" patch="1">DSA-328</ref>
    </refs>
    <vuln_soft>
      <prod name="webfs" vendor="webfs">
        <vers num="1.17" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0446" seq="2003-0446" published="2003-07-24" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0120.html">20030617 Re: Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005762.html">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105585986015421&amp;w=2">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105595990924165&amp;w=2">20030617 Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105585001905002&amp;w=2">20030617 Cross-Site Scripting in Unparsable XML Files (GM#013-IE)</ref>
      <ref source="MISC" url="http://security.greymagic.com/adv/gm013-ie/" adv="1">http://security.greymagic.com/adv/gm013-ie/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7938">7938</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12334">ie-msxml-xss(12334)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0447" seq="2003-0447" published="2003-07-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005763.html">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105585933614773&amp;w=2">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105585142406147&amp;w=2">20030617 Script Injection to Custom HTTP Errors in Local Zone (GM#014-IE)</ref>
      <ref source="MISC" url="http://security.greymagic.com/adv/gm014-ie/" adv="1">http://security.greymagic.com/adv/gm014-ie/</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0448" seq="2003-0448" published="2003-07-24" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105588111714856&amp;w=2">20030618 Portmon file arbitrary read/write access vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="portmon" vendor="aboleo.net">
        <vers num="1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0449" seq="2003-0449" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105561134624665&amp;w=2">20030614 SRT2003-06-13-0945 - Progress PATH based dlopen() issue</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105561189625082&amp;w=2">20030614 SRT2003-06-13-1009 - Progress _dbagent -installdir dlopen() issue</ref>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt" adv="1" patch="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-0945.txt</ref>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt" adv="1" patch="1">http://www.secnetops.com/research/advisories/SRT2003-06-13-1009.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="progress">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0450" seq="2003-0450" published="2003-08-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063" adv="1" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=196063</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000664">CLA-2003:664</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-321" adv="1" patch="1">DSA-321</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_030_radiusd_cistron.html">SuSE-SA:2003:030</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-40.txt" adv="1" patch="1">TLSA-2003-40</ref>
    </refs>
    <vuln_soft>
      <prod name="radius_daemon" vendor="cistron">
        <vers num="1.6.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0451" seq="2003-0451" published="2003-08-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-327" adv="1" patch="1">DSA-327</ref>
    </refs>
    <vuln_soft>
      <prod name="xbl" vendor="xblockout">
        <vers num="1.0j" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0452" seq="2003-0452" published="2003-08-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-329" adv="1" patch="1">DSA-329</ref>
    </refs>
    <vuln_soft>
      <prod name="osh" vendor="gunnar_ritter">
        <vers num="1.7-10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0453" seq="2003-0453" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105613905425563&amp;w=2">20030620 BAZARR FAREWELL</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-348">DSA-348</ref>
    </refs>
    <vuln_soft>
      <prod name="traceroute-nanog" vendor="ehud_gavron">
        <vers num="6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0454" seq="2003-0454" published="2003-08-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-334">DSA-334</ref>
    </refs>
    <vuln_soft>
      <prod name="xgalaga" vendor="joe_rumsey">
        <vers num="2.0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0455" seq="2003-0455" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105786393628728&amp;w=2">20030710 [OpenPKG-SA-2003.034] OpenPKG Security Advisory (imagemagick)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-331" adv="1" patch="1">DSA-331</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-494.html">RHSA-2004:494</ref>
    </refs>
    <vuln_soft>
      <prod name="libmagick_library" vendor="imagemagick">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0456" seq="2003-0456" published="2003-08-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0002.html" adv="1" patch="1">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105733894003737&amp;w=2">20030701 VisNetic WebSite Path Disclosure Vulnerability</ref>
      <ref source="MISC" url="http://www.krusesecurity.dk/advisories/vis0103.txt">http://www.krusesecurity.dk/advisories/vis0103.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8075" adv="1" patch="1">8075</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12483">visnetic-website-path-disclosure(12483)</ref>
    </refs>
    <vuln_soft>
      <prod name="visnetic_website" vendor="deerfield">
        <vers num="3.5.13"/>
        <vers num="3.5.15"/>
        <vers num="3.5.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0458" seq="2003-0458" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5545" adv="1">SSRT3488</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8080" adv="1" patch="1">8080</ref>
    </refs>
    <vuln_soft>
      <prod name="nonstop_seeview_server_gateway" vendor="hp">
        <vers num="d40.00"/>
        <vers num="d41.00"/>
        <vers num="d42.00"/>
        <vers num="d42.01"/>
        <vers num="d43.00"/>
        <vers num="d43.01"/>
        <vers num="d43.02"/>
        <vers num="d44.00"/>
        <vers num="d44.01"/>
        <vers num="d44.02"/>
        <vers num="d45.00"/>
        <vers num="d45.01"/>
        <vers num="d46.00"/>
        <vers num="d47.00"/>
        <vers num="d48.00"/>
        <vers num="d48.01"/>
        <vers num="d48.02"/>
        <vers num="d48.03"/>
        <vers num="g01.00"/>
        <vers num="g02.00"/>
        <vers num="g03.00"/>
        <vers num="g04.00"/>
        <vers num="g05.00"/>
        <vers num="g05.01"/>
        <vers num="g06.00"/>
        <vers num="g06.01"/>
        <vers num="g06.03"/>
        <vers num="g06.04"/>
        <vers num="g06.05"/>
        <vers num="g06.06"/>
        <vers num="g06.07"/>
        <vers num="g06.08"/>
        <vers num="g06.09"/>
        <vers num="g06.10"/>
        <vers num="g06.11"/>
        <vers num="g06.12"/>
        <vers num="g06.13"/>
        <vers num="g06.14"/>
        <vers num="g06.15"/>
        <vers num="g06.16"/>
        <vers num="g06.17"/>
        <vers num="g06.18"/>
        <vers num="g06.19"/>
        <vers num="g06.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0459" seq="2003-0459" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/007300.html">20030729 KDE Security Advisory: Konqueror Referrer Authentication Leak</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105986238428061&amp;w=2">20030802 [slackware-security]  KDE packages updated (SSA:2003-213-01)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-361">DSA-361</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20030729-1.txt">http://www.kde.org/info/security/advisory-20030729-1.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:079">MDKSA-2003:079</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-235.html" adv="1" patch="1">RHSA-2003:235</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-236.html" adv="1" patch="1">RHSA-2003:236</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-45.txt">TLSA-2003-45</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A411">oval:org.mitre.oval:def:411</ref>
    </refs>
    <vuln_soft>
      <prod name="konqueror" vendor="kde">
        <vers num="2.1.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.5"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod name="konqueror_embedded" vendor="kde">
        <vers num="0.1"/>
      </prod>
      <prod name="analog_real-time_synthesizer" vendor="redhat">
        <vers num="2.1.1-5" edition=":i386"/>
        <vers num="2.2-11" edition=":i386"/>
        <vers num="2.2-11" edition=":ia64"/>
      </prod>
      <prod name="kdebase" vendor="redhat">
        <vers num="3.0.3-13" edition=":i386"/>
        <vers num="3.0.3-13" edition=":i386_dev"/>
      </prod>
      <prod name="kdelibs" vendor="redhat">
        <vers num="2.1.1-5" edition=":i386"/>
        <vers num="2.2-11" edition=":i386"/>
        <vers num="2.2-11" edition=":ia64"/>
        <vers num="3.0.0-10" edition=":i386"/>
        <vers num="3.1-10" edition=":i386"/>
      </prod>
      <prod name="kdelibs_devel" vendor="redhat">
        <vers num="2.1.1-5" edition=":i386_dev"/>
        <vers num="2.2-11" edition=":i386_dev"/>
        <vers num="2.2-11" edition=":ia64_dev"/>
        <vers num="3.0.0-10" edition=":i386_dev"/>
        <vers num="3.0.3-8" edition=":i386_dev"/>
        <vers num="3.1-10" edition=":i386_dev"/>
      </prod>
      <prod name="kdelibs_sound" vendor="redhat">
        <vers num="2.1.1-5" edition=":i386_sound"/>
        <vers num="2.2-11" edition=":i386_sound"/>
        <vers num="2.2-11" edition=":ia64_sound"/>
      </prod>
      <prod name="kdelibs_sound_devel" vendor="redhat">
        <vers num="2.1.1-5" edition=":i386_sound_dev"/>
        <vers num="2.2-11" edition=":i386_sound_dev"/>
        <vers num="2.2-11" edition=":ia64_sound_dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0460" seq="2003-0460" published="2003-08-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/Announcement.html" patch="1">http://www.apache.org/dist/httpd/Announcement.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/694428">VU#694428</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0461" seq="2003-0461" published="2003-08-27" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html">http://rsbac.dyndns.org/pipermail/rsbac/2002-May/000162.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html">RHSA-2004:188</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A304">oval:org.mitre.oval:def:304</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9330">oval:org.mitre.oval:def:9330</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A997">oval:org.mitre.oval:def:997</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0462" seq="2003-0462" published="2003-08-27" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A309">oval:org.mitre.oval:def:309</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_multi_network_firewall" vendor="mandrakesoft">
        <vers num="8.2"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="8.2" edition=":ppc"/>
        <vers num="9.0"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0463" seq="2003-0463" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0464" seq="2003-0464" published="2003-08-27" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A311">oval:org.mitre.oval:def:311</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0465" seq="2003-0465" published="2003-08-18" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as opposed to the expected behavior of strncpy as implemented in libc, which could lead to information leaks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://marc.info/?l=linux-kernel&amp;m=105796021120436&amp;w=2">http://marc.info/?l=linux-kernel&amp;m=105796021120436&amp;w=2</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=linux-kernel&amp;m=105796415223490&amp;w=2">http://marc.info/?l=linux-kernel&amp;m=105796415223490&amp;w=2</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html" adv="1" patch="1">RHSA-2004:188</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10285">oval:org.mitre.oval:def:10285</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0466" seq="2003-0466" published="2003-08-27" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc">NetBSD-SA2003-011.txt.asc</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html" adv="1">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-019-01">IMNX-2003-7+-019-01</ref>
      <ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt">http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105967301604815&amp;w=2">20030731 wu-ftpd fb_realpath() off-by-one bug</ref>
      <ref source="FREEBSD" url="http://marc.info/?l=bugtraq&amp;m=106001410028809&amp;w=2">FreeBSD-SA-03:08</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106001702232325&amp;w=2">20030804 wu-ftpd-2.6.2 off-by-one remote exploit.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106002488209129&amp;w=2">20030804 Off-by-one Buffer Overflow Vulnerability in BSD libc realpath(3)</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007380">1007380</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001257.1-1">1001257</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-357">DSA-357</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/743092" adv="1">VU#743092</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:080">MDKSA-2003:080</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_032_wuftpd.html">SuSE-SA:2003:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-245.html">RHSA-2003:245</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-246.html">RHSA-2003:246</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424852/100/0/threaded">20060213 Latest wu-ftpd exploit :-s</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425061/100/0/threaded">20060214 Re: Latest wu-ftpd exploit :-s</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8315" adv="1" patch="1">8315</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-46.txt">TLSA-2003-46</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12785">libc-realpath-offbyone-bo(12785)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1970">oval:org.mitre.oval:def:1970</ref>
    </refs>
    <vuln_soft>
      <prod name="wu_ftpd" vendor="redhat">
        <vers num="2.6.1-16" edition=":i386"/>
        <vers num="2.6.1-16" edition=":powerpc"/>
        <vers num="2.6.1-18" edition=":i386"/>
        <vers num="2.6.1-18" edition=":ia64"/>
        <vers num="2.6.2-5" edition=":i386"/>
        <vers num="2.6.2-8" edition=":i386"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2.6"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.6"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0467" seq="2003-0467" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105985703724758&amp;w=2">20030802 [SECURITY] Netfilter Security Advisory: NAT Remote DOS (SACK mangle)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0468" seq="2003-0468" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717">CLA-2003:717</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106001525130257&amp;w=2">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-363" adv="1" patch="1">DSA-363</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081">MDKSA-2003:081</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html">SuSE-SA:2003:033</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-251.html">RHSA-2003:251</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8333">8333</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A522">oval:org.mitre.oval:def:522</ref>
    </refs>
    <vuln_soft>
      <prod name="postfix" vendor="wietse_venema">
        <vers num="1.0.21"/>
        <vers num="1.1.11"/>
        <vers num="1999-09-06"/>
        <vers num="1999-12-31"/>
        <vers num="2000-02-28"/>
        <vers num="2001-11-15"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0469" seq="2003-0469" published="2003-08-07" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006155.html">20030701 PoC for Internet Explorer >=5.0 buffer overflow (trivial exploit for hard case).</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006067.html">20030625 Re: Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105639925122961&amp;w=2">20030622 Internet Explorer >=5.0 : Buffer overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-14.html">CA-2003-14</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/823260">VU#823260</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8016">8016</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-023">MS03-023</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="64-bit"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0470" seq="2003-0470" published="2003-08-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/006014.html">20030622 Symantec ActiveX control buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105647537823877&amp;w=2">20030624 [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007029">1007029</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527228">VU#527228</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8008">8008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12423">symantec-security-activex-bo(12423)</ref>
    </refs>
    <vuln_soft>
      <prod name="security_check" vendor="symantec">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0471" seq="2003-0471" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105647081418155&amp;w=2">20030624 Remote Buffer Overrun WebAdmin.exe</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105648385900792&amp;w=2">20030624 Re: WebAdmin from ALT-N remote exploit PoC</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8024">8024</ref>
    </refs>
    <vuln_soft>
      <prod name="webadmin" vendor="alt-n">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0472" seq="2003-0472" published="2003-08-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" adv="1" patch="1">20030607-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8027">8027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12676">irix-inetd-portscan-dos(12676)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0473" seq="2003-0473" published="2003-08-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030607-01-P" adv="1" patch="1">20030607-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8029">8029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12677">irix-snoop-gain-privileges(12677)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0474" seq="2003-0474" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105049794801319&amp;w=2">20030416 SFAD03-001: iWeb Mini Web Server Remote Directory Traversal</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673543626636&amp;w=2">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod name="iweb_server" vendor="ashley_brown">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0475" seq="2003-0475" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105640001823769&amp;w=2">20030623 TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673543626636&amp;w=2">20030627 Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod name="iweb_server" vendor="ashley_brown">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0476" seq="2003-0476" published="2003-08-07" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105664924024009&amp;w=2">20030626 Linux 2.4.x execve() file read race vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:074">MDKSA-2003:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-368.html" adv="1" patch="1">RHSA-2003:368</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-408.html">RHSA-2003:408</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A327">oval:org.mitre.oval:def:327</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0477" seq="2003-0477" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105674242105302&amp;w=2">20030627 wzdftpd remote DoS</ref>
      <ref source="CONFIRM" url="http://www.wzdftpd.net/changea.html" adv="1" patch="1">http://www.wzdftpd.net/changea.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wzdftpd" vendor="wzdftpd">
        <vers num="0.1_rc4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0478" seq="2003-0478" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105665996104723&amp;w=2">20030626 Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673489525906&amp;w=2">20030627 Re: Bahamut IRCd &lt;= 1.4.35 and several derived daemons</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673555726823&amp;w=2">20030627 Bahamut DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="adromedeircd" vendor="andromede">
        <vers num="1.2.3"/>
      </prod>
      <prod name="methane" vendor="daniel_moss">
        <vers num="0.1.1"/>
      </prod>
      <prod name="digatech" vendor="hans_westerhof">
        <vers num="1.2.1"/>
      </prod>
      <prod name="ircd-ru" vendor="wenet">
        <vers num=""/>
      </prod>
      <prod name="ircd" vendor="bahamut">
        <vers num="1.4.35" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0479" seq="2003-0479" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673452325230&amp;w=2">20030627 WebBBS Guestbook : Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod name="affordable_web_space_design_webbbs" vendor="affordable_web_space_design">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0480" seq="2003-0480" published="2003-08-07" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105673688529147&amp;w=2">20030627 VMware Workstation 4.0: Possible privilege escalation on the host</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019" adv="1" patch="1">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1019</ref>
    </refs>
    <vuln_soft>
      <prod name="workstation" vendor="vmware">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0481" seq="2003-0481" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105638743109781&amp;w=2">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod name="tutos" vendor="gero_kohnert">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0482" seq="2003-0482" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105638743109781&amp;w=2">20030623 [KSA-001] Multiple vulnerabilities in Tutos</ref>
    </refs>
    <vuln_soft>
      <prod name="tutos" vendor="gero_kohnert">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0483" seq="2003-0483" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105638720409307&amp;w=2">20030623 Many XSS Vulnerabilities in XMB Forum.</ref>
    </refs>
    <vuln_soft>
      <prod name="xmb" vendor="xmb_forum">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0484" seq="2003-0484" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105639883722514&amp;w=2">20030621 XSS Exploit In phpBB viewtopic.php</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0485" seq="2003-0485" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105613243117155&amp;w=2">20030620 SRT2003-06-20-1232 - Progress 4GL Compiler datatype overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7997" adv="1">7997</ref>
    </refs>
    <vuln_soft>
      <prod name="4gl_compiler" vendor="progress">
        <vers num="9.1" edition="d06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0486" seq="2003-0486" published="2003-08-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105607263130644&amp;w=2">20030619 phpBB password disclosure by sql injection</ref>
      <ref source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?t=112052" adv="1" patch="1">http://www.phpbb.com/phpBB/viewtopic.php?t=112052</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7979" adv="1" patch="1">7979</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12366">phpbb-viewtopic-sql-injection(12366)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0487" seq="2003-0487" published="2003-08-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105596982503760&amp;w=2">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
      <ref source="MISC" url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7967" adv="1" patch="1">7967</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12368">kerio-multiple-modules-bo(12368)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerio_mailserver" vendor="kerio">
        <vers num="5.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0488" seq="2003-0488" published="2003-08-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105596982503760&amp;w=2">20030618 Multiple buffer overflows and XSS in Kerio MailServer</ref>
      <ref source="MISC" url="http://nautopia.org/vulnerabilidades/kerio_mailserver.htm" adv="1">http://nautopia.org/vulnerabilidades/kerio_mailserver.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7966" adv="1" patch="1">7966</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7968" adv="1" patch="1">7968</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12367">kerio-multiple-modules-xss(12367)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerio_mailserver" vendor="kerio">
        <vers num="5.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0489" seq="2003-0489" published="2003-08-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-330" adv="1" patch="1">DSA-330</ref>
    </refs>
    <vuln_soft>
      <prod name="tcptraceroute" vendor="michael_c._toren">
        <vers num="1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0490" seq="2003-0490" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105579526026992&amp;w=2">20030616 Dantz Retrospect Client 5.0.540 for Mac OS X - permission issues</ref>
    </refs>
    <vuln_soft>
      <prod name="retrospect_client" vendor="dantz">
        <vers num="5.0.540"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0491" seq="2003-0491" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=vuln-dev&amp;m=105577873506147&amp;w=2">20030616 Directory traversal vulnerability on Xoops/E-xoops CMS module "tutorials"</ref>
    </refs>
    <vuln_soft>
      <prod name="tutorials" vendor="mytutorials">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0492" seq="2003-0492" published="2003-08-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7922" adv="1">7922</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12325">snitz-search-xss(12325)</ref>
    </refs>
    <vuln_soft>
      <prod name="snitz_forums_2000" vendor="snitz_communications">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0493" seq="2003-0493" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7924" adv="1">7924</ref>
    </refs>
    <vuln_soft>
      <prod name="snitz_forums_2000" vendor="snitz_communications">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0494" seq="2003-0494" published="2003-08-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105578322012128&amp;w=2">20030616 Multiple Vulnerabilities In Snitz Forums</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7925" adv="1">7925</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12326">snitz-forums-password-reset(12326)</ref>
    </refs>
    <vuln_soft>
      <prod name="snitz_forums_2000" vendor="snitz_communications">
        <vers num="3.4.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0495" seq="2003-0495" published="2003-08-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105578330812212&amp;w=2">20030615 XSS Vulnerability in LedNews (CGI/Perl) v0.7</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7920">7920</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12304">lednews-message-xss(12304)</ref>
    </refs>
    <vuln_soft>
      <prod name="lednews" vendor="ledscripts.com">
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0496" seq="2003-0496" published="2003-08-18" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html" adv="1" patch="1">20030709 Pipe Filename Local Privilege Escalation FAQ</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820282607865&amp;w=2">20030714 @stake named pipe exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105830986720243&amp;w=2">20030715 CreateFile exploit, (working)</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a070803-1.txt" adv="1" patch="1">A070803-1</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0497" seq="2003-0497" published="2003-08-07" modified="2019-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cach? Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IDEFENSE" url="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7">20030701 Caché Insecure Installation File and Directory Permissions</ref>
      <ref source="CONFIRM" url="https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/">https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/</ref>
    </refs>
    <vuln_soft>
      <prod name="cache_database" vendor="intersystems">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0498" seq="2003-0498" published="2003-08-07" modified="2019-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cach? Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IDEFENSE" url="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=7">20030701 Caché Insecure Installation File and Directory Permissions</ref>
      <ref source="CONFIRM" url="https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/">https://www.intersystems.com/support-learning/support/product-news-alerts/support-alerts-2003/</ref>
    </refs>
    <vuln_soft>
      <prod name="cache_database" vendor="intersystems">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0499" seq="2003-0499" published="2003-08-07" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="https://www.debian.org/security/2003/dsa-335">DSA-335</ref>
    </refs>
    <vuln_soft>
      <prod name="mantis" vendor="mantis">
        <vers num="0.17.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0500" seq="2003-0500" published="2003-08-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-June/005826.html">20030618 SQL Inject in ProFTPD login against Postgresql using mod_sql</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-338" adv="1" patch="1">DSA-338</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2.9_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0501" seq="2003-0501" published="2003-08-07" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105621758104242">20030620 Linux /proc sensitive information disclosure</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html" adv="1" patch="1">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A328">oval:org.mitre.oval:def:328</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0502" seq="2003-0502" published="2003-08-27" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html" adv="1">20030723 R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server</ref>
      <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0015.html">http://www.rapid7.com/advisories/R7-0015.html</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.3g" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0503" seq="2003-0503" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105725489003575&amp;w=2">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105724538222772&amp;w=2">20030703 [SNS Advisory No.65] Windows 2000 ShellExecute() API Let Applications to Cause Buffer Overflow</ref>
      <ref source="MISC" url="http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html">http://www.lac.co.jp/security/intelligence/SNSAdvisory/65.html</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0504" seq="2003-0504" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000697">CLA-2003:697</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105718361607981&amp;w=2">20030702 [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-365">DSA-365</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:077">MDKSA-2003:077</ref>
      <ref source="MISC" url="http://www.security-corporation.com/articles-20030702-005.html">http://www.security-corporation.com/articles-20030702-005.html</ref>
    </refs>
    <vuln_soft>
      <prod name="phpgroupware" vendor="phpgroupware">
        <vers num="0.9.14.003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0505" seq="2003-0505" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105716650021546&amp;w=2">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7931" adv="1" patch="1">7931</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0506" seq="2003-0506" published="2003-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105716650021546&amp;w=2">20030702 CORE-2003-0305-04: NetMeeting Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0507" seq="2003-0507" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105716669921775&amp;w=2">20030702 CORE-2003-0305-03: Active Directory Stack Overflow</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?kbid=319709" adv="1" patch="1">Q319709</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/594108">VU#594108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7930">7930</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0508" seq="2003-0508" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105709569312583&amp;w=2">20030701 [sec-labs] Adobe Acrobat Reader &lt;=5.0.7 Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105785749721291&amp;w=2">20030709 Acroread 5.0.7 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0509" seq="2003-0509" published="2003-08-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105709450711395&amp;w=2">20030701 CyberStrong Shopping Cart - Advisory &amp; Exploit Code</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007092">1007092</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/14101">14101</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/14103">14103</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/14112">14112</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12485">cyberstrongeshop-multiple-sql-injection(12485)</ref>
    </refs>
    <vuln_soft>
      <prod name="eshop" vendor="cyberstrong">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0510" seq="2003-0510" published="2003-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://druglord.freelsd.org/ezbounce/">http://druglord.freelsd.org/ezbounce/</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105709355110281&amp;w=2">20030701 ezbounce[v1.0-(1.04a/1.50pre6)]: remote format string exploit.</ref>
    </refs>
    <vuln_soft>
      <prod name="ezbounce" vendor="ezbounce">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.30"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="1.33"/>
        <vers num="1.34"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0511" seq="2003-0511" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0055.html" adv="1">20030728 Cisco Aironet AP 1100 Malformed HTTP Request Crash Vulnerability</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030728-ap1x00.shtml">20030728 HTTP GET Vulnerability in AP1x00</ref>
      <ref source="MISC" url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5834">oval:org.mitre.oval:def:5834</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.2(4)ja"/>
        <vers num="12.2(4)ja1"/>
        <vers num="12.2(8)ja"/>
        <vers num="12.2(11)ja"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0512" seq="2003-0512" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html" adv="1">20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml">20030724 Enumerating Locally Defined Users in Cisco IOS</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/886796">VU#886796</ref>
      <ref source="MISC" url="http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm">http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5824">oval:org.mitre.oval:def:5824</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0(24)s1"/>
        <vers num="12.0(24.2)s"/>
        <vers num="12.2(11)ja1"/>
        <vers num="12.2(14.5)"/>
        <vers num="12.2(14.5)t"/>
        <vers num="12.2(15)zn"/>
        <vers num="12.2(15.1)s"/>
        <vers num="12.2(16)b"/>
        <vers num="12.2(16.1)b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0513" seq="2003-0513" published="2004-04-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.0.1" edition="sp4"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0514" seq="2003-0514" published="2004-04-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod name="safari" vendor="apple">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0515" seq="2003-0515" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-347" adv="1" patch="1">DSA-347</ref>
    </refs>
    <vuln_soft>
      <prod name="teapop" vendor="teapop">
        <vers num="0.3.4"/>
        <vers num="0.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0516" seq="2003-0516" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz" patch="1">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="mgetty" vendor="gert_doering">
        <vers num="1.1.28" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0517" seq="2003-0517" published="2003-08-18" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz">ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="mgetty" vendor="gert_doering">
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
        <vers num="1.1.22"/>
        <vers num="1.1.28" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0518" seq="2003-0518" published="2003-08-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0034.html" adv="1">20030704 MacOSX - crash screensaver locked with password and get the desktop back</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0187.html" patch="1">20030715 FIXED: MacOSX - crash screensaver locked with password and get thedesktop back</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=120232">http://docs.info.apple.com/article.html?artnum=120232</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0519" seq="2003-0519" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006286.html">20030707 Internet Explorer 6 DoS Bug</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0520" seq="2003-0520" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105735714318026&amp;w=2">20030704 Trillian Remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8107" adv="1">8107</ref>
    </refs>
    <vuln_soft>
      <prod name="trillian" vendor="cerulean_studios">
        <vers num="0.74"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0521" seq="2003-0521" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
cPanel, cPanel, 7.0</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105760556627616&amp;w=2">20030706 cPanel Malicious HTML Tags Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="cpanel" vendor="cpanel">
        <vers num="5.0"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.2"/>
        <vers num="6.4"/>
        <vers num="6.4.1"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2_stable_48"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0522" seq="2003-0522" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105733145930031&amp;w=2">20030704 Another ProductCart SQL Injection Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105760660928715&amp;w=2">20030705 Re: Another ProductCart SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="productcart" vendor="early_impact">
        <vers num="1.5"/>
        <vers num="1.6b"/>
        <vers num="1.6b001"/>
        <vers num="1.6b002"/>
        <vers num="1.6b003"/>
        <vers num="1.6br"/>
        <vers num="1.6br001"/>
        <vers num="1.6br003"/>
        <vers num="1.5002"/>
        <vers num="1.5003"/>
        <vers num="1.5003r"/>
        <vers num="1.5004"/>
        <vers num="1.6002"/>
        <vers num="1.6003"/>
        <vers num="2"/>
        <vers num="2br000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0523" seq="2003-0523" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105761696706800&amp;w=2">20030705 ProductCart XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="productcart" vendor="early_impact">
        <vers num="1.5"/>
        <vers num="1.6b"/>
        <vers num="1.6b001"/>
        <vers num="1.6b002"/>
        <vers num="1.6b003"/>
        <vers num="1.6br"/>
        <vers num="1.6br001"/>
        <vers num="1.6br003"/>
        <vers num="1.5002"/>
        <vers num="1.5003"/>
        <vers num="1.5003r"/>
        <vers num="1.5004"/>
        <vers num="1.6002"/>
        <vers num="1.6003"/>
        <vers num="2"/>
        <vers num="2br000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0524" seq="2003-0524" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105769387706906&amp;w=2">20030708 Qt temporary files race condition in Knoppix 3.1</ref>
    </refs>
    <vuln_soft>
      <prod name="knoppix" vendor="knoppix">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0525" seq="2003-0525" published="2003-08-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a072303-1.txt" adv="1">A072303-1</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-029">MS03-029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12701">winnt-file-management-dos(12701)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A319">oval:org.mitre.oval:def:319</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0526" seq="2003-0526" published="2003-08-18" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0029.html" adv="1">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0031.html">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105838519729525&amp;w=2">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105838862201266&amp;w=2">20030716 ISA Server - Error Page Cross Site Scripting</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105838590030409&amp;w=2">20030716 Microsoft ISA Server HTTP error handler XSS (TL#007)</ref>
      <ref source="MISC" url="http://pivx.com/larholm/adv/TL006">http://pivx.com/larholm/adv/TL006</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-028">MS03-028</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A117">oval:org.mitre.oval:def:117</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000" edition="fp1"/>
        <vers num="2000" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0528" seq="2003-0528" published="2003-09-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0100.html">20030911 NSFOCUS SA2003-06 : Microsoft Windows RPC DCOM Interface Heap Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106407417011430&amp;w=2">20030920 The Analysis of RPC Long Filename Heap Overflow AND a Way to Write  Universal Heap Overflow of Windows</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-23.html" adv="1" patch="1">CA-2003-23</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/254236">VU#254236</ref>
      <ref source="MISC" url="http://www.nsfocus.com/english/homepage/research/0306.htm">http://www.nsfocus.com/english/homepage/research/0306.htm</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039">MS03-039</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A127">oval:org.mitre.oval:def:127</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2884">oval:org.mitre.oval:def:2884</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2968">oval:org.mitre.oval:def:2968</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3966">oval:org.mitre.oval:def:3966</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0530" seq="2003-0530" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007538">1007538</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-22.html">CA-2003-22</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/548964">VU#548964</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8454" adv="1">8454</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032">MS03-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12962">ie-br549-activex-bo(12962)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0531" seq="2003-0531" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-22.html">CA-2003-22</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/205148">VU#205148</ref>
      <ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/67_e.html">http://www.lac.co.jp/security/english/snsadv_e/67_e.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8457" adv="1">8457</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032">MS03-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12961">ie-cache-script-injection(12961)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0532" seq="2003-0532" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0084.html" adv="1">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106149026621753&amp;w=2">20030820 EEYE: Internet Explorer Object Data Remote Execution Vulnerability</ref>
      <ref source="MISC" url="http://www.eeye.com/html/Research/Advisories/AD20030820.html">http://www.eeye.com/html/Research/Advisories/AD20030820.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/865940" adv="1">VU#865940</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032">MS03-032</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0533" seq="2003-0533" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html">20040413 EEYE: Windows Local Security Authority Service Remote Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108325860431471&amp;w=2">20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040413C.html">AD20040413C</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/753212" adv="1" patch="1">VU#753212</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10108">10108</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15699">win-lsass-bo(15699)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A883">oval:org.mitre.oval:def:883</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A898">oval:org.mitre.oval:def:898</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A919">oval:org.mitre.oval:def:919</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0535" seq="2003-0535" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006386.html">20030708 Fwd: xbl vulnerabilty</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-345" adv="1" patch="1">DSA-345</ref>
    </refs>
    <vuln_soft>
      <prod name="xbl" vendor="xblockout">
        <vers num="1.0i"/>
        <vers num="1.0k"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0536" seq="2003-0536" published="2003-08-18" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105128606513226&amp;w=2">20030425 Unauthorized reading files on phpSysInfo</ref>
      <ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=670222&amp;group_id=15&amp;atid=100015</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-346" adv="1" patch="1">DSA-346</ref>
    </refs>
    <vuln_soft>
      <prod name="phpsysinfo" vendor="phpsysinfo">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0537" seq="2003-0537" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-341" adv="1" patch="1">DSA-341</ref>
    </refs>
    <vuln_soft>
      <prod name="liece_emacs_irc_client" vendor="daiki_ueno">
        <vers num="2.0_0.2003-05-27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0538" seq="2003-0538" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-342" adv="1" patch="1">DSA-342</ref>
    </refs>
    <vuln_soft>
      <prod name="mozart" vendor="mozart">
        <vers num="1.2.3"/>
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0539" seq="2003-0539" published="2003-08-18" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-343" adv="1" patch="1">DSA-343</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-242.html">RHSA-2003:242</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A28">oval:org.mitre.oval:def:28</ref>
    </refs>
    <vuln_soft>
      <prod name="ddskk" vendor="ddskk">
        <vers num="11.6_.rel.0"/>
      </prod>
      <prod name="daredevil_skk" vendor="redhat">
        <vers num="11.3.2" edition=":noarch"/>
        <vers num="11.3.5" edition=":noarch"/>
        <vers num="11.6.0-6" edition=":noarch"/>
        <vers num="11.6.0-8" edition=":noarch"/>
        <vers num="11.6.0-10" edition=":noarch"/>
      </prod>
      <prod name="ddskk-xemacs" vendor="redhat">
        <vers num="11.6.0-6" edition=":noarch"/>
        <vers num="11.6.0-8" edition=":noarch"/>
        <vers num="11.6.0-10" edition=":noarch"/>
      </prod>
      <prod name="skk" vendor="skk">
        <vers num="10.62a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0540" seq="2003-0540" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000717">CLA-2003:717</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-August/007693.html">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106001525130257&amp;w=2">20030804 Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=106029188614704&amp;w=2">2003-0029</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-363" adv="1" patch="1">DSA-363</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/895508">VU#895508</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3517.html">ESA-20030804-019</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:081">MDKSA-2003:081</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_033_postfix.html">SuSE-SA:2003:033</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-251.html" adv="1" patch="1">RHSA-2003:251</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8333">8333</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A544">oval:org.mitre.oval:def:544</ref>
    </refs>
    <vuln_soft>
      <prod name="postfix" vendor="wietse_venema">
        <vers num="1.0.21"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1999-09-06"/>
        <vers num="1999-12-31"/>
        <vers num="2000-02-28"/>
        <vers num="2001-11-15"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0541" seq="2003-0541" published="2003-09-17" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737">CLA-2003:737</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-710">DSA-710</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:093">MDKSA-2003:093</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-264.html" adv="1" patch="1">RHSA-2003:264</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A148">oval:org.mitre.oval:def:148</ref>
    </refs>
    <vuln_soft>
      <prod name="gtkhtml" vendor="gnome">
        <vers num="1.1.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0542" seq="2003-0542" published="2003-11-03" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.6/SCOSA-2004.6.txt">SCOSA-2004.6</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031203-01-U.asc">20031203-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://httpd.apache.org/dist/httpd/Announcement2.html">http://httpd.apache.org/dist/httpd/Announcement2.html</ref>
      <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106761802305141&amp;w=2">20031031 GLSA:  apache (200310-04)</ref>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2">SSRT090208</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101444-1">101444</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1">101841</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/434566">VU#434566</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/549142">VU#549142</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103">MDKSA-2003:103</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-320.html">RHSA-2003:320</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-360.html">RHSA-2003:360</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-405.html">RHSA-2003:405</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-015.html" adv="1" patch="1">RHSA-2004:015</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/6079">HPSBUX0311-301</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342674">20031028 [OpenPKG-SA-2003.046] OpenPKG Security Advisory (apache)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8911" adv="1" patch="1">8911</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13400">apache-modalias-modrewrite-bo(13400)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3799">oval:org.mitre.oval:def:3799</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A863">oval:org.mitre.oval:def:863</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A864">oval:org.mitre.oval:def:864</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9458">oval:org.mitre.oval:def:9458</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.9"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="2.0"/>
        <vers num="2.0.28"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0543" seq="2003-0543" published="2003-11-17" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1">201029</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-26.html">CA-2003-26</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-393">DSA-393</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-394">DSA-394</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/255484">VU#255484</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html">ESA-20030930-027</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-291.html" adv="1" patch="1">RHSA-2003:291</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-292.html">RHSA-2003:292</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8732">8732</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/3900">ADV-2006-3900</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4254">oval:org.mitre.oval:def:4254</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5292">oval:org.mitre.oval:def:5292</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0544" seq="2003-0544" published="2003-11-17" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1">201029</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-26.html">CA-2003-26</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-393">DSA-393</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-394">DSA-394</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/380864">VU#380864</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html">ESA-20030930-027</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-291.html" adv="1" patch="1">RHSA-2003:291</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-292.html" adv="1" patch="1">RHSA-2003:292</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8732">8732</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/3900">ADV-2006-3900</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/43041">openssl-asn1-sslclient-dos(43041)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4574">oval:org.mitre.oval:def:4574</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0545" seq="2003-0545" published="2003-11-17" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-26.html">CA-2003-26</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-394">DSA-394</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/935264">VU#935264</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-292.html" adv="1" patch="1">RHSA-2003:292</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8732">8732</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/3900">ADV-2006-3900</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2590">oval:org.mitre.oval:def:2590</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0546" seq="2003-0546" published="2003-08-27" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;m=106036724315539&amp;w=2">RHSA-2003:255</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A631">oval:org.mitre.oval:def:631</ref>
    </refs>
    <vuln_soft>
      <prod name="up2date" vendor="redhat">
        <vers num="3.0.7-1" edition=":i386"/>
        <vers num="3.0.7-1" edition=":i386_gnome"/>
        <vers num="3.1.23-1" edition=":i386"/>
        <vers num="3.1.23-1" edition=":i386_gnome"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0547" seq="2003-0547" published="2003-08-27" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729">CLA-2003:729</ref>
      <ref source="CONFIRM" url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106194792924122&amp;w=2">20030824 [slackware-security]  GDM security update (SSA:2003-236-01)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-258.html" adv="1" patch="1">RHSA-2003:258</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A112">oval:org.mitre.oval:def:112</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod name="kdebase" vendor="redhat">
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0548" seq="2003-0548" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729">CLA-2003:729</ref>
      <ref source="CONFIRM" url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-258.html" adv="1" patch="1">RHSA-2003:258</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-259.html" adv="1" patch="1">RHSA-2003:259</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A113">oval:org.mitre.oval:def:113</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.2.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod name="kdebase" vendor="redhat">
        <vers num="2.0_beta2.45" edition=":i386"/>
        <vers num="2.0_beta2.45" edition=":ppc"/>
        <vers num="2.2.3.1.20" edition=":i386"/>
        <vers num="2.2.3.1.20" edition=":ia64"/>
        <vers num="2.2.3.1.22" edition=":i386"/>
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":workstation_ia64"/>
      </prod>
      <prod name="linux_advanced_workstation" vendor="redhat">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0549" seq="2003-0549" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000729">CLA-2003:729</ref>
      <ref source="CONFIRM" url="http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html">http://mail.gnome.org/archives/gnome-hackers/2003-August/msg00045.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-258.html" adv="1" patch="1">RHSA-2003:258</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-259.html" adv="1" patch="1">RHSA-2003:259</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A129">oval:org.mitre.oval:def:129</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.2.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
      </prod>
      <prod name="kdebase" vendor="redhat">
        <vers num="2.0_beta2.45" edition=":i386"/>
        <vers num="2.0_beta2.45" edition=":ppc"/>
        <vers num="2.2.3.1.20" edition=":i386"/>
        <vers num="2.2.3.1.20" edition=":ia64"/>
        <vers num="2.2.3.1.22" edition=":i386"/>
        <vers num="2.4.0.7.13" edition=":i386"/>
        <vers num="2.4.1.3.5" edition=":i386"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":workstation_ia64"/>
      </prod>
      <prod name="linux_advanced_workstation" vendor="redhat">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0550" seq="2003-0550" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A380">oval:org.mitre.oval:def:380</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0551" seq="2003-0551" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A384">oval:org.mitre.oval:def:384</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0552" seq="2003-0552" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423" adv="1" patch="1">DSA-423</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html" adv="1" patch="1">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A385">oval:org.mitre.oval:def:385</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0553" seq="2003-0553" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf">http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820193406838&amp;w=2">20030714 Netscape 7.02 Client Detection Tool plug-in buffer overrun</ref>
    </refs>
    <vuln_soft>
      <prod name="navigator" vendor="netscape">
        <vers num="7.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0554" seq="2003-0554" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006505.html">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820316708258&amp;w=2">20030714 [sec-labs] Remote Denial of Service vulnerability in NeoModus Direct Connect 1.0 build 9</ref>
    </refs>
    <vuln_soft>
      <prod name="direct_connect" vendor="neomodus">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0555" seq="2003-0555" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820576111599&amp;w=2">20030714 ImageMagick's Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="5.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0556" seq="2003-0556" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006494.html">20030712 DoS - Polycom MGC 25 Control Port</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105804648003163&amp;w=2">20030712 DoS - Polycom MGC 25 Control Port</ref>
    </refs>
    <vuln_soft>
      <prod name="mgc-100" vendor="polycom">
        <vers num=""/>
      </prod>
      <prod name="mgc-25" vendor="polycom">
        <vers num="5.51.21"/>
        <vers num="5.51.211"/>
      </prod>
      <prod name="mgc-50" vendor="polycom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0557" seq="2003-0557" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.</descript>
    </desc>
    <sols>
      <sol source="nvd">This issue was addressed in a hot fix for StoreFront 6.1 in late January 2004.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105804683203384&amp;w=2">20030712 ZH2003-3SA (security advisory): Storefront sql injection: users</ref>
    </refs>
    <vuln_soft>
      <prod name="storefront" vendor="lagarde">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0558" seq="2003-0558" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105795219412333&amp;w=2">20030711 LeapFTP remote buffer overflow exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="leapftp" vendor="leapware">
        <vers num="2.7.3.600"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0559" seq="2003-0559" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105787021803729&amp;w=2">20030710 PHP-Include-Hack-Possibility in phpforum 2 RC-1</ref>
    </refs>
    <vuln_soft>
      <prod name="phpforum" vendor="phpforum">
        <vers num="2.0_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0560" seq="2003-0560" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105733277731084&amp;w=2">20030704 VPASP SQL Injection Vulnerability &amp; Exploit CODE</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8159" adv="1">8159</ref>
    </refs>
    <vuln_soft>
      <prod name="vp-asp" vendor="virtual_programming">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0561" seq="2003-0561" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0010.html">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105769805311484&amp;w=2">20030707 Multiple Buffer Overflows in IglooFTP PRO</ref>
    </refs>
    <vuln_soft>
      <prod name="iglooftp_pro" vendor="iglooftp">
        <vers num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0562" seq="2003-0562" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0041.html">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105897561229347&amp;w=2">20030723 NOVL-2003-2966549 - Enterprise Web Server PERL Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105897724931665&amp;w=2">20030723 Buffer Overflow in Netware Web Server PERL Handler</ref>
      <ref source="CONFIRM" url="http://support.novell.com/servlet/tidfinder/2966549">http://support.novell.com/servlet/tidfinder/2966549</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/185593">VU#185593</ref>
      <ref source="MISC" url="http://www.protego.dk/advisories/200301.html">http://www.protego.dk/advisories/200301.html</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="5.1" edition="sp4"/>
        <vers num="5.1" edition="sp6"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0564" seq="2003-0564" published="2003-12-01" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040402-01-U.asc">20040402-01-U</ref>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=108448379429944&amp;w=2">SSRT4722</ref>
      <ref source="FEDORA" url="http://marc.info/?l=bugtraq&amp;m=109900315219363&amp;w=2">FLSA:2089</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/428230" adv="1">VU#428230</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021">MDKSA-2004:021</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-110.html" adv="1" patch="1">RHSA-2004:110</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-112.html">RHSA-2004:112</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8981" adv="1">8981</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/smime.htm" adv="1" patch="1">http://www.uniras.gov.uk/vuls/2003/006489/smime.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13603">smime-asn1-bo(13603)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11462">oval:org.mitre.oval:def:11462</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A872">oval:org.mitre.oval:def:872</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A914">oval:org.mitre.oval:def:914</ref>
    </refs>
    <vuln_soft>
      <prod name="groupmax_mail_-_security_option" vendor="hitachi">
        <vers num="6.0"/>
      </prod>
      <prod name="pki_runtime_library" vendor="hitachi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0565" seq="2003-0565" published="2003-12-01" modified="2005-10-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927278" adv="1">VU#927278</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/x400.htm" adv="1">http://www.uniras.gov.uk/vuls/2003/006489/x400.htm</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0567" seq="2003-0567" published="2003-08-18" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006743.html">20030718 (no subject)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-15.html" adv="1" patch="1">CA-2003-15</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-17.html" adv="1" patch="1">CA-2003-17</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml">20030717 IOS Interface Blocked by IPv4 Packet</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/411332">VU#411332</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5603">oval:org.mitre.oval:def:5603</ref>
    </refs>
    <vuln_soft>
      <prod name="optical_networking_systems_software" vendor="cisco">
        <vers num="3.0"/>
        <vers num="3.1.0"/>
        <vers num="3.2.0"/>
        <vers num="3.3.0"/>
        <vers num="3.4.0"/>
        <vers num="4.0.0"/>
      </prod>
      <prod name="ons_15454_optical_transport_platform" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="11.0"/>
        <vers num="11.1"/>
        <vers num="11.1aa"/>
        <vers num="11.1ca"/>
        <vers num="11.1cc"/>
        <vers num="11.2"/>
        <vers num="11.2p"/>
        <vers num="11.2sa"/>
        <vers num="11.3"/>
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1m"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xk"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2ja"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2s"/>
        <vers num="12.2sx"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xw"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zj"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0568" seq="2003-0568" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0569" seq="2003-0569" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0570" seq="2003-0570" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0571" seq="2003-0571" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0572" seq="2003-0572" published="2003-08-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" adv="1" patch="1">20030701-01-P</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12635">irix-nsd-map-dos(12635)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0573" seq="2003-0573" published="2003-08-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030701-01-P" adv="1" patch="1">20030701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0574" seq="2003-0574" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030702-01-P" adv="1" patch="1">20030702-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17"/>
        <vers num="6.5.18"/>
        <vers num="6.5.19"/>
        <vers num="6.5.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0575" seq="2003-0575" published="2003-08-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to gain root privileges via the AUTH_UNIX gid list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030704-01-P" adv="1" patch="1">20030704-01-P</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105958240709302&amp;w=2">20030730 [LSD] IRIX nsd remote buffer overflow vulnerability</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-130.shtml">N-130</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/682900">VU#682900</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8304" adv="1">8304</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12763">irix-authunix-nsd-bo(12763)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0576" seq="2003-0576" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030801-01-P">20030801-01-P</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030801-02-P">20030801-02-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0577" seq="2003-0577" published="2003-08-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt">CSSA-2004-002.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000695" adv="1">CLA-2003:695</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:078">MDKSA-2003:078</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306903" patch="1">20030116 Re[2]: Local/remote mpg123 exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6629" adv="1" patch="1">6629</ref>
    </refs>
    <vuln_soft>
      <prod name="mpg123" vendor="mpg123">
        <vers num="0.59r"/>
        <vers num="pre0.59s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0578" seq="2003-0578" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0025.html" adv="1">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839150004682&amp;w=2">20030716 SRT2003-07-07-0831 - IBM U2 UniVerse cci_dir creates hard links as root</ref>
    </refs>
    <vuln_soft>
      <prod name="u2_universe" vendor="ibm">
        <vers num="10.0.0.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0579" seq="2003-0579" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0026.html" adv="1">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105838948002337&amp;w=2">20030716 SRT2003-07-07-0833 - IBM U2 UniVerse users with uvadm rights can take root via uvadmsh</ref>
    </refs>
    <vuln_soft>
      <prod name="u2_universe" vendor="ibm">
        <vers num="10.0.0.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0580" seq="2003-0580" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0028.html" adv="1" patch="1">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839042603476&amp;w=2">20030716 SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod name="u2_universe" vendor="ibm">
        <vers num="10.0.0.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0581" seq="2003-0581" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105829691405446&amp;w=2">20030714 xfstt-1.4 vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-360" adv="1" patch="1">DSA-360</ref>
    </refs>
    <vuln_soft>
      <prod name="xfstt" vendor="xfstt">
        <vers num="1.2.1"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0582" seq="2003-0582" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0504.  Reason: This candidate is a duplicate of CVE-2003-0504.  Notes: All CVE users should reference CVE-2003-0504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0583" seq="2003-0583" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105846288808846&amp;w=2">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod name="bru" vendor="tolis_group">
        <vers num="17.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0584" seq="2003-0584" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105846288808846&amp;w=2">20030716 SRT2003-07-16-0358 - bru has buffer overflow and format issues</ref>
    </refs>
    <vuln_soft>
      <prod name="bru" vendor="tolis_group">
        <vers num="17.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0585" seq="2003-0585" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105845898003616&amp;w=2">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod name="estore" vendor="brooky">
        <vers num="1.0.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0586" seq="2003-0586" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105845898003616&amp;w=2">20030717 eStore SQL Injection Vulnerability &amp; Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod name="estore" vendor="brooky">
        <vers num="1.0.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0587" seq="2003-0587" published="2003-08-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839276105934&amp;w=2">20030716 Changing UBB cookie allows account hijack</ref>
    </refs>
    <vuln_soft>
      <prod name="ultimate_bulletin_board" vendor="infopop">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0588" seq="2003-0588" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839007002993&amp;w=2">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod name="digi-news" vendor="digi-fx">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0589" seq="2003-0589" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839007002993&amp;w=2">20030716 Digi-news and Digi-ads version 1.1 admin access without password</ref>
    </refs>
    <vuln_soft>
      <prod name="digi-news" vendor="digi-fx">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0590" seq="2003-0590" published="2003-08-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105830019209609&amp;w=2">20030715 Splatt Forum html injection code in post icon</ref>
      <ref source="MISC" url="http://members.fortunecity.it/lethalman2002/bugs/splatt.html">http://members.fortunecity.it/lethalman2002/bugs/splatt.html</ref>
    </refs>
    <vuln_soft>
      <prod name="splatt_forum" vendor="splatt">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0591" seq="2003-0591" published="2003-08-27" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a duplicate number that was created during the refinement phase.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0592" seq="2003-0592" published="2004-04-15" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-459" adv="1" patch="1">DSA-459</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:022">MDKSA-2004:022</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-074.html" adv="1" patch="1">RHSA-2004:074</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A823">oval:org.mitre.oval:def:823</ref>
    </refs>
    <vuln_soft>
      <prod name="konqueror" vendor="kde">
        <vers num="2.1.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.5"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod name="konqueror_embedded" vendor="kde">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0593" seq="2003-0593" published="2004-04-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="5.0" edition=":linux"/>
        <vers num="5.0" edition=":mac"/>
        <vers num="5.0.2" edition=":win32"/>
        <vers num="5.1.0" edition=":win32"/>
        <vers num="5.1.1" edition=":win32"/>
        <vers num="5.12" edition=":win32"/>
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0.1" edition=":linux"/>
        <vers num="6.0.1" edition=":win32"/>
        <vers num="6.0.2" edition=":linux"/>
        <vers num="6.0.2" edition=":win32"/>
        <vers num="6.0.3" edition=":linux"/>
        <vers num="6.0.3" edition=":win32"/>
        <vers num="6.0.4" edition=":win32"/>
        <vers num="6.0.5" edition=":win32"/>
        <vers num="6.0.6" edition=":win32"/>
        <vers num="6.10" edition=":linux"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="7.0.2" edition=":win32"/>
        <vers num="7.0.3" edition=":win32"/>
        <vers num="7.0_beta1" edition=":win32"/>
        <vers num="7.0_beta2" edition=":win32"/>
        <vers num="7.10"/>
        <vers num="7.11"/>
        <vers num="7.11b"/>
        <vers num="7.11j"/>
        <vers num="7.20"/>
        <vers num="7.20_beta1_build2981"/>
        <vers num="7.21"/>
        <vers num="7.22"/>
        <vers num="7.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0594" seq="2003-0594" published="2004-04-15" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0056.html" adv="1">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018475.html">20040310 Corsaire Security Advisory: Multiple vendor HTTP user agent cookie path traversal issue</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021">MDKSA-2004:021</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-112.html">RHSA-2004:112</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A873">oval:org.mitre.oval:def:873</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A917">oval:org.mitre.oval:def:917</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9826">oval:org.mitre.oval:def:9826</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0595" seq="2003-0595" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0038.html" adv="1">20030718 Witango &amp; Tango 2000 Application Server Remote System Buffer Overrun</ref>
    </refs>
    <vuln_soft>
      <prod name="tango_server" vendor="witango">
        <vers num="2000"/>
      </prod>
      <prod name="witango_server" vendor="witango">
        <vers num="5.0.1.061"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0596" seq="2003-0596" published="2003-08-27" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to read or modify files of other fdclone users by creating the directory ahead of time.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=186219</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2003/dsa-352">DSA-352</ref>
    </refs>
    <vuln_soft>
      <prod name="fdclone" vendor="fdclone">
        <vers num="2.00a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0597" seq="2003-0597" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://marc.info/?l=bugtraq&amp;m=105889063714201&amp;w=2">CSSA-2003-SCO-11</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0598" seq="2003-0598" published="2003-08-27" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0657.  Reason: This candidate is a reservation duplicate of CVE-2003-0657.  Notes: All CVE users should reference CVE-2003-0657 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0599" seq="2003-0599" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html">http://mail.gnu.org/archive/html/phpgroupware-users/2003-07/msg00035.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-365">DSA-365</ref>
      <ref source="CONFIRM" url="http://www.phpgroupware.org">http://www.phpgroupware.org</ref>
    </refs>
    <vuln_soft>
      <prod name="phpgroupware" vendor="phpgroupware">
        <vers num="0.9.14.004" prev="1"/>
        <vers num="0.9.16prerc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0601" seq="2003-0601" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=25631" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=25631</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8266" adv="1" patch="1">8266</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12728">macos-workgroup-gain-access(12728)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0602" seq="2003-0602" published="2003-08-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653">CLA-2003:653</ref>
      <ref source="CONFIRM" url="http://www.bugzilla.org/security/2.16.2/">http://www.bugzilla.org/security/2.16.2/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6861" adv="1" patch="1">6861</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6868" adv="1" patch="1">6868</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0603" seq="2003-0603" published="2003-08-27" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000653" adv="1">CLA-2003:653</ref>
      <ref source="CONFIRM" url="http://www.bugzilla.org/security/2.16.2/">http://www.bugzilla.org/security/2.16.2/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7412" adv="1" patch="1">7412</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0604" seq="2003-0604" published="2003-08-27" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105899261818572&amp;w=2">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105906867322856&amp;w=2">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105899408520292&amp;w=2">20030723 Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105906261314411&amp;w=2">20030723 Re: Drivial Pursuit: Internet Explorer Browser &amp; Your Files and Folders !</ref>
      <ref source="MISC" url="http://www.malware.com/once.again!.html">http://www.malware.com/once.again!.html</ref>
      <ref source="MISC" url="http://www.pivx.com/larholm/unpatched/">http://www.pivx.com/larholm/unpatched/</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0605" seq="2003-0605" published="2003-08-27" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006851.html">20030721 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105880332428706&amp;w=2">20030720 Microsoft Windows 2000 RPC DCOM Interface DOS AND Privilege Escalation Vulnerability</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-19.html">CA-2003-19</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-23.html">CA-2003-23</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/326746">VU#326746</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039">MS03-039</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1118">oval:org.mitre.oval:def:1118</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A494">oval:org.mitre.oval:def:494</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0606" seq="2003-0606" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-353" adv="1" patch="1">DSA-353</ref>
    </refs>
    <vuln_soft>
      <prod name="cvsup-mirror" vendor="cvsup">
        <vers num="1.2"/>
      </prod>
      <prod name="sup" vendor="sup">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0607" seq="2003-0607" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-354" adv="1" patch="1">DSA-354</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8307" adv="1">8307</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12765">xconq-user-display-bo(12765)</ref>
    </refs>
    <vuln_soft>
      <prod name="xconq" vendor="stanley_t._shebs">
        <vers num="7.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0609" seq="2003-0609" published="2003-08-27" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105951760418667&amp;w=2">20030729 Solaris ld.so.1 buffer overflow</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55680">55680</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/advisory/07.29.03.txt">20030729 Buffer Overflow in Sun Solaris Runtime Linker</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12755">sun-ldso1-ldpreload-bo(12755)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3601">oval:org.mitre.oval:def:3601</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0610" seq="2003-0610" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp" adv="1" patch="1">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="epolicy_orchestrator" vendor="mcafee">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0611" seq="2003-0611" published="2003-08-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-356" adv="1" patch="1">DSA-356</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8312" adv="1" patch="1">8312</ref>
    </refs>
    <vuln_soft>
      <prod name="xtokkaetama" vendor="xtokkaetama">
        <vers num="1.0_b6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0612" seq="2003-0612" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203541</ref>
      <ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt">http://packages.debian.org/changelogs/pool/non-free/c/crafty/crafty_19.15-1/changelog.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1009393">1009393</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1009398">1009398</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357601">20040315 Crafty Game Stack Overflow &amp; Exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9893">9893</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13017">crafty-long-argument-bo(13017)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15501">crafty-command-line-bo(15501)</ref>
    </refs>
    <vuln_soft>
      <prod name="crafty" vendor="robert_hyatt">
        <vers num="19.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0613" seq="2003-0613" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-369" adv="1" patch="1">DSA-369</ref>
    </refs>
    <vuln_soft>
      <prod name="zblast" vendor="zblast">
        <vers num="1.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0614" seq="2003-0614" published="2003-08-27" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=82&amp;mode=thread&amp;order=0&amp;thold=0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252092421469&amp;w=2">20030902 GLSA:  gallery (200309-06)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-355" adv="1" patch="1">DSA-355</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/330676">20030727 Gallery XSS security advisory (with fix and patch instructions)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348641/30/21790/threaded">20040101 Re: Gallery v1.3.3 Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery" vendor="gallery_project">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.1_p1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0615" seq="2003-0615" published="2003-08-27" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000713">CLA-2003:713</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105880349328877&amp;w=2">20030720 CGI.pm vulnerable to Cross-site Scripting</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106018783704468&amp;w=2">20030806 [OpenPKG-SA-2003.036] OpenPKG Security Advisory (perl-www)</ref>
      <ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=105875211018698&amp;w=2">20030720 CGI.pm vulnerable to Cross-site Scripting.</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007234">1007234</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101426-1">101426</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-155.shtml">N-155</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-371">DSA-371</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/246409">VU#246409</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-256.html">RHSA-2003:256</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8231" adv="1" patch="1">8231</ref>
      <ref source="MANDRAKE" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:084">MDKSA-2003:084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12669">cgi-startform-xss(12669)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A307">oval:org.mitre.oval:def:307</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A470">oval:org.mitre.oval:def:470</ref>
    </refs>
    <vuln_soft>
      <prod name="cgi.pm" vendor="cgi.pm">
        <vers num="2.73"/>
        <vers num="2.74"/>
        <vers num="2.75"/>
        <vers num="2.76"/>
        <vers num="2.78"/>
        <vers num="2.79"/>
        <vers num="2.93"/>
        <vers num="2.751"/>
        <vers num="2.753"/>
      </prod>
      <prod name="openpkg" vendor="openpkg">
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="current"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0616" seq="2003-0616" published="2003-08-27" modified="2013-07-23" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a073103-1.txt">A073103-1</ref>
      <ref source="CONFIRM" url="http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp">http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="epolicy_orchestrator" vendor="mcafee">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0617" seq="2003-0617" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252097421549&amp;w=2">20030902 GLSA:  mindi (200309-05)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-362" adv="1" patch="1">DSA-362</ref>
    </refs>
    <vuln_soft>
      <prod name="mindi" vendor="hugo_rabson">
        <vers num="0.58_r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0618" seq="2003-0618" published="2004-05-04" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=203426</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-431" adv="1" patch="1">DSA-431</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9543">9543</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15012">suidperl-obtain-information(15012)</ref>
    </refs>
    <vuln_soft>
      <prod name="suidperl" vendor="perl">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0619" seq="2003-0619" published="2003-08-27" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105950927708272&amp;w=2">20030729 Remote Linux Kernel &lt; 2.4.21 DoS in XDR routine.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-358">DSA-358</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A386">oval:org.mitre.oval:def:386</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.21" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0620" seq="2003-0620" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105951284512898&amp;w=2">20030729 man-db[] multiple(4) vulnerabilities.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105960276803617&amp;w=2">20030730 Re: man-db[] multiple(4) vulnerabilities.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-364" adv="1" patch="1">DSA-364</ref>
    </refs>
    <vuln_soft>
      <prod name="man" vendor="andries_brouwer">
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.20"/>
        <vers num="2.4"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0621" seq="2003-0621" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" adv="1" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8931" adv="1" patch="1">8931</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13559">bea-tuxedo-file-disclosure(13559)</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="bea">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="7.1"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod name="weblogic_server" vendor="bea">
        <vers num="4.2" edition=":enterprise"/>
        <vers num="5.0.1" edition=":enterprise"/>
        <vers num="5.1" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0622" seq="2003-0622" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" adv="1" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8931" adv="1" patch="1">8931</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13560">bea-tuxedo-device-dos(13560)</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="bea">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="7.1"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod name="weblogic_server" vendor="bea">
        <vers num="4.2" edition=":enterprise"/>
        <vers num="5.0.1" edition=":enterprise"/>
        <vers num="5.1" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0623" seq="2003-0623" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp" adv="1" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/advisory03_38_00.jsp</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106762000607681&amp;w=2">20031031 Corsaire Security Advisory: BEA Tuxedo Administration CGI multiple argument issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8931" adv="1" patch="1">8931</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13561">bea-tuxedo-filename-xss(13561)</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="bea">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="7.1"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod name="weblogic_server" vendor="bea">
        <vers num="4.2" edition=":enterprise"/>
        <vers num="5.0.1" edition=":enterprise"/>
        <vers num="5.1" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0624" seq="2003-0624" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp" adv="1" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106761926906781&amp;w=2">20031031 Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8938" adv="1">8938</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13568">bea-weblogic-interactivequery-xss(13568)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="3.1.8"/>
        <vers num="8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0625" seq="2003-0625" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://developer.berlios.de/forum/forum.php?forum_id=2819">http://developer.berlios.de/forum/forum.php?forum_id=2819</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105941103709264&amp;w=2">20030727 [PAPER]: Address relay fingerprinting.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-360" adv="1" patch="1">DSA-360</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8255" adv="1">8255</ref>
    </refs>
    <vuln_soft>
      <prod name="xfstt" vendor="xfstt">
        <vers num="1.2.1"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0626" seq="2003-0626" published="2003-11-13" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html" adv="1">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html" adv="1">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3610">ESB-2003.0786</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9037" adv="1">9037</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13754">peoplesoft-searchcgi-directory-traversal(13754)</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.4"/>
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.19"/>
        <vers num="8.20"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
        <vers num="8.42"/>
        <vers num="8.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0627" seq="2003-0627" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0042.html">20031113 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013652.html">20031103 Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9038">9038</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13754">peoplesoft-searchcgi-directory-traversal(13754)</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.40"/>
        <vers num="8.41"/>
        <vers num="8.42"/>
        <vers num="8.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0628" seq="2003-0628" published="2003-12-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106874146204158&amp;w=2">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.4"/>
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.19"/>
        <vers num="8.20"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
        <vers num="8.42"/>
        <vers num="8.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0629" seq="2003-0629" published="2003-12-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106874146204158&amp;w=2">20031113 Corsaire Security Advisory: PeopleSoft Gateway Administration servlet path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.4"/>
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.19"/>
        <vers num="8.20"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
        <vers num="8.42"/>
        <vers num="8.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0630" seq="2003-0630" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252128221901&amp;w=2">20030902 GLSA:  atari800 (200309-07)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-359" adv="1" patch="1">DSA-359</ref>
    </refs>
    <vuln_soft>
      <prod name="atari800" vendor="atari800">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.1_pre0"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0631" seq="2003-0631" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105899875225268&amp;w=2">20030723 VMware GSX Server 2.5.1 / Workstation 4.0 (for Linux systems)</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1039</ref>
    </refs>
    <vuln_soft>
      <prod name="gsx_server" vendor="vmware">
        <vers num="2.5.1"/>
      </prod>
      <prod name="workstation" vendor="vmware">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0632" seq="2003-0632" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105906721920776&amp;w=2">20030724 Integrigy Security Alert - Oracle E-Business Suite FNDWRR Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="applications" vendor="oracle">
        <vers num="10.7"/>
        <vers num="11.0"/>
      </prod>
      <prod name="e-business_suite" vendor="oracle">
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.3"/>
        <vers num="11.4"/>
        <vers num="11.5"/>
        <vers num="11.6"/>
        <vers num="11.7"/>
        <vers num="11.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0633" seq="2003-0633" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105906689120237&amp;w=2">20030724 Integrigy Security Alert - Oracle E-Business Suite AOL/J Setup Test Information Disclosure</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8268">8268</ref>
    </refs>
    <vuln_soft>
      <prod name="applications" vendor="oracle">
        <vers num="10.7"/>
        <vers num="11.0"/>
      </prod>
      <prod name="e-business_suite" vendor="oracle">
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.3"/>
        <vers num="11.4"/>
        <vers num="11.5"/>
        <vers num="11.6"/>
        <vers num="11.7"/>
        <vers num="11.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0634" seq="2003-0634" published="2003-08-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0105.html">20030912 Update to the Oracle EXTPROC advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105914979629857&amp;w=2">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105916455814904&amp;w=2">20030725 question about oracle advisory</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=105915485303327&amp;w=2">20030725 Oracle Extproc Buffer Overflow (#NISR25072003)</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/936868">VU#936868</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8267" adv="1" patch="1">8267</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12721">oracle-extproc-bo(12721)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="enterprise_8.1.5_.0.0"/>
        <vers num="enterprise_8.1.5_.0.2"/>
        <vers num="enterprise_8.1.5_.1.0"/>
        <vers num="enterprise_8.1.6_.0.0"/>
        <vers num="enterprise_8.1.6_.1.0"/>
        <vers num="enterprise_8.1.7_.0.0"/>
        <vers num="enterprise_8.1.7_.1.0"/>
        <vers num="standard_8.1.5"/>
        <vers num="standard_8.1.6"/>
        <vers num="standard_8.1.7"/>
        <vers num="standard_8.1.7_.0.0"/>
        <vers num="standard_8.1.7_.1"/>
        <vers num="standard_8.1.7_.4"/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num="client_9.2.0.1"/>
        <vers num="client_9.2.0.2"/>
        <vers num="enterprise_9.0.1"/>
        <vers num="enterprise_9.2.0.1"/>
        <vers num="enterprise_9.2.0.2"/>
        <vers num="personal_9.0.1"/>
        <vers num="personal_9.2.0.1"/>
        <vers num="personal_9.2.0.2"/>
        <vers num="standard_9.0"/>
        <vers num="standard_9.0.1"/>
        <vers num="standard_9.0.1.2"/>
        <vers num="standard_9.0.1.3"/>
        <vers num="standard_9.0.1.4"/>
        <vers num="standard_9.0.2"/>
        <vers num="standard_9.2.0.1"/>
        <vers num="standard_9.2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0635" seq="2003-0635" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="ichain" vendor="novell">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0636" seq="2003-0636" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="ichain" vendor="novell">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0637" seq="2003-0637" published="2003-08-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="ichain" vendor="novell">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0638" seq="2003-0638" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via (1) a long user name or (2) an unknown attack related to a "special script against login."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105492847631711&amp;w=2">20030606 NOVL-2003-2966207 - iChain 2.1 Field Patch 3</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="ichain" vendor="novell">
        <vers num="2.1" edition="sp1"/>
        <vers num="2.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0639" seq="2003-0639" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105492852131747&amp;w=2">20030606 NOVL-2003-2966205 - iChain 2.2 Field Patch 1a</ref>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966435.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="ichain" vendor="novell">
        <vers num="2.1" edition="sp1"/>
        <vers num="2.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0640" seq="2003-0640" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-33.jsp</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0641" seq="2003-0641" published="2003-08-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105848106631132&amp;w=2">20030717 Bypassing ServerLock protection on Windows 2000</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8222" adv="1">8222</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12665">serverlock-openprocess-load-module(12665)</ref>
    </refs>
    <vuln_soft>
      <prod name="serverlock" vendor="watchguard">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0642" seq="2003-0642" published="2003-08-27" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WatchGuard ServerLock for Windows 2000 before SL 2.0.4 allows local users to access kernel memory via a symlink attack on \Device\PhysicalMemory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105848106631132&amp;w=2">20030717 Bypassing ServerLock protection on Windows 2000</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8223" adv="1">8223</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12666">serverlock-physicalmemory-symlink(12666)</ref>
    </refs>
    <vuln_soft>
      <prod name="serverlock" vendor="watchguard">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0643" seq="2003-0643" published="2003-07-25" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog">http://gentoo.kems.net/gentoo-x86-portage/sys-kernel/gentoo-sources/ChangeLog</ref>
      <ref source="MISC" url="http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml">http://www.ultramonkey.org/bugs/cve/CAN-2003-0643.shtml</ref>
      <ref source="MISC" url="http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch">http://www.ultramonkey.org/bugs/cve-patch/CAN-2003-0643.patch</ref>
      <ref source="CONFIRM" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0644" seq="2003-0644" published="2003-09-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kdbg 1.1.0 through 1.2.8 does not check permissions of the .kdbgrc file, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://lists.debian.org/debian-devel-changes/2003/09/msg00767.html" adv="1">[debian-devel-changes] 20030909 Accepted kdbg 1.2.9-1 (i386 source)</ref>
      <ref source="CONFIRM" url="http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2" adv="1" patch="1">http://lists.kde.org/?l=kde-announce&amp;m=106296509815092&amp;w=2</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-416.html">RHSA-2005:416</ref>
    </refs>
    <vuln_soft>
      <prod name="kdbg" vendor="johannes_sixt">
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0645" seq="2003-0645" published="2003-08-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106018504800341&amp;w=2">20030806 man-db[v2.4.1-]: open_cat_stream() privileged call exploit.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-364" adv="1" patch="1">DSA-364</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8352">8352</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12848">mandb-opencatstream-gain-privileges(12848)</ref>
    </refs>
    <vuln_soft>
      <prod name="man" vendor="andries_brouwer">
        <vers num="2.3.20"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0646" seq="2003-0646" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionID=15274</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-July/006488.html">20030711 Trend Micro ActiveX Multiple Overflows</ref>
    </refs>
    <vuln_soft>
      <prod name="damage_cleanup_server" vendor="trend_micro">
        <vers num="1.0"/>
      </prod>
      <prod name="housecall" vendor="trend_micro">
        <vers num="5.5"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0647" seq="2003-0647" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sn-20030730-ios-2gb-get.shtml" adv="1" patch="1">20030731 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579324" adv="1" patch="1">VU#579324</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0648" seq="2003-0648" published="2004-05-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1009655">1009655</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1009656">1009656</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-472" adv="1" patch="1">DSA-472</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/354838">VU#354838</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/900964">VU#900964</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10041">10041</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15726">ftetexteditor-vfte-bo(15726)</ref>
    </refs>
    <vuln_soft>
      <prod name="fte_text_editor" vendor="fte">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0649" seq="2003-0649" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-368" adv="1" patch="1">DSA-368</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053">MDKSA-2004:053</ref>
    </refs>
    <vuln_soft>
      <prod name="xpcd" vendor="xpcd">
        <vers num="2.08" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0650" seq="2003-0650" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0064.html">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105958779017085&amp;w=2">20030730 GameSpy Arcade Arbitrary File Writing Vulnerability</ref>
      <ref source="MISC" url="http://www.gamespyarcade.com/features/versions.shtml">http://www.gamespyarcade.com/features/versions.shtml</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8309" adv="1" patch="1">8309</ref>
    </refs>
    <vuln_soft>
      <prod name="arcade" vendor="gamespy">
        <vers num="1.3e" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0651" seq="2003-0651" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-07/0355.html" adv="1" patch="1">20030728 Remotely exploitable overflow in mod_mylo for Apache</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8287" adv="1" patch="1">8287</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_mylo" vendor="mod_mylo">
        <vers num="0.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0652" seq="2003-0652" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability than CVE-2003-0611.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106001473329625&amp;w=2">20030803 xtokkaetama[v1.0b+]: (missed) buffer overflow exploit.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-367" adv="1" patch="1">DSA-367</ref>
    </refs>
    <vuln_soft>
      <prod name="xtokkaetama" vendor="xtokkaetama">
        <vers num="1.0_b6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0653" seq="2003-0653" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or crash) via certain OSI packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-010.txt.asc">NetBSD-SA2003-010</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0654" seq="2003-0654" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-373">DSA-373</ref>
    </refs>
    <vuln_soft>
      <prod name="autorespond" vendor="autorespond">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0655" seq="2003-0655" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is running with privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105978381618095&amp;w=2">20030801 SRT2003-08-01-0126 - cdrtools local root exploit</ref>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt">http://www.secnetops.com/research/advisories/SRT2003-08-01-0126.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="cdrtools" vendor="cdrtools">
        <vers num="2.0"/>
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0656" seq="2003-0656" published="2003-08-27" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252649028401&amp;w=2">20030902 GLSA:  eroaster (200309-04)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-366" adv="1" patch="1">DSA-366</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:083">MDKSA-2003:083</ref>
    </refs>
    <vuln_soft>
      <prod name="eroaster" vendor="eroaster">
        <vers num="2.0.0"/>
        <vers num="2.1.0"/>
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0657" seq="2003-0657" published="2003-08-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unauthorized database actions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-365" adv="1" patch="1">DSA-365</ref>
    </refs>
    <vuln_soft>
      <prod name="phpgroupware" vendor="phpgroupware">
        <vers num="0.9.14" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0658" seq="2003-0658" published="2003-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openlinux_server" vendor="caldera">
        <vers num="3.1.1"/>
      </prod>
      <prod name="openlinux_workstation" vendor="caldera">
        <vers num="3.1.1"/>
      </prod>
      <prod name="openserver" vendor="caldera">
        <vers num="5.0.7"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0659" seq="2003-0659" published="2003-11-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106631999907035&amp;w=2">20031016 Listbox And Combobox Control Buffer Overflow</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106632111408343&amp;w=2">20031016 Listbox And Combobox Control Buffer Overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/967668" adv="1" patch="1">VU#967668</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8827" adv="1" patch="1">8827</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-045">MS03-045</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13424">win-user32-control-bo(13424)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A201">oval:org.mitre.oval:def:201</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A340">oval:org.mitre.oval:def:340</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0660" seq="2003-0660" published="2003-11-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/838572" adv="1" patch="1">VU#838572</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8830" adv="1" patch="1">8830</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-041">MS03-041</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13422">win-authenticode-code-execution(13422)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A185">oval:org.mitre.oval:def:185</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A198">oval:org.mitre.oval:def:198</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0661" seq="2003-0661" published="2003-10-20" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/989932">VU#989932</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-034">MS03-034</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3483">oval:org.mitre.oval:def:3483</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0662" seq="2003-0662" published="2003-11-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.html" adv="1" patch="1">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106632192709608&amp;w=2">20031016 Microsoft Local Troubleshooter ActiveX control buffer overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/989932" adv="1" patch="1">VU#989932</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8833" adv="1" patch="1">8833</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-042">MS03-042</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13423">win2k-local-troubleshooter-bo(13423)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A237">oval:org.mitre.oval:def:237</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0663" seq="2003-0663" published="2004-06-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/639428" adv="1" patch="1">VU#639428</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10114">10114</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15700">win2k-lsass-ldap-dos(15700)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1016">oval:org.mitre.oval:def:1016</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0664" seq="2003-0664" published="2003-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-035">MS03-035</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A188" adv="1">oval:org.mitre.oval:def:188</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="97" edition="sr1"/>
        <vers num="97" edition="sr2"/>
        <vers num="98" edition="::ja"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2000" edition="sr1a"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
      <prod name="works" vendor="microsoft">
        <vers num="2001"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0665" seq="2003-0665" published="2003-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/992132">VU#992132</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8536">8536</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-038">MS03-038</ref>
    </refs>
    <vuln_soft>
      <prod name="access" vendor="microsoft">
        <vers num="97"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0666" seq="2003-0666" published="2003-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0092.html" adv="1">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106261952827573&amp;w=2">20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106279971612961&amp;w=2">20030905 Microsoft WordPerfect Document Converter Exploit</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-036">MS03-036</ref>
    </refs>
    <vuln_soft>
      <prod name="wordperfect_converter" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0669" seq="2003-0669" published="2003-08-27" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F47353" adv="1" patch="1">47353</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4561">oval:org.mitre.oval:def:4561</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0670" seq="2003-0670" published="2003-08-27" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a080703-1.txt" adv="1" patch="1">A080703-1</ref>
    </refs>
    <vuln_soft>
      <prod name="ipnetmonitorx" vendor="sustainable_softworks">
        <vers num=""/>
      </prod>
      <prod name="ipnetsentryx" vendor="sustainable_softworks">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0671" seq="2003-0671" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a080703-1.txt" adv="1" patch="1">A080703-1</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a080703-2.txt">A080703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpflow" vendor="jeremy_elson">
        <vers num="0.10"/>
        <vers num="0.11"/>
        <vers num="0.12"/>
        <vers num="0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0672" seq="2003-0672" published="2003-08-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-370" adv="1" patch="1">DSA-370</ref>
    </refs>
    <vuln_soft>
      <prod name="pam-pgsql" vendor="leon_j_breedt">
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0676" seq="2003-0676" published="2003-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106036588613929&amp;w=2">20030808 Directory Traversal in Sun iPlanet Administration Server 5.1</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_directory_server" vendor="sun">
        <vers num="5.0"/>
        <vers num="5.1" edition="sp1"/>
        <vers num="5.1" edition="sp2"/>
      </prod>
      <prod name="one_directory_server" vendor="sun">
        <vers num="5.0" edition="sp1"/>
        <vers num="5.0_sp2"/>
        <vers num="5.1" edition="sp1"/>
        <vers num="5.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0677" seq="2003-0677" published="2003-08-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0073.html" adv="1">20030807 Cisco CSS 11000 Series DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0079.html">20030808 Re: [VulnWatch] Cisco CSS 11000 Series DoS</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/332284" adv="1" patch="1">20030807 Cisco CSS 11000 Series DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="webns" vendor="cisco">
        <vers num="5.0_0.038s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0678" seq="2003-0678" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0679" seq="2003-0679" published="2003-08-27" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030802-01-P">20030802-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.21f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0680" seq="2003-0680" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030901-01-P">20030901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0681" seq="2003-0681" published="2003-10-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742">CLA-2003:742</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106383437615742&amp;w=2">20030917 GLSA:  sendmail (200309-13)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106398718909274&amp;w=2">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-384">DSA-384</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/108964">VU#108964</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092">MDKSA-2003:092</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-283.html">RHSA-2003:283</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8649" adv="1">8649</ref>
      <ref source="CONFIRM" url="http://www.sendmail.org/8.12.10.html" patch="1">http://www.sendmail.org/8.12.10.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13216">sendmail-ruleset-parsing-bo(13216)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3606">oval:org.mitre.oval:def:3606</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A595">oval:org.mitre.oval:def:595</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_message_server" vendor="sendmail">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
      <prod name="sendmail" vendor="sendmail">
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="8.8.8"/>
        <vers num="8.9.0"/>
        <vers num="8.9.1"/>
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.11.4"/>
        <vers num="8.11.5"/>
        <vers num="8.11.6"/>
        <vers num="8.12" edition="beta10"/>
        <vers num="8.12" edition="beta12"/>
        <vers num="8.12" edition="beta16"/>
        <vers num="8.12" edition="beta5"/>
        <vers num="8.12" edition="beta7"/>
        <vers num="8.12.0"/>
        <vers num="8.12.1"/>
        <vers num="8.12.2"/>
        <vers num="8.12.3"/>
        <vers num="8.12.4"/>
        <vers num="8.12.5"/>
        <vers num="8.12.6"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
        <vers num="8.12.9"/>
      </prod>
      <prod name="sendmail_pro" vendor="sendmail">
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
      </prod>
      <prod name="sendmail_switch" vendor="sendmail">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod name="linux" vendor="gentoo">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.11"/>
        <vers num="11.22"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.3"/>
        <vers num="1.5" edition=":sh3"/>
        <vers num="1.5" edition=":x86"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6" edition="beta"/>
        <vers num="1.6.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="3.2"/>
        <vers num="3.3"/>
      </prod>
      <prod name="turbolinux_advanced_server" vendor="turbolinux">
        <vers num="6.0"/>
      </prod>
      <prod name="turbolinux_server" vendor="turbolinux">
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
      <prod name="turbolinux_workstation" vendor="turbolinux">
        <vers num="6.0"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0682" seq="2003-0682" published="2003-10-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741">CLA-2003:741</ref>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2">RHSA-2003:279</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-382" adv="1" patch="1">DSA-382</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-383">DSA-383</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-280.html" adv="1" patch="1">RHSA-2003:280</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A446">oval:org.mitre.oval:def:446</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0683" seq="2003-0683" published="2003-11-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031004-01-P">20031004-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8921" adv="1" patch="1">8921</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0684" seq="2003-0684" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0685" seq="2003-0685" published="2003-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netris 0.52 and earlier, and possibly other versions, allows remote malicious Netris servers to execute arbitrary code on netris clients via a long server response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106071059430211&amp;w=2">20030812 Netris client Buffer Overflow Vulnerability.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-372" adv="1">DSA-372</ref>
    </refs>
    <vuln_soft>
      <prod name="netris" vendor="netris">
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0686" seq="2003-0686" published="2003-10-20" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000734">CLA-2003:734</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252769930090&amp;w=2">20030901 GLSA:  pam_smb (200309-01)</ref>
      <ref source="CONFIRM" url="http://us2.samba.org/samba/ftp/pam_smb/">http://us2.samba.org/samba/ftp/pam_smb/</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-374" adv="1" patch="1">DSA-374</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/680260">VU#680260</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-261.html">RHSA-2003:261</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-262.html" adv="1" patch="1">RHSA-2003:262</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-50.txt">TLSA-2003-50</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A469">oval:org.mitre.oval:def:469</ref>
    </refs>
    <vuln_soft>
      <prod name="pam_smb" vendor="dave_airlie">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="2.0_rc4"/>
      </prod>
      <prod name="pam_smb" vendor="redhat">
        <vers num="1.1.6-2" edition=":i386"/>
        <vers num="1.1.6-2" edition=":ia64"/>
        <vers num="1.1.6-5" edition=":i386"/>
        <vers num="1.1.6-7" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0687" seq="2003-0687" published="2004-08-18" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was internally assigned to a problem that was not reachable (the affected routine was not used by the software).  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0688" seq="2003-0688" published="2003-10-20" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030803-01-P">20030803-01-P</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000727">CLA-2003:727</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/993452">VU#993452</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:086">MDKSA-2003:086</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_035_sendmail.html">SuSE-SA:2003:035</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-265.html" adv="1" patch="1">RHSA-2003:265</ref>
      <ref source="CONFIRM" url="http://www.sendmail.org/dnsmap1.html">http://www.sendmail.org/dnsmap1.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A597">oval:org.mitre.oval:def:597</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="redhat">
        <vers num="8.12.5-7" edition=":i386"/>
        <vers num="8.12.5-7" edition=":i386_cf"/>
        <vers num="8.12.5-7" edition=":i386_dev"/>
        <vers num="8.12.5-7" edition=":i386_doc"/>
        <vers num="8.12.8-4" edition=":i386"/>
        <vers num="8.12.8-4" edition=":i386_cf"/>
        <vers num="8.12.8-4" edition=":i386_dev"/>
        <vers num="8.12.8-4" edition=":i386_doc"/>
      </prod>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.12.1"/>
        <vers num="8.12.2"/>
        <vers num="8.12.3"/>
        <vers num="8.12.4"/>
        <vers num="8.12.5"/>
        <vers num="8.12.6"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="5.0a"/>
        <vers num="5.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.8"/>
        <vers num="5.0"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="3.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.19"/>
        <vers num="6.5.20"/>
        <vers num="6.5.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0689" seq="2003-0689" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-249.html" adv="1" patch="1">RHSA-2003:249</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-325.html">RHSA-2003:325</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":workstation_ia64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0690" seq="2003-0690" published="2003-10-06" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106374551513499&amp;w=2">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-388">DSA-388</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20030916-1.txt" adv="1" patch="1">http://www.kde.org/info/security/advisory-20030916-1.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091">MDKSA-2003:091</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-270.html" adv="1" patch="1">RHSA-2003:270</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-286.html">RHSA-2003:286</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-287.html">RHSA-2003:287</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-288.html">RHSA-2003:288</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-289.html">RHSA-2003:289</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A193">oval:org.mitre.oval:def:193</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0_beta"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3a"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5a"/>
        <vers num="3.0.5b"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.1a"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0691" seq="2003-0691" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not associated with any specific security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0692" seq="2003-0692" published="2003-10-06" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html">http://cert.uni-stuttgart.de/archive/suse/security/2002/12/msg00101.html</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106374551513499&amp;w=2">20030916 [KDE SECURITY ADVISORY] KDM vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-388" adv="1" patch="1">DSA-388</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20030916-1.txt" adv="1" patch="1">http://www.kde.org/info/security/advisory-20030916-1.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:091">MDKSA-2003:091</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-270.html" adv="1" patch="1">RHSA-2003:270</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-288.html">RHSA-2003:288</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A215">oval:org.mitre.oval:def:215</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0_beta"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3a"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5a"/>
        <vers num="3.0.5b"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.1a"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0693" seq="2003-0693" published="2003-09-22" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010103.html">20030915 new ssh exploit?</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010135.html">20030915 openssh remote exploit</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010146.html">20030916 The lowdown on SSH vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106373247528528&amp;w=2">20030916 OpenSSH Buffer Management Bug Advisory</ref>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2">RHSA-2003:279</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106374466212309&amp;w=2">20030916 [slackware-security]  OpenSSH Security Advisory (SSA:2003-259-01)</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=106381396120332&amp;w=2">2003-0033</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000620.1-1">1000620</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-24.html">CA-2003-24</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-382">DSA-382</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-383">DSA-383</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/333628" adv="1" patch="1">VU#333628</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090">MDKSA-2003:090</ref>
      <ref source="CONFIRM" url="http://www.openssh.com/txt/buffer.adv">http://www.openssh.com/txt/buffer.adv</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-280.html">RHSA-2003:280</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13191">openssh-packet-bo(13191)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2719">oval:org.mitre.oval:def:2719</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A447">oval:org.mitre.oval:def:447</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0694" seq="2003-0694" published="2003-10-06" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt">SCOSA-2004.11</ref>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/4119.html">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html">20030917 Zalewski Advisory - Sendmail 8.12.9 prescan bug</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000742">CLA-2003:742</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106381604923204&amp;w=2">20030917 Sendmail 8.12.9 prescan bug (a new one) [CAN-2003-0694]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106382859407683&amp;w=2">20030917 [slackware-security]  Sendmail vulnerabilities fixed (SSA:2003-260-02)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106383437615742&amp;w=2">20030917 GLSA:  sendmail (200309-13)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106398718909274&amp;w=2">20030919 [OpenPKG-SA-2003.041] OpenPKG Security Advisory (sendmail)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-25.html" adv="1" patch="1">CA-2003-25</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-384">DSA-384</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/784980">VU#784980</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:092">MDKSA-2003:092</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-283.html">RHSA-2003:283</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-284.html">RHSA-2003:284</ref>
      <ref source="CONFIRM" url="http://www.sendmail.org/8.12.10.html" patch="1">http://www.sendmail.org/8.12.10.html</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2975">oval:org.mitre.oval:def:2975</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A572">oval:org.mitre.oval:def:572</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A603">oval:org.mitre.oval:def:603</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_message_server" vendor="sendmail">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
      <prod name="sendmail" vendor="sendmail">
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="8.8.8"/>
        <vers num="8.9.0"/>
        <vers num="8.9.1"/>
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.11.4"/>
        <vers num="8.11.5"/>
        <vers num="8.11.6"/>
        <vers num="8.12" edition="beta10"/>
        <vers num="8.12" edition="beta12"/>
        <vers num="8.12" edition="beta16"/>
        <vers num="8.12" edition="beta5"/>
        <vers num="8.12" edition="beta7"/>
        <vers num="8.12.0"/>
        <vers num="8.12.1"/>
        <vers num="8.12.2"/>
        <vers num="8.12.3"/>
        <vers num="8.12.4"/>
        <vers num="8.12.5"/>
        <vers num="8.12.6"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
        <vers num="8.12.9"/>
      </prod>
      <prod name="sendmail_pro" vendor="sendmail">
        <vers num="8.9.2"/>
        <vers num="8.9.3"/>
      </prod>
      <prod name="sendmail_switch" vendor="sendmail">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0f_pk8_bl22"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="4.0g_pk4_bl22"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1a_pk4_bl21"/>
        <vers num="5.1a_pk5_bl23"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
        <vers num="5.1b_pk2_bl22"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0" edition="releng"/>
        <vers num="4.0" edition="releng"/>
        <vers num="4.3" edition="release_p38"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.4" edition="release_p42"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.5" edition="release_p32"/>
        <vers num="4.5" edition="releng"/>
        <vers num="4.6" edition="release_p20"/>
        <vers num="4.6" edition="releng"/>
        <vers num="4.7" edition="release_p17"/>
        <vers num="4.7" edition="releng"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="5.0" edition="release_p14"/>
        <vers num="5.0" edition="releng"/>
        <vers num="5.1" edition="release_p5"/>
        <vers num="5.1" edition="releng"/>
      </prod>
      <prod name="linux" vendor="gentoo">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.11"/>
        <vers num="11.22"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.3"/>
        <vers num="1.5" edition=":sh3"/>
        <vers num="1.5" edition=":x86"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6" edition="beta"/>
        <vers num="1.6.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
      <prod name="turbolinux_advanced_server" vendor="turbolinux">
        <vers num="6.0"/>
      </prod>
      <prod name="turbolinux_server" vendor="turbolinux">
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
      <prod name="turbolinux_workstation" vendor="turbolinux">
        <vers num="6.0"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0695" seq="2003-0695" published="2003-10-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000741">CLA-2003:741</ref>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;m=106373546332230&amp;w=2">RHSA-2003:279</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=106381396120332&amp;w=2">2003-0033</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106381409220492&amp;w=2">20030917 [OpenPKG-SA-2003.040] OpenPKG Security Advisory (openssh)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106382542403716&amp;w=2">20030917 [slackware-security]  OpenSSH updated again (SSA:2003-260-01)</ref>
      <ref source="MISC" url="http://marc.info/?l=openbsd-security-announce&amp;m=106375582924840">http://marc.info/?l=openbsd-security-announce&amp;m=106375582924840</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-382">DSA-382</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-383" adv="1" patch="1">DSA-383</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:090">MDKSA-2003:090</ref>
      <ref source="CONFIRM" url="http://www.openssh.com/txt/buffer.adv">http://www.openssh.com/txt/buffer.adv</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-280.html" adv="1" patch="1">RHSA-2003:280</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A452">oval:org.mitre.oval:def:452</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0696" seq="2003-0696" published="2004-01-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8738" adv="1" patch="1">8738</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13328">aix-sendmail-getipnodebyname-dos(13328)</ref>
      <ref source="CONFIRM" url="https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true">https://techsupport.services.ibm.com/server/pseries.subscriptionSvcs?mode=7&amp;heading=AIX51&amp;topic=SECURITY&amp;month=200310&amp;label=getipnodebyname%28%29+API+does+not+close+sockets.&amp;date=20031001&amp;bulletin=datafile150755&amp;embed=true</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0697" seq="2003-0697" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1">http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1605.1</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45250&amp;apar=only">IY45250</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY45344&amp;apar=only" adv="1">IY45344</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY46256&amp;apar=only">IY46256</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0698" seq="2003-0698" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0743.  Reason: This candidate is a duplicate of CVE-2003-0743.  Notes: All CVE users should reference CVE-2003-0743 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0699" seq="2003-0699" published="2003-08-27" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-198.html" adv="1" patch="1">RHSA-2003:198</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-239.html">RHSA-2003:239</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A387">oval:org.mitre.oval:def:387</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
      </prod>
      <prod name="linux_advanced_workstation" vendor="redhat">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0700" seq="2003-0700" published="2004-02-17" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-238.html" adv="1" patch="1">RHSA-2003:238</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-044.html" adv="1" patch="1">RHSA-2004:044</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A401">oval:org.mitre.oval:def:401</ref>
    </refs>
    <vuln_soft>
      <prod name="kernel" vendor="redhat">
        <vers num="2.4.21" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0701" seq="2003-0701" published="2003-08-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106148101210479&amp;w=2">20030820 [SNS Advisory No.68] Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/334928">VU#334928</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032">MS03-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12970">ie-dbcs-object-bo(12970)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6.0" edition=":windows_server_2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0702" seq="2003-0702" published="2003-10-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server (IIS) via a certain URL through SSL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106278164225389&amp;w=2">20030905 ISS Server Sensor Denial of Service</ref>
      <ref source="MISC" url="http://www.enteredge.com/research/CAN-2003-0702.asp">http://www.enteredge.com/research/CAN-2003-0702.asp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13088">realsecure-isapi-dos(13088)</ref>
    </refs>
    <vuln_soft>
      <prod name="realsecure_server_sensor" vendor="iss">
        <vers num="7.0" edition="xpu20.16"/>
        <vers num="7.0" edition="xpu20.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0703" seq="2003-0703" published="2003-09-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KisMAC before 0.05d trusts user-supplied variables to load arbitrary kernels or kernel modules, which allows local users to gain privileges via the $DRIVER_KEXT environment variable as used in (1) viha_driver.sh, (2) macjack_load.sh, or (3) airojack_load.sh, or (4) via "similar techniques" using exchangeKernel.sh.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a082203-1.txt" adv="1" patch="1">A082203-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8497" adv="1">8497</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13007">kismac-driverkext-load-modules(13007)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13008">kismac-exchangekernel-kernel-overwrite(13008)</ref>
    </refs>
    <vuln_soft>
      <prod name="kismac" vendor="kismac">
        <vers num="0.05d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0704" seq="2003-0704" published="2003-09-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KisMAC before 0.05d trusts user-supplied variables when chown'ing files or directories, which allows local users to gain privileges via the $DRIVER_KEXT environment variable in (1) viha_driver.sh, (2) macjack_load.sh, (3) airojack_load.sh, (4) setuid_enable.sh, (5) setuid_disable.sh, and using a "similar technique" for (6) viha_prep.sh and (7) viha_unprep.sh.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a082203-1.txt" adv="1" patch="1">A082203-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8497" adv="1">8497</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13006">kismac-driverkext-modify-ownership(13006)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13009">kismac-setuid-modify-ownership(13009)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13010">kismac-viha-gain-privileges(13010)</ref>
    </refs>
    <vuln_soft>
      <prod name="kismac" vendor="kismac">
        <vers num="0.05d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0705" seq="2003-0705" published="2003-09-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-378" patch="1">DSA-378</ref>
    </refs>
    <vuln_soft>
      <prod name="mah-jong" vendor="nicolas_boullis">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0706" seq="2003-0706" published="2003-09-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-378" patch="1">DSA-378</ref>
    </refs>
    <vuln_soft>
      <prod name="mah-jong" vendor="nicolas_boullis">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0707" seq="2003-0707" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-375" adv="1" patch="1">DSA-375</ref>
    </refs>
    <vuln_soft>
      <prod name="linuxnode" vendor="tomi_manninen">
        <vers num="0.3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0708" seq="2003-0708" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-375" adv="1" patch="1">DSA-375</ref>
    </refs>
    <vuln_soft>
      <prod name="linuxnode" vendor="tomi_manninen">
        <vers num="0.3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0709" seq="2003-0709" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.zone-h.org/en/advisories/read/id=2925/" adv="1" patch="1">http://www.zone-h.org/en/advisories/read/id=2925/</ref>
    </refs>
    <vuln_soft>
      <prod name="whois" vendor="whois">
        <vers num="4.5.7"/>
        <vers num="4.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0711" seq="2003-0711" published="2003-11-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106631908105696&amp;w=2">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106632194809632&amp;w=2">20031016 Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/467036" adv="1" patch="1">VU#467036</ref>
      <ref source="MISC" url="http://www.ngssoftware.com/advisories/ms-pchealth.txt">http://www.ngssoftware.com/advisories/ms-pchealth.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8828" adv="1" patch="1">8828</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-044">MS03-044</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A217">oval:org.mitre.oval:def:217</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3685">oval:org.mitre.oval:def:3685</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3889">oval:org.mitre.oval:def:3889</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4706">oval:org.mitre.oval:def:4706</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0712" seq="2003-0712" published="2003-11-17" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106631918405915&amp;w=2">20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435444" adv="1" patch="1">VU#435444</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8832" adv="1" patch="1">8832</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047">MS03-047</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="5.5" edition="sp3"/>
        <vers num="5.5" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0714" seq="2003-0714" published="2003-11-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106682909006586&amp;w=2">20031022 MS03-046 Microsoft Exchange 2000 Heap Overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/422156" adv="1" patch="1">VU#422156</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8838" adv="1" patch="1">8838</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046">MS03-046</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="5.5" edition="sp3"/>
        <vers num="5.5" edition="sp4"/>
        <vers num="2000" edition="sp1"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0715" seq="2003-0715" published="2003-09-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322856608909&amp;w=2">20030910 EEYE: Microsoft RPC Heap Corruption Vulnerability - Part II</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-23.html">CA-2003-23</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/483492">VU#483492</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039">MS03-039</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1202">oval:org.mitre.oval:def:1202</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1813">oval:org.mitre.oval:def:1813</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A20">oval:org.mitre.oval:def:20</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A264">oval:org.mitre.oval:def:264</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4224">oval:org.mitre.oval:def:4224</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0717" seq="2003-0717" published="2003-11-17" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106666713812158&amp;w=2">20031018 Proof of concept for Windows Messenger Service overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106632188709562&amp;w=2">20031016 MS03-043 Popup Messenger Servce buffer-overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-27.html">CA-2003-27</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/575892" adv="1" patch="1">VU#575892</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8826" adv="1" patch="1">8826</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-043">MS03-043</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A213">oval:org.mitre.oval:def:213</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A268">oval:org.mitre.oval:def:268</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0718" seq="2003-0718" published="2004-11-03" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109762641822064&amp;w=2">20041012 Microsoft IIS 5.x/6.0 WebDAV (XML parser) attribute blowup DoS</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-030">MS04-030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/17645">iis-webdav-xml-attribute-dos(17645)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/17656">iis-ms04030-patch(17656)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1330">oval:org.mitre.oval:def:1330</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1427">oval:org.mitre.oval:def:1427</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4767">oval:org.mitre.oval:def:4767</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0719" seq="2003-0719" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/586540" adv="1" patch="1">VU#586540</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/361836" adv="1" patch="1">20040430 A technical description of the SSL PCT vulnerability (CVE-2003-0719)</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/168" adv="1" patch="1">20040413 Microsoft SSL Library Remote Compromise Vulnerability</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093">oval:org.mitre.oval:def:1093</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889">oval:org.mitre.oval:def:889</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903">oval:org.mitre.oval:def:903</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951">oval:org.mitre.oval:def:951</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0720" seq="2003-0720" published="2003-09-17" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0099.html">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322571805153&amp;w=2">20030910 iDEFENSE Security Advisory 09.10.03: Two Exploitable Overflows in PINE</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106329356702508&amp;w=2">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/09.10.03.txt" adv="1" patch="1">http://www.idefense.com/advisory/09.10.03.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-273.html" adv="1" patch="1">RHSA-2003:273</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-274.html">RHSA-2003:274</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A499">oval:org.mitre.oval:def:499</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="3.98"/>
        <vers num="4.0.2"/>
        <vers num="4.0.4"/>
        <vers num="4.10"/>
        <vers num="4.20"/>
        <vers num="4.21"/>
        <vers num="4.30"/>
        <vers num="4.33"/>
        <vers num="4.44"/>
        <vers num="4.50"/>
        <vers num="4.52"/>
        <vers num="4.53"/>
        <vers num="4.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0721" seq="2003-0721" published="2003-09-17" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009850.html">20030911 Pine: .procmailrc rule against integer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106329356702508&amp;w=2">20030911 [slackware-security]  security issues in pine (SSA:2003-253-01)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106367213400313&amp;w=2">20030915 remote Pine &lt;= 4.56 exploit fully automatic</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/advisory/09.10.03.txt" adv="1" patch="1">20030910 Two Exploitable Overflows in PINE</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-273.html" adv="1" patch="1">RHSA-2003:273</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-274.html">RHSA-2003:274</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A503">oval:org.mitre.oval:def:503</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="3.98"/>
        <vers num="4.0.2"/>
        <vers num="4.0.4"/>
        <vers num="4.10"/>
        <vers num="4.20"/>
        <vers num="4.21"/>
        <vers num="4.30"/>
        <vers num="4.33"/>
        <vers num="4.44"/>
        <vers num="4.50"/>
        <vers num="4.52"/>
        <vers num="4.53"/>
        <vers num="4.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0722" seq="2003-0722" published="2003-09-22" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0115.html">20030918 Solaris SADMIND Exploitation</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106391959014331&amp;w=2">20030918 Solaris SADMIND Exploitation</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56740-1&amp;searchclause=security">56740</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-148.shtml">N-148</ref>
      <ref source="MISC" url="http://www.idefense.com/advisory/09.16.03.txt">http://www.idefense.com/advisory/09.16.03.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/41870">VU#41870</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8615">8615</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1273">oval:org.mitre.oval:def:1273</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0723" seq="2003-0723" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:087">MDKSA-2003:087</ref>
    </refs>
    <vuln_soft>
      <prod name="gkrellm" vendor="gkrellm">
        <vers num="2.1.7"/>
        <vers num="2.1.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0724" seq="2003-0724" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5736" adv="1">SSRT3588</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8492" adv="1" patch="1">8492</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="compaq">
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1a_pk4_bl21"/>
        <vers num="5.1a_pk5_bl23"/>
        <vers num="5.1b_pk2_bl22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0725" seq="2003-0725" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0087.html" adv="1">20030825 New Bug in RealServer</ref>
      <ref source="MISC" url="http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html">http://lists.immunitysec.com/pipermail/dailydave/2003-August/000030.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/934932" adv="1">VU#934932</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8476" adv="1" patch="1">8476</ref>
      <ref source="CONFIRM" url="http://www.service.real.com/help/faq/security/rootexploit082203.html">http://www.service.real.com/help/faq/security/rootexploit082203.html</ref>
    </refs>
    <vuln_soft>
      <prod name="helix_universal_server" vendor="realnetworks">
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2.794"/>
      </prod>
      <prod name="realserver" vendor="realnetworks">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0_beta"/>
        <vers num="g2_1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0726" seq="2003-0726" published="2003-10-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007532">1007532</ref>
      <ref source="MISC" url="http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html" adv="1" patch="1">http://www.digitalpranksters.com/advisories/realnetworks/smilscriptprotocol.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/335293" adv="1">20030827 RealOne Player Allows Cross Zone and Domain Access</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8453" adv="1" patch="1">8453</ref>
      <ref source="CONFIRM" url="http://www.service.real.com/help/faq/security/securityupdate_august2003.html">http://www.service.real.com/help/faq/security/securityupdate_august2003.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13028">realone-smil-execute-code(13028)</ref>
    </refs>
    <vuln_soft>
      <prod name="realone_desktop_manager" vendor="realnetworks">
        <vers num=""/>
      </prod>
      <prod name="realone_enterprise_desktop" vendor="realnetworks">
        <vers num="6.0.11.774"/>
      </prod>
      <prod name="realone_player" vendor="realnetworks">
        <vers num="2.0"/>
        <vers num="6.0.10.505" edition="gold"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0727" seq="2003-0727" published="2003-10-20" modified="2017-09-27" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf">http://otn.oracle.com/deploy/security/pdf/2003Alert58.pdf</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42780/">42780</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0728" seq="2003-0728" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106081310531567&amp;w=2">20030813 PCL-0001: Remote Vulnerability in HORDE MTA &lt; 2.2.4</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252836330987&amp;w=2">20030901 GLSA:  horde (200309-02)</ref>
    </refs>
    <vuln_soft>
      <prod name="horde" vendor="horde">
        <vers num="2.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0729" seq="2003-0729" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0091.html" adv="1">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252411425545&amp;w=2">20030901 Security Vulnerability in Tellurian TftpdNT (Long Filename)</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html" adv="1">http://www.securiteam.com/windowsntfocus/5RP0M1PAUM.html</ref>
    </refs>
    <vuln_soft>
      <prod name="tftpdnt" vendor="tellurian">
        <vers num="1.8"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0730" seq="2003-0730" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-015.txt.asc">NetBSD-SA2003-015</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031101-01-U.asc">20031101-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106229335312429&amp;w=2">20030830 Multiple integer overflows in XFree86 (local/remote)</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1">102803</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm">http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380" adv="1" patch="1">DSA-380</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:089">MDKSA-2003:089</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-286.html" adv="1" patch="1">RHSA-2003:286</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-287.html">RHSA-2003:287</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-288.html">RHSA-2003:288</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-289.html">RHSA-2003:289</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8514" adv="1" patch="1">8514</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2007/0589">ADV-2007-0589</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="4.2.1"/>
        <vers num="4.3.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0731" seq="2003-0731" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" adv="1" patch="1">20030813 CiscoWorks Application Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/333028" adv="1">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="ciscoworks_common_management_foundation" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="resource_manager" vendor="cisco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="resource_manager_essentials" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="ciscoworks_cd1" vendor="cisco">
        <vers num="1st"/>
        <vers num="2nd"/>
        <vers num="3rd"/>
        <vers num="4th"/>
        <vers num="5th"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0732" seq="2003-0732" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030813-cmf.shtml" adv="1" patch="1">20030813 CiscoWorks Application Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/333028" adv="1">20030813 Portcullis Security Advisory: CiscoWorks 2000 Privilege Escalation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="ciscoworks_common_management_foundation" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="resource_manager" vendor="cisco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="resource_manager_essentials" vendor="cisco">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="ciscoworks_cd1" vendor="cisco">
        <vers num="1st"/>
        <vers num="2nd"/>
        <vers num="3rd"/>
        <vers num="4th"/>
        <vers num="5th"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0733" seq="2003-0733" published="2003-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8357" adv="1" patch="1">8357</ref>
    </refs>
    <vuln_soft>
      <prod name="liquid_data" vendor="bea">
        <vers num="1.1"/>
      </prod>
      <prod name="weblogic_integration" vendor="bea">
        <vers num="2.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="weblogic_server" vendor="bea">
        <vers num="5.1"/>
        <vers num="7.0" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0734" seq="2003-0734" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:088">MDKSA-2003:088</ref>
    </refs>
    <vuln_soft>
      <prod name="pam_ldap" vendor="padl_software">
        <vers num="162" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0735" seq="2003-0735" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/925166">VU#925166</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebsite" vendor="phpwebsite">
        <vers num="0.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0736" seq="2003-0736" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2">20030902 GLSA:  phpwebsite (200309-03)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/664422">VU#664422</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebsite" vendor="phpwebsite">
        <vers num="0.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0737" seq="2003-0737" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2">20030902 GLSA:  phpwebsite (200309-03)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebsite" vendor="phpwebsite">
        <vers num="0.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0738" seq="2003-0738" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106062021711496&amp;w=2">20030810 phpWebSite SQL Injection &amp; DoS &amp; XSS Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252188522715&amp;w=2">20030902 GLSA:  phpwebsite (200309-03)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebsite" vendor="phpwebsite">
        <vers num="0.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0739" seq="2003-0739" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106029217115023&amp;w=2">20030807 VMware Workstation 4.0.1 (for Linux systems) vulnerability</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106" adv="1" patch="1">http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1106</ref>
    </refs>
    <vuln_soft>
      <prod name="workstation" vendor="vmware">
        <vers num="4.0.1_build_5289" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0740" seq="2003-0740" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000736">CLA-2003:736</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106260760211958&amp;w=2">20030903 Stunnel-3.x Daemon Hijacking</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:108">MDKSA-2003:108</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-297.html">RHSA-2003:297</ref>
    </refs>
    <vuln_soft>
      <prod name="stunnel" vendor="stunnel">
        <vers num="3.3"/>
        <vers num="3.4a"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.21a"/>
        <vers num="3.21b"/>
        <vers num="3.21c"/>
        <vers num="3.22"/>
        <vers num="3.24"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0741" seq="2003-0741" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0742" seq="2003-0742" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0743" seq="2003-0743" published="2003-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000735">CLA-2003:735</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106252015820395&amp;w=2">20030901 exim remote heap overflow, probably not exploitable</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=106264740820334&amp;w=2">20030903 Re: exim remote heap overflow, probably not exploitable</ref>
      <ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog">http://packages.debian.org/changelogs/pool/main/e/exim/exim_3.36-13/changelog</ref>
      <ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog">http://packages.debian.org/changelogs/pool/main/e/exim4/exim4_4.34-10/changelog</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-376" adv="1" patch="1">DSA-376</ref>
      <ref source="CONFIRM" url="http://www.exim.org/pipermail/exim-announce/2003q3/000094.html">http://www.exim.org/pipermail/exim-announce/2003q3/000094.html</ref>
      <ref source="MLIST" url="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057720.html">[Exim] 20030814 Minor security bug</ref>
      <ref source="MLIST" url="http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030811/057809.html">[Exim] 20030815 Minor security bug</ref>
    </refs>
    <vuln_soft>
      <prod name="exim" vendor="university_of_cambridge">
        <vers num="3.0"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.17"/>
        <vers num="3.18"/>
        <vers num="3.19"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="4.10"/>
        <vers num="4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0744" seq="2003-0744" published="2003-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/" adv="1">20030903 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</ref>
      <ref source="CONFIRM" url="http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt">http://leafnode.sourceforge.net/leafnode-SA-2003-01.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106270038210736&amp;w=2">20030904 leafnode 1.9.3 - 1.9.41 security announcement SA-2003-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8541">8541</ref>
    </refs>
    <vuln_soft>
      <prod name="leafnode" vendor="leafnode">
        <vers num="1.9.19"/>
        <vers num="1.9.20"/>
        <vers num="1.9.21"/>
        <vers num="1.9.22"/>
        <vers num="1.9.23"/>
        <vers num="1.9.24"/>
        <vers num="1.9.25"/>
        <vers num="1.9.26"/>
        <vers num="1.9.27"/>
        <vers num="1.9.29"/>
        <vers num="1.9.30"/>
        <vers num="1.9.31"/>
        <vers num="1.9.35"/>
        <vers num="1.9.36"/>
        <vers num="1.9.37"/>
        <vers num="1.9.38"/>
        <vers num="1.9.39"/>
        <vers num="1.9.40"/>
        <vers num="1.9.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0745" seq="2003-0745" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0340.html" adv="1" patch="1">20030825 SNMPc v5 and v6 remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="snmpc" vendor="castle_rock_computing">
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="6.0.5"/>
        <vers num="6.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0746" seq="2003-0746" published="2003-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerabilities CVE-2003-0352 or CVE-2003-0605, such as the Blaster/MSblast/LovSAN worm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030902-01-P">20030902-01-P</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q3/0042.html">HPSBUX0308-274</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/377804" adv="1">VU#377804</ref>
    </refs>
    <vuln_soft>
      <prod name="openview" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0747" seq="2003-0747" published="2003-10-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" adv="1">20030830 SAP Internet Transaction Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8515" adv="1">8515</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13063">its-wgatedll-information-disclosure(13063)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4620.2.0.323011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0748" seq="2003-0748" published="2003-10-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" adv="1">20030830 SAP Internet Transaction Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8516" adv="1">8516</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13066">its-wgatedll-directory-traversal(13066)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4620.2.0.323011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0749" seq="2003-0749" published="2003-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.html" adv="1">20030830 SAP Internet Transaction Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8517" adv="1">8517</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4620.2.0.323011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0750" seq="2003-0750" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod name="py-membres" vendor="py-membres">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0751" seq="2003-0751" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0089.html" adv="1">20030826 [PHP] PY-Membres 4.2 : Admin Access, SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod name="py-membres" vendor="py-membres">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0752" seq="2003-0752" published="2003-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0090.html" adv="1">20030826 [PHP] AttilaPHP 3.0 : User/Admin Access</ref>
    </refs>
    <vuln_soft>
      <prod name="attilaphp" vendor="attila-php.net">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0753" seq="2003-0753" published="2003-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" adv="1">20030824 newsPHP file inclusion &amp; bad login validation</ref>
    </refs>
    <vuln_soft>
      <prod name="newsphp" vendor="newsphp">
        <vers num="216" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0754" seq="2003-0754" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html" adv="1">20030824 newsPHP file inclusion &amp; bad login validation</ref>
    </refs>
    <vuln_soft>
      <prod name="newsphp" vendor="newsphp">
        <vers num="216" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0755" seq="2003-0755" published="2003-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2003-q3/0101.html" adv="1">20030826 gtkftpd[v1.0.4(and below)]: remote root buffer overflow exploit.</ref>
    </refs>
    <vuln_soft>
      <prod name="gtkftp" vendor="gtkftpd">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0756" seq="2003-0756" published="2003-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0011.html">20030831 Directory Traversal in SITEBUILDER - v1.4</ref>
    </refs>
    <vuln_soft>
      <prod name="sitebuilder" vendor="sitebuilder">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0757" seq="2003-0757" published="2003-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0018.html" adv="1">20030902 IRM 007: The IP addresses of Check Point Firewall-1 internal interfaces may be enumerated using SecuRemote</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0758" seq="2003-0758" published="2003-10-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106389919618721&amp;w=2">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-154.shtml">N-154</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8552" adv="1" patch="1">8552</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13218">ibm-db2-db2dart-bo(13218)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0759" seq="2003-0759" published="2003-10-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0114.html">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106389919618721&amp;w=2">20030918 CORE-2003-0531: Multiple IBM DB2 Stack Overflow Vulnerabilities</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-154.shtml">N-154</ref>
      <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=366&amp;idxseccion=10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8553" adv="1" patch="1">8553</ref>
      <ref source="AIXAPAR" url="http://www-3.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/aparlib.d2w/display_apar_details?aparno=IY47653">IY47653</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0760" seq="2003-0760" published="2003-09-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html" patch="1">http://www.securiteam.com/windowsntfocus/5RP0N15AUC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8482" adv="1">8482</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13012">blubster-port701-dos(13012)</ref>
    </refs>
    <vuln_soft>
      <prod name="blubster" vendor="optisoft">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0761" seq="2003-0761" published="2003-09-17" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arbitrary code via certain (1) MESSAGE or (2) INFO requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a090403-1.txt" adv="1">A090403-1</ref>
    </refs>
    <vuln_soft>
      <prod name="asterisk" vendor="digium">
        <vers num="1.2.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0762" seq="2003-0762" published="2003-09-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0096.html" adv="1">20030905 [SCAN Associates Sdn Bhd Security Advisory] Foxweb 2.5 bufferoverflow in CGI and ISAPI extension</ref>
    </refs>
    <vuln_soft>
      <prod name="foxweb" vendor="foxweb">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0763" seq="2003-0763" published="2003-09-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106312344631197&amp;w=2">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod name="escapade" vendor="squished_mosquito">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0764" seq="2003-0764" published="2003-09-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Escapade Scripting Engine (ESP) allows remote attackers to obtain sensitive path information via a malformed request, which leaks the information in an error message, as demonstrated using the PAGE parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106312344631197&amp;w=2">20030909 Escapade Scripting Engine XSS Vulnerability and Path Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod name="escapade" vendor="squished_mosquito">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0765" seq="2003-0765" published="2003-09-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106305643432112&amp;w=2">20030908 Winamp 2.91 lets code execution through MIDI files</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="2.81"/>
        <vers num="2.91"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0766" seq="2003-0766" published="2003-09-17" modified="2017-04-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106305502230604&amp;w=2">20030908 Multiple Heap Overflows in FTP Desktop</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_desktop" vendor="ftp_desktop">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0767" seq="2003-0767" published="2003-09-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106304902323758&amp;w=2">20030908 Rogerwilco: server's buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="roger_wilco_dedicated_server" vendor="gamespy">
        <vers num="0.26"/>
        <vers num="0.27"/>
        <vers num="0.28"/>
        <vers num="0.29"/>
        <vers num="0.30a"/>
      </prod>
      <prod name="roger_wilco_graphical_server" vendor="gamespy">
        <vers num="1.4.1.1"/>
        <vers num="1.4.1.2"/>
        <vers num="1.4.1.3"/>
        <vers num="1.4.1.4"/>
        <vers num="1.4.1.5"/>
        <vers num="1.4.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0768" seq="2003-0768" published="2003-09-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106304326916062&amp;w=2">20030908 Advisory: Incorrect Handling of XSS Protection in ASP.Net</ref>
    </refs>
    <vuln_soft>
      <prod name="asp.net" vendor="microsoft">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0769" seq="2003-0769" published="2003-09-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="2003a_build3777"/>
        <vers num="2003a_build3799"/>
        <vers num="2003a_build3800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0770" seq="2003-0770" published="2003-09-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106381136115972&amp;w=2">20030917 Exploit: IkonBoard 3.1.1/3.1.2a arbitrary command execution</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317234" adv="1" patch="1">20030401 IkonBoard v3.1.1: arbitrary command execution</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/336598">20030908 IkonBoard 3.1.2a arbitrary command execution</ref>
    </refs>
    <vuln_soft>
      <prod name="ikonboard" vendor="ikonboard.com">
        <vers num="3.1.1"/>
        <vers num="3.1.2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0771" seq="2003-0771" published="2003-09-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106304236914921&amp;w=2">20030907 Apache::Gallery local webserver compromise, privilege escalation</ref>
    </refs>
    <vuln_soft>
      <prod name="apache_gallery" vendor="apache_gallery">
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0772" seq="2003-0772" published="2003-09-22" modified="2019-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106288825902868&amp;w=2">20030906 Remote and Local Vulnerabilities In WS_FTP Server</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/219140">VU#219140</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/792284">VU#792284</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8542" adv="1">8542</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13119">wsftp-ftp-command-bo(13119)</ref>
    </refs>
    <vuln_soft>
      <prod name="ws_ftp_server" vendor="ipswitch">
        <vers num="4.01"/>
      </prod>
      <prod name="ipswitch_ws_ftp_server" vendor="progress">
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0773" seq="2003-0773" published="2003-09-22" modified="2013-08-23" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8595" adv="1" patch="1">8595</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0774" seq="2003-0774" published="2003-09-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379" adv="1" patch="1">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0775" seq="2003-0775" published="2003-09-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379" adv="1" patch="1">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8600" adv="1" patch="1">8600</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0776" seq="2003-0776" published="2003-09-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379" adv="1" patch="1">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0777" seq="2003-0777" published="2003-09-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379" adv="1" patch="1">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8597">8597</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0778" seq="2003-0778" published="2003-09-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt">CSSA-2004-005.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-379" adv="1" patch="1">DSA-379</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:099">MDKSA-2003:099</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_046_sane.html">SuSE-SA:2003:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-278.html" adv="1" patch="1">RHSA-2003:278</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-285.html">RHSA-2003:285</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8593">8593</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8596">8596</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_beta1"/>
        <vers num="1.0.7_beta2"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod name="sane-backend" vendor="sane">
        <vers num="1.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0779" seq="2003-0779" published="2003-09-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a091103-1.txt" adv="1">A091103-1</ref>
    </refs>
    <vuln_soft>
      <prod name="asterisk" vendor="digium">
        <vers num="0.1.7"/>
        <vers num="0.1.8"/>
        <vers num="0.1.9"/>
        <vers num="0.1.9.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0780" seq="2003-0780" published="2003-09-22" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009819.html">20030910 Buffer overflow in MySQL</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106364207129993&amp;w=2">20030913 exploit for mysql -- [get_salt_from_password] problem</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=106381424420775&amp;w=2">2003-0034</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-381" adv="1" patch="1">DSA-381</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/516492">VU#516492</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:094">MDKSA-2003:094</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-281.html" adv="1" patch="1">RHSA-2003:281</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-282.html">RHSA-2003:282</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/337012" adv="1" patch="1">20030910 Buffer overflow in MySQL</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="mysql">
        <vers num="4.1.0" edition="alpha"/>
        <vers num="4.1.0.0"/>
      </prod>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23"/>
        <vers num="3.23.2"/>
        <vers num="3.23.3"/>
        <vers num="3.23.4"/>
        <vers num="3.23.5"/>
        <vers num="3.23.8"/>
        <vers num="3.23.9"/>
        <vers num="3.23.10"/>
        <vers num="3.23.22"/>
        <vers num="3.23.23"/>
        <vers num="3.23.24"/>
        <vers num="3.23.25"/>
        <vers num="3.23.26"/>
        <vers num="3.23.27"/>
        <vers num="3.23.28" edition="gamma"/>
        <vers num="3.23.29"/>
        <vers num="3.23.30"/>
        <vers num="3.23.31"/>
        <vers num="3.23.32"/>
        <vers num="3.23.33"/>
        <vers num="3.23.34"/>
        <vers num="3.23.36"/>
        <vers num="3.23.37"/>
        <vers num="3.23.38"/>
        <vers num="3.23.39"/>
        <vers num="3.23.40"/>
        <vers num="3.23.41"/>
        <vers num="3.23.42"/>
        <vers num="3.23.43"/>
        <vers num="3.23.44"/>
        <vers num="3.23.45"/>
        <vers num="3.23.46"/>
        <vers num="3.23.47"/>
        <vers num="3.23.48"/>
        <vers num="3.23.49"/>
        <vers num="3.23.50"/>
        <vers num="3.23.51"/>
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.53a"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
        <vers num="3.23.55"/>
        <vers num="3.23.56"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7" edition="gamma"/>
        <vers num="4.0.8" edition="gamma"/>
        <vers num="4.0.9" edition="gamma"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11" edition="gamma"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0781" seq="2003-0781" published="2004-05-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-467" patch="1">DSA-467</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12929">ecartis-subscribe-password-disclosure(12929)</ref>
    </refs>
    <vuln_soft>
      <prod name="ecartis" vendor="ecartis">
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0782" seq="2003-0782" published="2004-05-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-467" patch="1">DSA-467</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12928">ecartis-multiple-bo(12928)</ref>
    </refs>
    <vuln_soft>
      <prod name="ecartis" vendor="ecartis">
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0783" seq="2003-0783" published="2003-10-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106424495804417&amp;w=2">20030921 Fw: 0x333hztty => hztty 2.0 local root exploit</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007756">1007756</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007757">1007757</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-385" adv="1" patch="1">DSA-385</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8656" adv="1" patch="1">8656</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13243">hztty-bo(13243)</ref>
    </refs>
    <vuln_soft>
      <prod name="hztty" vendor="yongguang_zhang">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0784" seq="2003-0784" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47764&amp;apar=only">IY47764</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0785" seq="2003-0785" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-389" adv="1" patch="1">DSA-389</ref>
    </refs>
    <vuln_soft>
      <prod name="ipmasq" vendor="brian_bassett">
        <vers num="3.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0786" seq="2003-0786" published="2003-11-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/602204">VU#602204</ref>
      <ref source="CONFIRM" url="http://www.openssh.com/txt/sshpam.adv">http://www.openssh.com/txt/sshpam.adv</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/338616">20030923 Portable OpenSSH 3.7.1p2 released</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/338617">20030923 Multiple PAM vulnerabilities in portable OpenSSH</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8677">8677</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.7.1"/>
        <vers num="3.7.1p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0787" seq="2003-0787" published="2003-11-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html">20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/209807">VU#209807</ref>
      <ref source="CONFIRM" url="http://www.openssh.com/txt/sshpam.adv">http://www.openssh.com/txt/sshpam.adv</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/338616">20030923 Portable OpenSSH 3.7.1p2 released</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/338617">20030923 Multiple PAM vulnerabilities in portable OpenSSH</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8677">8677</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.7.1"/>
        <vers num="3.7.1p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0788" seq="2003-0788" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=97958</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000779">CLA-2003:779</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000788">CLA-2003:788</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:104">MDKSA-2003:104</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-275.html" adv="1" patch="1">RHSA-2003:275</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8952" adv="1" patch="1">8952</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-63.txt">TLSA-2003-63</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13584">cups-ipp-dos(13584)</ref>
    </refs>
    <vuln_soft>
      <prod name="cups" vendor="easy_software_products">
        <vers num="1.0.4"/>
        <vers num="1.0.4_8"/>
        <vers num="1.1.1"/>
        <vers num="1.1.4"/>
        <vers num="1.1.4_2"/>
        <vers num="1.1.4_3"/>
        <vers num="1.1.4_5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.10"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0789" seq="2003-0789" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://apache.secsup.org/dist/httpd/Announcement2.html" adv="1">http://apache.secsup.org/dist/httpd/Announcement2.html</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000775">CLA-2003:775</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00045.html">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106761802305141&amp;w=2">20031031 GLSA:  apache (200310-04)</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200310-04.xml">200310-04</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-015.shtml">O-015</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:103">MDKSA-2003:103</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-320.html" adv="1" patch="1">RHSA-2003:320</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/6079">HPSBUX0311-301</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8926">8926</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13552">apache-modcgi-info-disclosure(13552)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E">[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.48" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0790" seq="2003-0790" published="2003-11-17" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: the reported issue is not a vulnerability or exposure.  Notes: This candidate was assigned to a "head-reading" bug in a component of fetchmail 6.2.4 and earlier, which was claimed to allow a denial of service.  However, the bug is in a broken component of fetchmail that is not "reachable" by any execution path, so it cannot be triggered by any sort of attack and is not exploitable.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0791" seq="2003-0791" published="2003-10-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:021">MDKSA-2004:021</ref>
      <ref source="SCO" url="http://www.securityfocus.com/advisories/6979" adv="1" patch="1">SCOSA-2004.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9322" adv="1" patch="1">9322</ref>
      <ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=221526" adv="1" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=221526</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="0.8"/>
        <vers num="0.9.2"/>
        <vers num="0.9.2.1"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.35"/>
        <vers num="0.9.48"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0792" seq="2003-0792" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-004.0/CSSA-2004-004.0.txt">CSSA-2004-004.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107731542827401&amp;w=2">20040220 LNSA-#2004-0002: Fetchmail 6.2.4 and earlier remote denial of service</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-10.xml" adv="1">GLSA-200403-10</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:101">MDKSA-2003:101</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/advisories/5987">IMNX-2003-7+-023-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8843" adv="1" patch="1">8843</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-61.txt">TLSA-2003-61</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13450">fetchmail-email-dos(13450)</ref>
    </refs>
    <vuln_soft>
      <prod name="fetchmail" vendor="fetchmail">
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.1.0"/>
        <vers num="5.1.4"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.3"/>
        <vers num="5.3.8"/>
        <vers num="5.4.0"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.5.0"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.6.0"/>
        <vers num="5.7.0"/>
        <vers num="5.7.2"/>
        <vers num="5.7.4"/>
        <vers num="5.8"/>
        <vers num="5.8.1"/>
        <vers num="5.8.2"/>
        <vers num="5.8.3"/>
        <vers num="5.8.4"/>
        <vers num="5.8.5"/>
        <vers num="5.8.6"/>
        <vers num="5.8.11"/>
        <vers num="5.8.13"/>
        <vers num="5.8.14"/>
        <vers num="5.8.17"/>
        <vers num="5.9.0"/>
        <vers num="5.9.4"/>
        <vers num="5.9.5"/>
        <vers num="5.9.8"/>
        <vers num="5.9.10"/>
        <vers num="5.9.11"/>
        <vers num="5.9.13"/>
        <vers num="6.0.0"/>
        <vers num="6.1.0"/>
        <vers num="6.1.3"/>
        <vers num="6.2.0"/>
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.3"/>
        <vers num="6.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0793" seq="2003-0793" published="2003-11-17" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766">CLA-2003:766</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100">MDKSA-2003:100</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8846" adv="1" patch="1">8846</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13447">gdm-dos(13447)</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.2.5.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
        <vers num="2.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0794" seq="2003-0794" published="2003-11-17" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome">http://cvs.gnome.org/bonsai/cvsblame.cgi?file=gdm2/NEWS&amp;rev=&amp;root=/cvs/gnome</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000766">CLA-2003:766</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:100">MDKSA-2003:100</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8846" adv="1" patch="1">8846</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13448">gdm-command-dos(13448)</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.2.5.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1.1"/>
        <vers num="2.4.1.2"/>
        <vers num="2.4.1.3"/>
        <vers num="2.4.1.4"/>
        <vers num="2.4.1.5"/>
        <vers num="2.4.1.6"/>
        <vers num="2.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0795" seq="2003-0795" published="2003-12-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106883387304266&amp;w=2">20031114 Quagga remote vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-415" adv="1" patch="1">DSA-415</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-305.html" adv="1" patch="1">RHSA-2003:305</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-307.html" adv="1" patch="1">RHSA-2003:307</ref>
    </refs>
    <vuln_soft>
      <prod name="zebra" vendor="gnu">
        <vers num="0.91a"/>
        <vers num="0.92a"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
      </prod>
      <prod name="quagga" vendor="quagga">
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.96.1"/>
        <vers num="0.96.2"/>
        <vers num="0.96.3" prev="1"/>
      </prod>
      <prod name="propack" vendor="sgi">
        <vers num="2.2.1"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0796" seq="2003-0796" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc">20031102-01-P</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc">20031102-02-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9085" adv="1">9085</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13807">rpcmountd-mount-gain-access(13807)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0797" seq="2003-0797" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031102-01-P.asc">20031102-01-P</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031102-02-P.asc">20031102-02-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9084" adv="1">9084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13808">rpcmountd-dos(13808)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14"/>
        <vers num="6.5.15"/>
        <vers num="6.5.16"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0798" seq="2003-0798" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0799" seq="2003-0799" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0800" seq="2003-0800" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0801" seq="2003-0801" published="2003-10-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod name="electronic_documentation" vendor="nokia">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0802" seq="2003-0802" published="2003-10-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod name="electronic_documentation" vendor="nokia">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0803" seq="2003-0803" published="2003-10-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a091503-1.txt" adv="1">A091503-1</ref>
    </refs>
    <vuln_soft>
      <prod name="electronic_documentation" vendor="nokia">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0804" seq="2003-0804" published="2003-11-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:14.arp.asc">FreeBSD-SA-03:14</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc">20040502-01-P</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.6.2"/>
        <vers num="4.7"/>
        <vers num="4.8"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0805" seq="2003-0805" published="2003-10-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105804485302211&amp;w=2">20030712 UMN gopherd[2.x.x/3.x.x]: ftp gateway, and GSisText() buffer</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106123498310717&amp;w=2">20030818 FW: [gopher] UMN Gopher 3.0.6 released</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-387" adv="1" patch="1">DSA-387</ref>
    </refs>
    <vuln_soft>
      <prod name="gopherd" vendor="university_of_minnesota">
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0806" seq="2003-0806" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/471260" adv="1" patch="1">VU#471260</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10126">10126</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15702">win-winlogon-bo(15702)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1054">oval:org.mitre.oval:def:1054</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A895">oval:org.mitre.oval:def:895</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A896">oval:org.mitre.oval:def:896</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0807" seq="2003-0807" published="2004-06-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Apr/1009762.html">1009762</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-115.shtml">O-115</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698564" adv="1" patch="1">VU#698564</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10123">10123</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012">MS04-012</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15709">win-cis-rpc-http-dos(15709)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1030">oval:org.mitre.oval:def:1030</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A969">oval:org.mitre.oval:def:969</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A995">oval:org.mitre.oval:def:995</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0809" seq="2003-0809" published="2003-11-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8565" adv="1" patch="1">8565</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-040">MS03-040</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13300">ie-xmlobject-code-execution(13300)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A123">oval:org.mitre.oval:def:123</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0812" seq="2003-0812" published="2003-12-15" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106859247713009&amp;w=2">20031111 EEYE: Windows Workstation Service Remote Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106865197102041&amp;w=2">20031112 Proof of concept for Windows Workstation Service overflow</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-28.html">CA-2003-28</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20040129-ms03-049.shtml">20040129 Buffer Overrun in Microsoft Windows 2000 Workstation Service (MS03-049)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/567620" adv="1" patch="1">VU#567620</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9011" adv="1" patch="1">9011</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-049">MS03-049</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A331">oval:org.mitre.oval:def:331</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A575">oval:org.mitre.oval:def:575</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0813" seq="2003-0813" published="2003-11-17" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.html">20031010 Re : [VERY] BAD news on RPC DCOM Exploit</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.html">20031010 Re: Bad news on RPC DCOM vulnerability</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.html">20031011 Bad news on RPC DCOM2 vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106579825211708&amp;w=2">20031010 Bad news on RPC DCOM vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106588827513795&amp;w=2">20031011 RE: Bad news on RPC DCOM vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106580303918155&amp;w=2">20031010 Bad news on RPC DCOM vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/547820" adv="1" patch="1">VU#547820</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8811">8811</ref>
      <ref source="MISC" url="http://www.securitylab.ru/_exploits/rpc2.c.txt">http://www.securitylab.ru/_exploits/rpc2.c.txt</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html">TA04-104A</ref>
      <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/155" adv="1" patch="1">20031014 Microsoft RPC Race Condition Denial of Service</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012">MS04-012</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A893">oval:org.mitre.oval:def:893</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A894">oval:org.mitre.oval:def:894</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A900">oval:org.mitre.oval:def:900</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0814" seq="2003-0814" published="2004-02-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007687">1007687</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0177.html">20030910 MSIE->BodyRefreshLoadsJPU:refresh is a new navigation method</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/326412" adv="1" patch="1">VU#326412</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm">http://www.safecenter.net/liudieyu/BodyRefreshLoadsJPU/BodyRefreshLoadsJPU-Content.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/337086">20030911 LiuDieYu's missing files are here.</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048">MS03-048</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A335">oval:org.mitre.oval:def:335</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A341">oval:org.mitre.oval:def:341</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A342">oval:org.mitre.oval:def:342</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A343">oval:org.mitre.oval:def:343</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A344">oval:org.mitre.oval:def:344</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A349">oval:org.mitre.oval:def:349</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A392">oval:org.mitre.oval:def:392</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0815" seq="2003-0815" published="2004-02-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106321757619047&amp;w=2">20030910 MSIE->LinkillerJPU:another caller-based authorization(is broken).</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322542104656&amp;w=2">20030910 MSIE->Findeath: break caller-based authorization</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007687">1007687</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-021.shtml">O-021</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0150.html">20030910 MSIE->LinkillerSaveRef:another caller-based authorization</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM">http://www.safecenter.net/UMBRELLAWEBV4/Linkiller/Linkiller-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerJPU/LinkillerJPU-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM">http://www.safecenter.net/UMBRELLAWEBV4/LinkillerSaveRef/LinkillerSaveRef-Content.HTM</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/337086">20030911 LiuDieYu's missing files are here.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9014" adv="1" patch="1">9014</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048">MS03-048</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13676">ie-pointer-zone-bypass(13676)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A351">oval:org.mitre.oval:def:351</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A352">oval:org.mitre.oval:def:352</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A353">oval:org.mitre.oval:def:353</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A356">oval:org.mitre.oval:def:356</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A357">oval:org.mitre.oval:def:357</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A359">oval:org.mitre.oval:def:359</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A472">oval:org.mitre.oval:def:472</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0816" seq="2003-0816" published="2004-02-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106321638416884&amp;w=2">20030910 MSIE->RefBack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106321693517858&amp;w=2">20030910 MSIE->NAFjpuInHistory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106321781819727&amp;w=2">20030910 MSIE->WsFakeSrc</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106321882821788&amp;w=2">20030910 MSIE->WsOpenFileJPU</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322063729496&amp;w=2">20030910 MSIE->WsBASEjpu</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322240132721&amp;w=2">20030910 MSIE->BackMyParent2:Multi-Thread version</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007687">1007687</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-09/0146.html">20030910 MSIE->WsOpenJpuInHistory</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652452" adv="1" patch="1">VU#652452</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/771604">VU#771604</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm">http://www.safecenter.net/liudieyu/BackMyParent/BackMyParent-content.htm</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM">http://www.safecenter.net/liudieyu/BackMyParent2/BackMyParent2-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM">http://www.safecenter.net/liudieyu/NAFjpuInHistory/NAFjpuInHistory-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM">http://www.safecenter.net/liudieyu/RefBack/RefBack-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM">http://www.safecenter.net/liudieyu/WsBASEjpu/WsBASEjpu-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM">http://www.safecenter.net/liudieyu/WsFakeSrc/WsFakeSrc-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM">http://www.safecenter.net/liudieyu/WsOpenJpuInHistory/WsOpenJpuInHistory-Content.HTM</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm">http://www.safecenter.net/UMBRELLAWEBV4/NAFfileJPU/NAFfileJPU-Content.htm</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM">http://www.safecenter.net/UMBRELLAWEBV4/WsOpenFileJPU/WsOpenFileJPU-Content.HTM</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/336937">20030910 MSIE->NAFfileJPU</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/337086">20030911 LiuDieYu's missing files are here.</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048">MS03-048</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A361">oval:org.mitre.oval:def:361</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A362">oval:org.mitre.oval:def:362</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A363">oval:org.mitre.oval:def:363</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A409">oval:org.mitre.oval:def:409</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A416">oval:org.mitre.oval:def:416</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A459">oval:org.mitre.oval:def:459</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A479">oval:org.mitre.oval:def:479</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0817" seq="2003-0817" published="2004-02-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/9012" adv="1" patch="1">9012</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048">MS03-048</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A508">oval:org.mitre.oval:def:508</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A520">oval:org.mitre.oval:def:520</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A543">oval:org.mitre.oval:def:543</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A548">oval:org.mitre.oval:def:548</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A549">oval:org.mitre.oval:def:549</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A556">oval:org.mitre.oval:def:556</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A566">oval:org.mitre.oval:def:566</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0818" seq="2003-0818" published="2004-03-03" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107643836125615&amp;w=2">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107643892224825&amp;w=2">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=107650972617367&amp;w=2">20040210 EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=107650972723080&amp;w=2">20040210 EEYE: Microsoft ASN.1 Library Bit String Heap Corruption</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/216324" adv="1">VU#216324</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583108">VU#583108</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-041A.html">TA04-041A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-007">MS04-007</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A653">oval:org.mitre.oval:def:653</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A796">oval:org.mitre.oval:def:796</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A797">oval:org.mitre.oval:def:797</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A799">oval:org.mitre.oval:def:799</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0819" seq="2003-0819" published="2004-02-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2004-01.html" adv="1" patch="1">CA-2004-01</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/749342" adv="1" patch="1">VU#749342</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9408" adv="1" patch="1">9408</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008698">1008698</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-001">MS04-001</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A478">oval:org.mitre.oval:def:478</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy_server" vendor="microsoft">
        <vers num="2.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0820" seq="2003-0820" published="2003-12-15" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html" adv="1">20031015 Few issues previously unpublished in English</ref>
      <ref source="MISC" url="http://www.security.nnov.ru/search/document.asp?docid=5243" adv="1">http://www.security.nnov.ru/search/document.asp?docid=5243</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8835" adv="1" patch="1">8835</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050">MS03-050</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13682" adv="1">word-macro-execute-code(13682)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A336" adv="1">oval:org.mitre.oval:def:336</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A585" adv="1">oval:org.mitre.oval:def:585</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A586" adv="1">oval:org.mitre.oval:def:586</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A668" adv="1">oval:org.mitre.oval:def:668</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="97" edition="::ja"/>
        <vers num="97" edition="::ko"/>
        <vers num="97" edition="::zh"/>
        <vers num="97" edition="sr1"/>
        <vers num="97" edition="sr2"/>
        <vers num="98" edition="::ja"/>
        <vers num="98" edition="::ko"/>
        <vers num="98" edition="::zh"/>
        <vers num="98" edition="sr1::ja"/>
        <vers num="98" edition="sr2::ja"/>
        <vers num="2000" edition="::ja"/>
        <vers num="2000" edition="::ko"/>
        <vers num="2000" edition="::zh"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2000" edition="sr1a"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
      <prod name="works" vendor="microsoft">
        <vers num="2001"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0821" seq="2003-0821" published="2003-12-15" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/9010" adv="1">9010</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-050">MS03-050</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13681" adv="1">excel-macro-execute-code(13681)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A636" adv="1">oval:org.mitre.oval:def:636</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A675" adv="1">oval:org.mitre.oval:def:675</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A695" adv="1">oval:org.mitre.oval:def:695</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="97" edition="::ja"/>
        <vers num="97" edition="::ko"/>
        <vers num="97" edition="::zh"/>
        <vers num="97" edition="sr1"/>
        <vers num="97" edition="sr2"/>
        <vers num="98" edition="::ja"/>
        <vers num="98" edition="::ko"/>
        <vers num="98" edition="::zh"/>
        <vers num="98" edition="sr1::ja"/>
        <vers num="98" edition="sr2::ja"/>
        <vers num="2000" edition="::ja"/>
        <vers num="2000" edition="::ko"/>
        <vers num="2000" edition="::zh"/>
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2000" edition="sr1a"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
      <prod name="works" vendor="microsoft">
        <vers num="2001"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0822" seq="2003-0822" published="2003-12-15" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106865318904055&amp;w=2">20031112 Frontpage Extensions Remote Command Execution</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106862654906759&amp;w=2">20031112 Frontpage Extensions Remote Command Execution</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/279156">VU#279156</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-051">MS03-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13674">fpse-debug-bo(13674)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A364">oval:org.mitre.oval:def:364</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A366">oval:org.mitre.oval:def:366</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A367">oval:org.mitre.oval:def:367</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A699">oval:org.mitre.oval:def:699</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A743">oval:org.mitre.oval:def:743</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage_server_extensions" vendor="microsoft">
        <vers num="2000"/>
        <vers num="2002"/>
      </prod>
      <prod name="sharepoint_team_services" vendor="microsoft">
        <vers num="2002"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0823" seq="2003-0823" published="2004-02-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106322197932006&amp;w=2">20030910 MSIE->HijackClick: 1+1=2</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/413886">VU#413886</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/337086">20030911 LiuDieYu's missing files are here.</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006036">1006036</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-048">MS03-048</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A368">oval:org.mitre.oval:def:368</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A369">oval:org.mitre.oval:def:369</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A370">oval:org.mitre.oval:def:370</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A371">oval:org.mitre.oval:def:371</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A372">oval:org.mitre.oval:def:372</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A588">oval:org.mitre.oval:def:588</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A733">oval:org.mitre.oval:def:733</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0824" seq="2003-0824" published="2003-12-15" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/179012">VU#179012</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-051">MS03-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13680">fpse-smarthtml-dos(13680)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A308">oval:org.mitre.oval:def:308</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A591">oval:org.mitre.oval:def:591</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A606">oval:org.mitre.oval:def:606</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A625">oval:org.mitre.oval:def:625</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A762">oval:org.mitre.oval:def:762</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage_server_extensions" vendor="microsoft">
        <vers num="2000"/>
        <vers num="2002"/>
      </prod>
      <prod name="sharepoint_team_services" vendor="microsoft">
        <vers num="2002"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0825" seq="2003-0825" published="2004-03-03" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-077.shtml">O-077</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/445214">VU#445214</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9624" adv="1" patch="1">9624</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-006">MS04-006</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15037">win-wins-gsflag-dos(15037)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A704">oval:org.mitre.oval:def:704</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A800">oval:org.mitre.oval:def:800</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A801">oval:org.mitre.oval:def:801</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A802">oval:org.mitre.oval:def:802</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="" edition="r2:x64"/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0826" seq="2003-0826" published="2003-10-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/211662">http://bugs.debian.org/211662</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010496.html">20030919 lsh patch (was Re: [Full-Disclosure] new ssh exploit?)</ref>
      <ref source="CONFIRM" url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html">http://lists.lysator.liu.se/pipermail/lsh-bugs/2003q3/000120.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106398939512178&amp;w=2">20030919 Remote root vuln in lsh 1.4.x</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106407188509874&amp;w=2">20030920 LSH: Buffer overrun and remote root compromise in lshd</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-717">DSA-717</ref>
    </refs>
    <vuln_soft>
      <prod name="lsh" vendor="gnu">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0827" seq="2003-0827" published="2003-10-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106399616919636&amp;w=2">20030919 AppSecInc Security Alert: Denial of Service Vulnerability in DB2 Discovery Service</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY47686&amp;apar=only">IY47686</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.1" edition=":linux"/>
        <vers num="7.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0828" seq="2003-0828" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-391" adv="1" patch="1">DSA-391</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8716" adv="1" patch="1">8716</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13301">freesweep-bo(13301)</ref>
    </refs>
    <vuln_soft>
      <prod name="freesweep" vendor="gus_and_psilord">
        <vers num="0.88"/>
        <vers num="0.90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0830" seq="2003-0830" published="2003-11-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-390" adv="1" patch="1">DSA-390</ref>
    </refs>
    <vuln_soft>
      <prod name="marbles" vendor="marbles">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0831" seq="2003-0831" published="2003-11-17" modified="2017-10-04" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012072.html">20031014 Another ProFTPd root EXPLOIT ?</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106441655617816&amp;w=2">20030924 [slackware-security]  ProFTPD Security Advisory (SSA:2003-259-02)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106606885611269&amp;w=2">20031013 Remote root exploit for proftpd \n bug</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/405348">VU#405348</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:095">MDKSA-2003:095</ref>
      <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/154">20030923 ProFTPD ASCII File Remote Compromise Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12200">proftpd-ascii-xfer-newline-bo(12200)</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/107/">107</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2.7"/>
        <vers num="1.2.7_rc1"/>
        <vers num="1.2.7_rc2"/>
        <vers num="1.2.7_rc3"/>
        <vers num="1.2.8"/>
        <vers num="1.2.8_rc1"/>
        <vers num="1.2.8_rc2"/>
        <vers num="1.2.9_rc1"/>
        <vers num="1.2.9_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0832" seq="2003-0832" published="2003-11-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-392" adv="1" patch="1">DSA-392</ref>
    </refs>
    <vuln_soft>
      <prod name="webfs" vendor="webfs">
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0833" seq="2003-0833" published="2003-11-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-392" adv="1" patch="1">DSA-392</ref>
    </refs>
    <vuln_soft>
      <prod name="webfs" vendor="webfs">
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0834" seq="2003-0834" published="2003-12-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P">20040801-01-P</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q4/0047.html">HPSBUX0311-297</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57414">57414</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=134&amp;type=vulnerabilities&amp;flashstatus=false">20040825 CDE libDtHelp LOGNAME Buffer Overflow Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/575804" adv="1" patch="1">VU#575804</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8973" adv="1" patch="1">8973</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5141">oval:org.mitre.oval:def:5141</ref>
    </refs>
    <vuln_soft>
      <prod name="open_unix" vendor="sco">
        <vers num="8.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.1"/>
        <vers num="7.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0835" seq="2003-0835" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000760">CLA-2003:760</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106454257221455&amp;w=2">20030925 MPlayer Security Advisory #01: Remotely exploitable buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106460912721618&amp;w=2">20030926 Mplayer Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106485005213109&amp;w=2">20030929 GLSA:  media-video/mplayer (200309-15)</ref>
      <ref source="CONFIRM" url="http://www.mplayerhq.hu/homepage/design6/news.html">http://www.mplayerhq.hu/homepage/design6/news.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mplayer" vendor="mplayer">
        <vers num="0.90"/>
        <vers num="0.90_pre"/>
        <vers num="0.90_rc"/>
        <vers num="0.90_rc4"/>
        <vers num="0.91"/>
        <vers num="1.0_pre1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0836" seq="2003-0836" published="2003-11-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.2" edition=":linux"/>
        <vers num="8.1" edition=":aix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0837" seq="2003-0837" published="2003-11-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106503709914622&amp;w=2">20031001 ptl-2003-02: IBM DB2 INVOKE Command Stack Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8743" adv="1" patch="1">8743</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13331">db2-invoke-bo(13331)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0838" seq="2003-0838" published="2003-11-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009639.html">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106304733121753&amp;w=2">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106304876523459&amp;w=2">20030908 Temporary Fix for IE Zero Day Malware RE: BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=106302799428500&amp;w=2">20030907 BAD NEWS: Microsoft Security Bulletin MS03-032</ref>
      <ref source="MISC" url="http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html">http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0310&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=2169">20031001 DNS/Hosts file issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8556">8556</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-040">MS03-040</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13314">ie-popup-code-execution(13314)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A204">oval:org.mitre.oval:def:204</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0839" seq="2003-0839" published="2003-11-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106563075612028&amp;w=2">20031008 Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability</ref>
      <ref source="MISC" url="http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html">http://www.geocities.co.jp/SiliconValley/1667/advisory08e.html</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0840" seq="2003-0840" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106563181313571&amp;w=2">20031008 HPUX dtprintinfo buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0841" seq="2003-0841" published="2003-11-17" modified="2019-08-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by directly accessing the files via a URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106554919000847&amp;w=2">20031007 PeopleSoft Grid Option Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="oracle">
        <vers num="8.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0842" seq="2003-0842" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_gzip" vendor="dag_apt_repository">
        <vers num="1.3.26.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0843" seq="2003-0843" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_gzip" vendor="dag_apt_repository">
        <vers num="1.3.26.1a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0844" seq="2003-0844" published="2003-11-17" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105457180009860&amp;w=2">20030601 Mod_gzip Debug Mode Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_gzip" vendor="dag_apt_repository">
        <vers num="1.3.26.1a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0845" seq="2003-0845" published="2003-11-17" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546044416498&amp;w=2">20031005 JBoss 3.2.1: Remote Command Injection</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106547728803252&amp;w=2">20031006 Update JBoss 308 &amp; 321: Remote Command Injection</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866">http://sourceforge.net/docman/display_doc.php?docid=19314&amp;group_id=22866</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1048.html">RHSA-2007:1048</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8773" adv="1" patch="1">8773</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300">oval:org.mitre.oval:def:11300</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0846" seq="2003-0846" published="2003-11-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546177518140&amp;w=2">20031006 Local root exploit in SuSE Linux 7.3Pro</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546531922379&amp;w=2">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.3" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0847" seq="2003-0847" published="2003-11-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106545972615578&amp;w=2">20031006 Local root exploit in SuSE Linux 8.2Pro</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546531922379&amp;w=2">20031006 Re: Local root exploit in SuSE Linux 8.2Pro</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="8.2" edition=":professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0848" seq="2003-0848" published="2003-11-17" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-001.0/CSSA-2004-001.0.txt">CSSA-2004-001.0</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546447321274&amp;w=2">20031006 SA-20031006 slocate vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106589631819348&amp;w=2">20031011 SA-20031006 slocate buffer overflow - exploitation proof</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-040.html">RHSA-2004:040</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-428" adv="1" patch="1">DSA-428</ref>
      <ref source="MISC" url="http://www.ebitech.sk/patrik/SA/SA-20031006.txt">http://www.ebitech.sk/patrik/SA/SA-20031006.txt</ref>
      <ref source="MISC" url="http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt">http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:004">MDKSA-2004:004</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00009.html">FEDORA-2004-059</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-041.html">RHSA-2004:041</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/misc/2004/TSL-2004-0005-slocate.asc.txt">2004-0005</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11033">oval:org.mitre.oval:def:11033</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A821">oval:org.mitre.oval:def:821</ref>
    </refs>
    <vuln_soft>
      <prod name="slocate" vendor="slocate">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0849" seq="2003-0849" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106451047819552&amp;w=2">20030925 Cfengine2 cfservd remote stack overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106485375218280&amp;w=2">20030928 cfengine2-2.0.3 remote exploit for redhat</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106546086216984&amp;w=2">20031005 GLSA: cfengine (200310-02)</ref>
    </refs>
    <vuln_soft>
      <prod name="cfengine" vendor="gnu">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5" edition="b1"/>
        <vers num="2.0.5" edition="pre"/>
        <vers num="2.0.5" edition="pre2"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7" edition="p1"/>
        <vers num="2.0.7" edition="p2"/>
        <vers num="2.0.7" edition="p3"/>
        <vers num="2.1.0" edition="a6"/>
        <vers num="2.1.0" edition="a8"/>
        <vers num="2.1.0" edition="a9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0850" seq="2003-0850" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000773">CLA-2003:773</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106728224210446&amp;w=2">20031027 Libnids &lt;= 1.17 buffer overflow</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=191323" adv="1">http://sourceforge.net/project/shownotes.php?release_id=191323</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-410" adv="1" patch="1">DSA-410</ref>
    </refs>
    <vuln_soft>
      <prod name="dsniff" vendor="dug_song">
        <vers num="2.3"/>
      </prod>
      <prod name="libnids" vendor="rafal_wojtczuk">
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0851" seq="2003-0851" published="2003-12-01" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.asc">NetBSD-SA2004-003</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc">20040304-01-U</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106796246511667&amp;w=2">20031104 [OpenSSL Advisory] Denial of Service in ASN.1 parsing</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108403850228012&amp;w=2">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-119.html">RHSA-2004:119</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtml">20030930 SSL Implementation Vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412478" adv="1" patch="1">VU#412478</ref>
      <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20031104.txt" adv="1" patch="1">http://www.openssl.org/news/secadv_20031104.txt</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html">FEDORA-2005-1042</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8970" adv="1" patch="1">8970</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5528">oval:org.mitre.oval:def:5528</ref>
    </refs>
    <vuln_soft>
      <prod name="css11000_content_services_switch" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="pix_firewall" vendor="cisco">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="12.1(11)e"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.2sx"/>
        <vers num="12.2sy"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.0(3)"/>
        <vers num="6.0(4)"/>
        <vers num="6.0(4.101)"/>
        <vers num="6.1"/>
        <vers num="6.1(1)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1(3)"/>
        <vers num="6.1(4)"/>
        <vers num="6.1(5)"/>
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.3(1)"/>
        <vers num="6.3(3.102)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0852" seq="2003-0852" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012542.html">20031022 Sylpheed-claws format string bug, yet still sylpheed much better than windows</ref>
      <ref source="CONFIRM" url="http://sylpheed.good-day.net/#changes">http://sylpheed.good-day.net/#changes</ref>
      <ref source="MISC" url="http://www.guninski.com/sylph.html">http://www.guninski.com/sylph.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8877" adv="1" patch="1">8877</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13508">sylpheed-smtp-format-string(13508)</ref>
    </refs>
    <vuln_soft>
      <prod name="sylpheed" vendor="sylpheed">
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
      </prod>
      <prod name="sylpheed-claws" vendor="sylpheed-claws">
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0853" seq="2003-0853" published="2003-11-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768">CLA-2003:768</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771">CLA-2003:771</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html">20031022 Fun with /bin/ls, yet still ls better than windows</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</ref>
      <ref source="MISC" url="http://www.guninski.com/binls.html">http://www.guninski.com/binls.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106">MDKSA-2003:106</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-309.html">RHSA-2003:309</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-310.html">RHSA-2003:310</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/advisories/6014">IMNX-2003-7+-026-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8875" adv="1" patch="1">8875</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-60.txt">TLSA-2003-60</ref>
    </refs>
    <vuln_soft>
      <prod name="fileutils" vendor="gnu">
        <vers num="4.0"/>
        <vers num="4.0.36"/>
        <vers num="4.1"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.1"/>
        <vers num="2.4.2_beta2" edition=":academ"/>
        <vers num="2.4.2_beta18" edition=":academ"/>
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr7"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0854" seq="2003-0854" published="2003-11-17" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000768">CLA-2003:768</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000771">CLA-2003:771</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012548.html">20031022 Fun with /bin/ls, yet still ls better than windows</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-213.pdf</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-705">DSA-705</ref>
      <ref source="MISC" url="http://www.guninski.com/binls.html">http://www.guninski.com/binls.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:106">MDKSA-2003:106</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-309.html">RHSA-2003:309</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-310.html">RHSA-2003:310</ref>
      <ref source="IMMUNIX" url="http://www.securityfocus.com/advisories/6014">IMNX-2003-7+-026-01</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-60.txt">TLSA-2003-60</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/115">115</ref>
    </refs>
    <vuln_soft>
      <prod name="fileutils" vendor="gnu">
        <vers num="4.0"/>
        <vers num="4.0.36"/>
        <vers num="4.1"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.1"/>
        <vers num="2.4.2_beta2" edition=":academ"/>
        <vers num="2.4.2_beta18" edition=":academ"/>
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr7"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0855" seq="2003-0855" published="2003-11-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONFIRM" url="http://bugzilla.gnome.org/show_bug.cgi?id=107025" patch="1">http://bugzilla.gnome.org/show_bug.cgi?id=107025</ref>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=107519</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-311.html">RHSA-2003:311</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-312.html">RHSA-2003:312</ref>
    </refs>
    <vuln_soft>
      <prod name="pan" vendor="charles_kerr">
        <vers num="0.13.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0856" seq="2003-0856" published="2003-12-15" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-492" adv="1" patch="1">DSA-492</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">SUSE-SR:2005:001</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00004.html">FEDORA-2004-115</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-316.html">RHSA-2003:316</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-317.html" adv="1" patch="1">RHSA-2003:317</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10912">oval:org.mitre.oval:def:10912</ref>
    </refs>
    <vuln_soft>
      <prod name="iproute" vendor="stephen_hemminger">
        <vers num="2.4.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0857" seq="2003-0857" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=108574">https://bugzilla.redhat.com/show_bug.cgi?id=108574</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0858" seq="2003-0858" published="2003-12-15" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-415" adv="1" patch="1">DSA-415</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-305.html" adv="1" patch="1">RHSA-2003:305</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-307.html" adv="1" patch="1">RHSA-2003:307</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-315.html" adv="1" patch="1">RHSA-2003:315</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10169">oval:org.mitre.oval:def:10169</ref>
    </refs>
    <vuln_soft>
      <prod name="zebra" vendor="gnu">
        <vers num="0.91" prev="1"/>
      </prod>
      <prod name="quagga_routing_software_suite" vendor="quagga">
        <vers num="0.95" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0859" seq="2003-0859" published="2003-12-15" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-325.html" adv="1" patch="1">RHSA-2003:325</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-334.html">RHSA-2003:334</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11337">oval:org.mitre.oval:def:11337</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.3.2"/>
      </prod>
      <prod name="zebra" vendor="gnu">
        <vers num="0.91a"/>
        <vers num="0.92a"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
      </prod>
      <prod name="quagga_routing_software_suite" vendor="quagga">
        <vers num="0.96.2"/>
      </prod>
      <prod name="propack" vendor="sgi">
        <vers num="2.2.1"/>
        <vers num="2.3"/>
      </prod>
      <prod name="ia64" vendor="intel">
        <vers num=""/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod name="linux_advanced_workstation" vendor="redhat">
        <vers num="2.1" edition=":itanium_processor"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0860" seq="2003-0860" published="2003-11-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php#4.3.3">http://www.php.net/ChangeLog-4.php#4.3.3</ref>
      <ref source="CONFIRM" url="http://www.php.net/release_4_3_3.php" adv="1">http://www.php.net/release_4_3_3.php</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0"/>
        <vers num="4.0.1" edition="patch1"/>
        <vers num="4.0.1" edition="patch2"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3" edition="patch1"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7" edition="rc1"/>
        <vers num="4.0.7" edition="rc2"/>
        <vers num="4.0.7" edition="rc3"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2" edition=":dev"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0861" seq="2003-0861" published="2003-11-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php#4.3.3">http://www.php.net/ChangeLog-4.php#4.3.3</ref>
      <ref source="CONFIRM" url="http://www.php.net/release_4_3_3.php" adv="1">http://www.php.net/release_4_3_3.php</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0"/>
        <vers num="4.0.1" edition="patch1"/>
        <vers num="4.0.1" edition="patch2"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3" edition="patch1"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7" edition="rc1"/>
        <vers num="4.0.7" edition="rc2"/>
        <vers num="4.0.7" edition="rc3"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2" edition=":dev"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0862" seq="2003-0862" published="2003-11-17" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0813.  Reason: This candidate is a duplicate of CVE-2003-0813.  Notes: All CVE users should reference CVE-2003-0813 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0863" seq="2003-0863" published="2003-11-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105839111204227">20030716 PHP safe mode broken?</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0864" seq="2003-0864" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.irc.org/irc/server/ChangeLog">ftp://ftp.irc.org/irc/server/ChangeLog</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000765">CLA-2003:765</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106606129601446&amp;w=2">20031012 buffer overflow in IRCD software</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106667431021928&amp;w=2">20031019 [OpenPKG-SA-2003.045] OpenPKG Security Advisory (ircd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8817" adv="1" patch="1">8817</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13408">ircd-mjoin-bo(13408)</ref>
    </refs>
    <vuln_soft>
      <prod name="ircnet_ircd" vendor="ircnet">
        <vers num="2.10"/>
        <vers num="2.10.3_p3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0865" seq="2003-0865" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt">CSSA-2004-002.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000781">CLA-2003:781</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106493686331198&amp;w=2">20030930 GLSA:  mpg123 (200309-17)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-435" adv="1" patch="1">DSA-435</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/338641" adv="1">20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8680" adv="1" patch="1">8680</ref>
    </refs>
    <vuln_soft>
      <prod name="mpg123" vendor="mpg123">
        <vers num="0.59r"/>
        <vers num="0.59s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0866" seq="2003-0866" published="2003-11-17" modified="2019-03-25" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506" adv="1" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=215506</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1">239312</ref>
      <ref source="CONFIRM" url="http://tomcat.apache.org/security-4.html">http://tomcat.apache.org/security-4.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-395" adv="1" patch="1">DSA-395</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8824" adv="1" patch="1">8824</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/1979/references">ADV-2008-1979</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13429">tomcat-non-http-dos(13429)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E">[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E">[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0867" seq="2003-0867" published="2003-11-17" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0662.  Reason: This candidate is a duplicate of CVE-2003-0662.  Notes: All CVE users should reference CVE-2003-0662 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0868" seq="2003-0868" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0869" seq="2003-0869" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0870" seq="2003-0870" published="2003-11-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0016.html">20031020 Opera HREF escaped server name overflow</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a102003-1.txt" adv="1" patch="1">A102003-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8853" adv="1" patch="1">8853</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13458">opera-escape-heap-overflow(13458)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="7.11"/>
        <vers num="7.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0871" seq="2003-0871" published="2003-11-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="APPLE" url="http://lists.apple.com/mhonarc/security-announce/msg00039.html">APPLE-SA-2003-10-28</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8922" adv="1" patch="1">8922</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0872" seq="2003-0872" published="2003-11-17" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.27/CSSA-2003-SCO.27.txt" adv="1" patch="1">CSSA-2003-SCO.27</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8864" adv="1" patch="1">8864</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0873" seq="2003-0873" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0874" seq="2003-0874" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0017.html">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106667525623311&amp;w=2">20031020 Multiple SQL Injection Vulnerabilities in DeskPRO</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6R0052K8KM.html" adv="1">http://www.securiteam.com/unixfocus/6R0052K8KM.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8856" adv="1" patch="1">8856</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13391">deskpro-multiple-sql-injection(13391)</ref>
    </refs>
    <vuln_soft>
      <prod name="deskpro" vendor="deskpro">
        <vers num="1.1_.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0875" seq="2003-0875" published="2003-11-17" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000723">CLA-2003:723</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106123103606336&amp;w=2">20030818 OpenSLP initscript symlink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="openslp" vendor="openslp">
        <vers num="1.0.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0876" seq="2003-0876" published="2003-11-03" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a102803-1.txt">A102803-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8916" adv="1" patch="1">8916</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8917">8917</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13537">macos-insecure-file-permissions(13537)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0877" seq="2003-0877" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a102803-1.txt" adv="1" patch="1">A102803-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8914" adv="1">8914</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8917">8917</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13542">macos-core-files-symlink(13542)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0878" seq="2003-0878" published="2003-11-03" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0879" seq="2003-0879" published="2003-11-17" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0518.  Reason: This candidate is a reservation duplicate of CVE-2003-0518.  Notes: All CVE users should reference CVE-2003-0518 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0880" seq="2003-0880" published="2003-11-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0881" seq="2003-0881" published="2003-11-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0882" seq="2003-0882" published="2003-11-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0883" seq="2003-0883" published="2003-11-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0885" seq="2003-0885" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=41253" adv="1" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=41253</ref>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</ref>
    </refs>
    <vuln_soft>
      <prod name="xscreensaver" vendor="xscreensaver">
        <vers num="4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0886" seq="2003-0886" published="2003-12-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000783">CLA-2003:783</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106858898708752&amp;w=2">20031111 HylaFAX - Format String Vulnerability Fixed</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-401" adv="1" patch="1">DSA-401</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:105">MDKSA-2003:105</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_045_hylafax.html">SuSE-SA:2003:045</ref>
    </refs>
    <vuln_soft>
      <prod name="hylafax" vendor="hylafax">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0887" seq="2003-0887" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?r1=1.4&amp;r2=1.5</ref>
      <ref source="CONFIRM" url="http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6">http://cvs.mandriva.com/cgi-bin/viewcvs.cgi/SPECS/ez-ipupdate/ez-ipupdate.spec?rev=1.6</ref>
    </refs>
    <vuln_soft>
      <prod name="ez-ipupdate" vendor="angus_mackay">
        <vers num="3.0.11b5"/>
        <vers num="3.0.11b7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0894" seq="2003-0894" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007956">1007956</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/496340">VU#496340</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8844">8844</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8845">8845</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13451">oracle-oracleo-binaries-bo(13451)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle9i" vendor="oracle">
        <vers num="enterprise_9.0.1"/>
        <vers num="enterprise_9.2.0.4"/>
        <vers num="personal_9.0.1"/>
        <vers num="personal_9.2.0.4"/>
        <vers num="standard_9.0"/>
        <vers num="standard_9.0.1"/>
        <vers num="standard_9.0.1.2"/>
        <vers num="standard_9.0.1.3"/>
        <vers num="standard_9.0.1.4"/>
        <vers num="standard_9.0.2"/>
        <vers num="standard_9.2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0895" seq="2003-0895" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a102803-3.txt">A102803-3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8913" adv="1">8913</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13541">macos-long-command-bo(13541)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0896" seq="2003-0896" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lsd-pl.net/code/JVM/jre.tar.gz">http://lsd-pl.net/code/JVM/jre.tar.gz</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106692334503819&amp;w=2">20021023 [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57221">57221</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200356-1">200356</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/6028">HPSBUX0311-295</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342580">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342583">20031027 Re: [LSD] Security vulnerability in SUN's Java Virtual Machineimplementation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8879">8879</ref>
    </refs>
    <vuln_soft>
      <prod name="jre" vendor="sun">
        <vers num="1.4.1" prev="1" edition="update3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0897" seq="2003-0897" published="2003-11-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106692772510010&amp;w=2">20031023 Shatter XP</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13558">winxp-commctl32-code-execution(13558)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0898" seq="2003-0898" published="2003-11-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/db2aixv7/FP10a_U495172/FixpakReadme.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106010332721672&amp;w=2">20030805 Local Vulnerability in IBM DB2 7.1 db2job binary</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.1" edition=":linux"/>
        <vers num="8.0" prev="1" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0899" seq="2003-0899" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '&lt;' or '>' characters, which trigger the overflow when the characters are expanded to "&amp;lt;" and "&amp;gt;" sequences.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Acme Labs, thttpd, 2.24</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106729188224252&amp;w=2">20031027 Remote overflow in thttpd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8906" patch="1">8906</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13530">thttpd-defang-bo(13530)</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2003/dsa-396">DSA-396</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd" vendor="acme_labs">
        <vers num="2.21"/>
        <vers num="2.21b"/>
        <vers num="2.22"/>
        <vers num="2.23b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0900" seq="2003-0900" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711">https://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=108711</ref>
    </refs>
    <vuln_soft>
      <prod name="perl" vendor="larry_wall">
        <vers num="5.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0901" seq="2003-0901" published="2003-11-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c">http://developer.postgresql.org/cvsweb.cgi/pgsql-server/src/backend/utils/adt/ascii.c</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000784">CLA-2003:784</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000772">CLSA-2003:772</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-397">DSA-397</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-313.html">RHSA-2003:313</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-314.html">RHSA-2003:314</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8741" adv="1" patch="1">8741</ref>
    </refs>
    <vuln_soft>
      <prod name="postgresql" vendor="postgresql">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0902" seq="2003-0902" published="2004-02-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-402" adv="1" patch="1">DSA-402</ref>
    </refs>
    <vuln_soft>
      <prod name="minimalist" vendor="minimalist">
        <vers num="2.2"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0903" seq="2003-0903" published="2004-02-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139150">VU#139150</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9407" adv="1">9407</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-003">MS04-003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14187">mdac-broadcastrequest-bo(14187)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A525">oval:org.mitre.oval:def:525</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A553">oval:org.mitre.oval:def:553</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A751">oval:org.mitre.oval:def:751</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A775">oval:org.mitre.oval:def:775</ref>
    </refs>
    <vuln_soft>
      <prod name="data_access_components" vendor="microsoft">
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0904" seq="2003-0904" published="2004-01-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/530660">VU#530660</ref>
      <ref source="CONFIRM" url="http://www.microsoft.com/exchange/support/e2k3owa.asp" adv="1" patch="1">http://www.microsoft.com/exchange/support/e2k3owa.asp</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0311&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=9281" adv="1">20031114 Exchange 2003 OWA major security flaw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9118" adv="1">9118</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9409">9409</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-002">MS04-002</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13869">exchange-owa-account-access(13869)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A477">oval:org.mitre.oval:def:477</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2003"/>
      </prod>
      <prod name="sharepoint_services" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0905" seq="2003-0905" published="2004-04-15" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/982630">VU#982630</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9825" adv="1" patch="1">9825</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-008">MS04-008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15038">win-media-services-dos(15038)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A842">oval:org.mitre.oval:def:842</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_services" vendor="microsoft">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0906" seq="2003-0906" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/547028" adv="1" patch="1">VU#547028</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10120">10120</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1064">oval:org.mitre.oval:def:1064</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A897">oval:org.mitre.oval:def:897</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A959">oval:org.mitre.oval:def:959</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0907" seq="2003-0907" published="2004-06-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.html">20040413 Microsoft Help and Support Center argument injection vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108196864221676&amp;w=2">20040413 [Full-Disclosure] iDEFENSE Security Advisory 04.13.04 - Microsoft Help and Support</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="MISC" url="http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities">http://www.idefense.com/application/poi/display?id=100&amp;type=vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/260588" adv="1" patch="1">VU#260588</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10119">10119</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15704">win-hcpurl-code-execution(15704)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000">oval:org.mitre.oval:def:1000</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904">oval:org.mitre.oval:def:904</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2003_server" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0908" seq="2003-0908" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0082.html">20040414 [SHATTER Team Security Alert] Microsoft Windows Utility Manager Vulnerability</ref>
      <ref source="MISC" url="http://www.appsecinc.com/resources/alerts/general/04-0001.html" adv="1" patch="1">http://www.appsecinc.com/resources/alerts/general/04-0001.html</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/526084" adv="1" patch="1">VU#526084</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html">http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10124">10124</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15632">win2k-utilitymgr-gain-privileges(15632)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1046">oval:org.mitre.oval:def:1046</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0909" seq="2003-0909" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206468" adv="1" patch="1">VU#206468</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10125">10125</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15678">winxp-task-gain-privileges(15678)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1004">oval:org.mitre.oval:def:1004</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0910" seq="2003-0910" published="2004-06-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html">20040413 EEYE: Windows Expand-Down Data Segment Local Privilege Escalation</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-114.shtml">O-114</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040413D.html" adv="1" patch="1">AD20040413D</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/122076" adv="1" patch="1">VU#122076</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10122">10122</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" adv="1">TA04-104A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011">MS04-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15707">win-ldt-gain-privileges(15707)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890">oval:org.mitre.oval:def:890</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911">oval:org.mitre.oval:def:911</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0913" seq="2003-0913" published="2003-12-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=120269" adv="1">http://docs.info.apple.com/article.html?artnum=120269</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00040.html">http://lists.apple.com/mhonarc/security-announce/msg00040.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8979" adv="1" patch="1">8979</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13620">macos-terminal-gain-access(13620)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.3"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0914" seq="2003-0914" published="2003-12-15" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-003.0/CSSA-2004-003.0.txt">CSSA-2004-003.0</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.33/CSSA-2003-SCO.33.txt">CSSA-2003-SCO.33</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57434">57434</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-409" adv="1" patch="1">DSA-409</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/734644" adv="1" patch="1">VU#734644</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/misc/2003/TSL-2003-0044-bind.asc.txt">2003-0044</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2011">oval:org.mitre.oval:def:2011</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2.3"/>
        <vers num="8.2.4"/>
        <vers num="8.2.5"/>
        <vers num="8.2.6"/>
        <vers num="8.2.7"/>
        <vers num="8.3.0"/>
        <vers num="8.3.1"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
      </prod>
      <prod name="namesurfer" vendor="nixu">
        <vers num="standard_3.0.1"/>
        <vers num="suite_3.0.1"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0f_pk8_bl22"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="4.0g_pk4_bl22"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1a_pk4_bl21"/>
        <vers num="5.1a_pk5_bl23"/>
        <vers num="5.1b"/>
        <vers num="5.1b_pk1_bl1"/>
        <vers num="5.1b_pk2_bl22"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.6.2"/>
        <vers num="4.7"/>
        <vers num="4.8"/>
        <vers num="4.9"/>
        <vers num="5.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="5.1l"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="current"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0917" seq="2003-0917" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0918" seq="2003-0918" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0919" seq="2003-0919" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0920" seq="2003-0920" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0921" seq="2003-0921" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0922" seq="2003-0922" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0923" seq="2003-0923" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0924" seq="2003-0924" published="2004-02-17" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-426" adv="1" patch="1">DSA-426</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-02.xml">GLSA-200410-02</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/487102" adv="1">VU#487102</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011">MDKSA-2004:011</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-030.html" adv="1" patch="1">RHSA-2004:030</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-031.html">RHSA-2004:031</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9442" adv="1">9442</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14874">netpbm-temp-insecure-file(14874)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A804">oval:org.mitre.oval:def:804</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A810">oval:org.mitre.oval:def:810</ref>
    </refs>
    <vuln_soft>
      <prod name="netpbm" vendor="netpbm">
        <vers num="9.25" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0925" seq="2003-0925" published="2003-12-01" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780">CLA-2003:780</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-407">DSA-407</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114">MDKSA-2003:114</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-323.html" adv="1" patch="1">RHSA-2003:323</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-324.html">RHSA-2003:324</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8951" adv="1" patch="1">8951</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-64.txt">TLSA-2003-64</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9692">oval:org.mitre.oval:def:9692</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0926" seq="2003-0926" published="2003-12-01" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780">CLA-2003:780</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-407">DSA-407</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114">MDKSA-2003:114</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-323.html">RHSA-2003:323</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-324.html" adv="1" patch="1">RHSA-2003:324</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8951" adv="1" patch="1">8951</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-64.txt">TLSA-2003-64</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11648">oval:org.mitre.oval:def:11648</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0927" seq="2003-0927" published="2003-12-01" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000780">CLA-2003:780</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-407">DSA-407</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00011.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00011.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:114">MDKSA-2003:114</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-323.html" adv="1" patch="1">RHSA-2003:323</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-324.html">RHSA-2003:324</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8951" adv="1" patch="1">8951</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-64.txt">TLSA-2003-64</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13578">ethereal-socks-heap-overflow(13578)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9691">oval:org.mitre.oval:def:9691</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0928" seq="2003-0928" published="2004-09-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
      <ref source="MISC" url="http://www.corsaire.com/advisories/c030807-001.txt">http://www.corsaire.com/advisories/c030807-001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.3.15" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0929" seq="2003-0929" published="2004-09-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
      <ref source="MISC" url="http://www.corsaire.com/advisories/c030807-001.txt" adv="1" patch="1">http://www.corsaire.com/advisories/c030807-001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.3.15" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0930" seq="2003-0930" published="2004-09-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109241692108678&amp;w=2">20040813 Corsaire Security Advisory - Clearswift MAILsweeper multiple encoding/compression issues</ref>
      <ref source="MISC" url="http://www.corsaire.com/advisories/c030807-001.txt" adv="1" patch="1">http://www.corsaire.com/advisories/c030807-001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.3.15" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0931" seq="2003-0931" published="2004-09-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109215951022437&amp;w=2">20040810 Corsaire Security Advisory - Sygate Enforcer discovery packet DoS issue</ref>
      <ref source="MISC" url="http://www.corsaire.com/advisories/c031120-001.txt" adv="1" patch="1">http://www.corsaire.com/advisories/c031120-001.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16949">sygate-enforcer-payload-dos(16949)</ref>
    </refs>
    <vuln_soft>
      <prod name="enforcer" vendor="sygate_technologies">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0932" seq="2003-0932" published="2003-12-15" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-400" adv="1" patch="1">DSA-400</ref>
    </refs>
    <vuln_soft>
      <prod name="omega-rpg" vendor="omega-rpg">
        <vers num="0.9.0_pa9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0933" seq="2003-0933" published="2003-12-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-398" adv="1" patch="1">DSA-398</ref>
    </refs>
    <vuln_soft>
      <prod name="conquest" vendor="conquest">
        <vers num="7.1.1_-6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0934" seq="2003-0934" published="2003-12-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106850011513880&amp;w=2">20031110 Symbol Technologies Default WEP KEYS Vulnerability</ref>
      <ref source="MISC" url="http://www.secnap.net/security/031106.html" adv="1" patch="1">http://www.secnap.net/security/031106.html</ref>
    </refs>
    <vuln_soft>
      <prod name="pdt" vendor="symbol_technologies">
        <vers num="8100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0935" seq="2003-0935" published="2003-12-01" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000778">CLA-2003:778</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=308015" patch="1">http://sourceforge.net/forum/forum.php?forum_id=308015</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-335.html" adv="1" patch="1">RHSA-2003:335</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-023.html">RHSA-2004:023</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A869">oval:org.mitre.oval:def:869</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9802">oval:org.mitre.oval:def:9802</ref>
    </refs>
    <vuln_soft>
      <prod name="net-snmp" vendor="net-snmp">
        <vers num="5.0.1"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4_pre2"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0936" seq="2003-0936" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106875764826251&amp;w=2">20031113 SRT2003-11-13-0218 - PCAnywhere local SYSTEM exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106876107330752&amp;w=2">20031113 RE: Secure Network Operations SRT2003-11-13-0218, PCAnywhere allows local users to become SYSTEM</ref>
      <ref source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html" adv="1" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2003.11.13.html</ref>
    </refs>
    <vuln_soft>
      <prod name="pcanywhere" vendor="symantec">
        <vers num="10.0"/>
        <vers num="10.5"/>
        <vers num="11.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0937" seq="2003-0937" published="2003-12-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/CSSA-2003-SCO.32/CSSA-2003-SCO.32.txt" adv="1" patch="1">CSSA-2003-SCO.32</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106865297403687&amp;w=2">20031112 Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.</ref>
      <ref source="MISC" url="http://www.texonet.com/advisories/TEXONET-20031024.txt" adv="1" patch="1">http://www.texonet.com/advisories/TEXONET-20031024.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="open_unix" vendor="sco">
        <vers num="8.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.1"/>
        <vers num="7.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0938" seq="2003-0938" published="2003-12-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-1.txt" adv="1" patch="1">A111703-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13765">sapdb-NETAPI32-gain-privileges(13765)</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0939" seq="2003-0939" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the niserver (aka serv.exe) process on TCP port 7269, which prevents the server from NULL terminating the string and leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-1.txt" adv="1" patch="1">A111703-1</ref>
      <ref source="CONFIRM" url="http://www.sapdb.org/7.4/new_relinfo.txt">http://www.sapdb.org/7.4/new_relinfo.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0940" seq="2003-0940" published="2003-12-15" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1" patch="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0941" seq="2003-0941" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1" patch="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0942" seq="2003-0942" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1" patch="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0943" seq="2003-0943" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against internal databases via (1) waecho, (2) Web SQL Interface (websql), or (3) Web Database Manager (webdbm).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1" patch="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0944" seq="2003-0944" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1" patch="1">A111703-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0945" seq="2003-0945" published="2003-12-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a111703-2.txt" adv="1">A111703-2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13774">sapdb-manager-sessionid-predictable(13774)</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.4.03.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0946" seq="2003-0946" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106867135830683&amp;w=2">20031112 SRT2003-11-11-1151 - clamav-milter remote exploit / DoS</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=197038" adv="1">http://sourceforge.net/project/shownotes.php?release_id=197038</ref>
    </refs>
    <vuln_soft>
      <prod name="clamav" vendor="clam_anti-virus">
        <vers num="0.60"/>
        <vers num="0.60p"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0947" seq="2003-0947" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106867458902521&amp;w=2">20031112 iwconfig vulnerability - the last code was demaged sending by email</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0948" seq="2003-0948" published="2003-12-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/6Y00R1P8KY.html" adv="1">http://www.securiteam.com/exploits/6Y00R1P8KY.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8901" adv="1">8901</ref>
    </refs>
    <vuln_soft>
      <prod name="wireless_tools" vendor="wireless_tools">
        <vers num="19"/>
        <vers num="20"/>
        <vers num="21"/>
        <vers num="22"/>
        <vers num="23"/>
        <vers num="24"/>
        <vers num="25"/>
        <vers num="26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0949" seq="2003-0949" published="2004-02-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-405" adv="1" patch="1">DSA-405</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9321" adv="1" patch="1">9321</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14098">xsok-command-execution(14098)</ref>
    </refs>
    <vuln_soft>
      <prod name="xsok" vendor="michael_bischoff">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0950" seq="2003-0950" published="2003-12-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/9041" adv="1">9041</ref>
      <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/157">20031112 IClient Servlet Remote Command Execution Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12805">peoplesoft-iclientservlet-file-upload(12805)</ref>
    </refs>
    <vuln_soft>
      <prod name="peopletools" vendor="peoplesoft">
        <vers num="8.4"/>
        <vers num="8.10"/>
        <vers num="8.11"/>
        <vers num="8.12"/>
        <vers num="8.13"/>
        <vers num="8.14"/>
        <vers num="8.15"/>
        <vers num="8.16"/>
        <vers num="8.17"/>
        <vers num="8.18"/>
        <vers num="8.19"/>
        <vers num="8.20"/>
        <vers num="8.40"/>
        <vers num="8.41"/>
        <vers num="8.42"/>
        <vers num="8.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0951" seq="2003-0951" published="2003-12-15" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q4/0041.html" adv="1" patch="1">HPSBUX0311-296</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5146">oval:org.mitre.oval:def:5146</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0952" seq="2003-0952" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0953" seq="2003-0953" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0954" seq="2003-0954" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008258">1008258</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9078" patch="1">9078</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48272&amp;apar=only">IY48272</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY48747&amp;apar=only">IY48747</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY49238&amp;apar=only">IY49238</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0955" seq="2003-0955" published="2003-12-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OPENBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch" patch="1">20031105 005: RELIABILITY FIX: November 4, 2003</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013315.html">20031104 OpenBSD kernel overflow, yet still *BSD much better than windows</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2">http://marc.info/?l=openbsd-security-announce&amp;m=106808820119679&amp;w=2</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2">http://marc.info/?l=openbsd-security-announce&amp;m=106917441524978&amp;w=2</ref>
      <ref source="MISC" url="http://www.guninski.com/msuxobsd2.html" adv="1">http://www.guninski.com/msuxobsd2.html</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata33.html">20031104 010: RELIABILITY FIX: November 4, 2003</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8978">8978</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0956" seq="2003-0956" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, which might allow local users to obtain sensitive data that was originally owned by other users, a different vulnerability than CVE-2003-0018.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability affects Linux O_DIRECT versions 2.4.22 and previous</sol>
    </sols>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg" adv="1" patch="1">http://linux.bkbits.net:8080/linux-2.4/cset@3ef33d95ym_22QH2xwhDMt264M55Fg</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/42942">linux-kernel-odirect-information-disclosure(42942)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0959" seq="2003-0959" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges via unspecified vectors that trigger copy_from_user function calls with improper length arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A">http://linux.bkbits.net:8080/linux-2.4/cset@3ed382f7UfJ9Q2LKCJq1Tc5B7-EC5A</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/43072">linux-kernel-unspecified-priv-escalation(43072)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0960" seq="2003-0960" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107003609308765&amp;w=2">20031128 [OpenCA Advisory] Vulnerabilities in signature verification</ref>
    </refs>
    <vuln_soft>
      <prod name="openca" vendor="openca">
        <vers num="0.8.0"/>
        <vers num="0.8.1"/>
        <vers num="0.8.6"/>
        <vers num="0.9.0"/>
        <vers num="0.9.0.1"/>
        <vers num="0.9.0.2"/>
        <vers num="0.9.1"/>
        <vers num="0.9.1.2"/>
        <vers num="0.9.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0961" seq="2003-0961" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000796">CLA-2003:796</ref>
      <ref source="MISC" url="http://isec.pl/papers/linux_kernel_do_brk.pdf">http://isec.pl/papers/linux_kernel_do_brk.pdf</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107064798706473&amp;w=2">20031204 [iSEC] Linux kernel do_brk() vulnerability details</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107064830206816&amp;w=2">20031204 Hot fix for do_brk bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-403" adv="1" patch="1">DSA-403</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-417">DSA-417</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-433">DSA-433</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-439">DSA-439</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-440">DSA-440</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-450">DSA-450</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-470">DSA-470</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-475">DSA-475</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/301156">VU#301156</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:110">MDKSA-2003:110</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html">SuSE-SA:2003:049</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-368.html">RHSA-2003:368</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-389.html" adv="1" patch="1">RHSA-2003:389</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0962" seq="2003-0962" published="2003-12-15" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20031202-01-U">20031202-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000794">CLA-2003:794</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107055681311602&amp;w=2">20031204 rsync security advisory (fwd)</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=107055684711629&amp;w=2">2003-0048</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107055702911867&amp;w=2">20031204 [OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107056923528423&amp;w=2">20031204 GLSA: exploitable heap overflow in rsync (200312-03)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/325603">VU#325603</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:111">MDKSA-2003:111</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-398.html" adv="1" patch="1">RHSA-2003:398</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9153" adv="1" patch="1">9153</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13899">linux-rsync-heap-overflow(13899)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9415">oval:org.mitre.oval:def:9415</ref>
    </refs>
    <vuln_soft>
      <prod name="rsync" vendor="andrew_tridgell">
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.8"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
      </prod>
      <prod name="rsync" vendor="redhat">
        <vers num="2.4.6-2" edition=":i386"/>
        <vers num="2.4.6-5" edition=":i386"/>
        <vers num="2.4.6-5" edition=":ia64"/>
        <vers num="2.5.4-2" edition=":i386"/>
        <vers num="2.5.5-1" edition=":i386"/>
        <vers num="2.5.5-4" edition=":i386"/>
      </prod>
      <prod name="secure_community" vendor="engardelinux">
        <vers num="1.0.1"/>
        <vers num="2.0"/>
      </prod>
      <prod name="secure_linux" vendor="engardelinux">
        <vers num="1.1" edition=":professional"/>
        <vers num="1.2" edition=":professional"/>
        <vers num="1.5" edition=":professional"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="8.1"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="current"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0963" seq="2003-0963" published="2004-01-05" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U">20040101-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107126386226196&amp;w=2">20031212 [slackware-security]  lftp security update (SSA:2003-346-01)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107152267121513&amp;w=2">20031213 lftp buffer overflows</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107167974714484&amp;w=2">20031217 [OpenPKG-SA-2003.053] OpenPKG Security Advisory (lftp)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107177409418121&amp;w=2">20031218 GLSA: lftp (200312-07)</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=107340499504411&amp;w=2">CLA-2004:800</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-406">DSA-406</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:116">MDKSA-2003:116</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_051_lftp.html">SuSE-SA:2003:051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-403.html">RHSA-2003:403</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-404.html">RHSA-2003:404</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180">oval:org.mitre.oval:def:11180</ref>
    </refs>
    <vuln_soft>
      <prod name="lftp" vendor="alexander_v._lukyanov">
        <vers num="2.3"/>
        <vers num="2.4.9"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0964" seq="2003-0964" published="2003-11-17" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: N/A. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-0965" seq="2003-0965" published="2004-02-17" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842">CLA-2004:842</ref>
      <ref source="MLIST" url="http://mail.python.org/pipermail/mailman-announce/2003-December/000066.html" adv="1" patch="1">[Mailman-Announce] 20031231 RELEASED Mailman 2.1.4</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-436">DSA-436</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013">MDKSA-2004:013</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-020.html" adv="1" patch="1">RHSA-2004:020</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9336" adv="1">9336</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14121">mailman-admin-xss(14121)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A813">oval:org.mitre.oval:def:813</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0966" seq="2003-0966" published="2004-02-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the frm command in elm 2.5.6 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code via a long Subject line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
      <ref source="MISC" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=112078</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-009.html" adv="1" patch="1">RHSA-2004:009</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9430" adv="1" patch="1">9430</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14840">elm-frm-subject-bo(14840)</ref>
    </refs>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0967" seq="2003-0967" published="2003-12-15" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106935911101493&amp;w=2">20031120 Remote DoS in FreeRADIUS, all versions.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106944220426970">20031121 FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=freeradius-users&amp;m=106947389449613&amp;w=2">http://marc.info/?l=freeradius-users&amp;m=106947389449613&amp;w=2</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-386.html">RHSA-2003:386</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10917">oval:org.mitre.oval:def:10917</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="0.9.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0968" seq="2003-0968" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106986437621130&amp;w=2">20031126 FreeRADIUS &lt;= 0.9.3 rlm_smb module stack overflow vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0969" seq="2003-0969" published="2004-01-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-411">DSA-411</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_02_tcpdump.html">SuSE-SA:2004:002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9364" adv="1">9364</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14148">mpg321-mp3-format-string(14148)</ref>
    </refs>
    <vuln_soft>
      <prod name="mpg321" vendor="mpg321">
        <vers num="0.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0970" seq="2003-0970" published="2003-12-15" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57430" adv="1" patch="1">57430</ref>
    </refs>
    <vuln_soft>
      <prod name="sun_fire" vendor="sun">
        <vers num="b1600"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0971" seq="2003-0971" published="2003-12-15" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000798">CLA-2003:798</ref>
      <ref source="CONFIRM" url="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html" adv="1" patch="1">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.html</ref>
      <ref source="CONFIRM" url="http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html" patch="1">http://lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106995769213221&amp;w=2">20031127 GnuPG's ElGamal signing keys compromised</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-429">DSA-429</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/940388">VU#940388</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:109">MDKSA-2003:109</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_048_gpg.html">SuSE-SA:2003:048</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-390.html">RHSA-2003:390</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-395.html">RHSA-2003:395</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9115" adv="1" patch="1">9115</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982">oval:org.mitre.oval:def:10982</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.3b"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2" edition="rc1"/>
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0972" seq="2003-0972" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000809">CLA-2004:809</ref>
      <ref source="CONFIRM" url="http://groups.yahoo.com/group/gnu-screen/message/3118">http://groups.yahoo.com/group/gnu-screen/message/3118</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106995837813873&amp;w=2">20031127 GNU screen buffer overflow</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-408" adv="1" patch="1">DSA-408</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:113">MDKSA-2003:113</ref>
    </refs>
    <vuln_soft>
      <prod name="screen" vendor="gnu">
        <vers num="3.9.4"/>
        <vers num="3.9.8"/>
        <vers num="3.9.9"/>
        <vers num="3.9.10"/>
        <vers num="3.9.11"/>
        <vers num="3.9.13"/>
        <vers num="3.9.15"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0973" seq="2003-0973" published="2003-12-15" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FEDORA" url="http://bugzilla.fedora.us/show_bug.cgi?id=1325">FEDORA-2004-1325</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000837">CLA-2004:837</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-452" adv="1" patch="1">DSA-452</ref>
      <ref source="CONFIRM" url="http://www.modpython.org/pipermail/mod_python/2003-November/004005.html" patch="1">http://www.modpython.org/pipermail/mod_python/2003-November/004005.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-058.html" adv="1" patch="1">RHSA-2004:058</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-063.html">RHSA-2004:063</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10259">oval:org.mitre.oval:def:10259</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A828">oval:org.mitre.oval:def:828</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A839">oval:org.mitre.oval:def:839</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_python" vendor="apache">
        <vers num="2.7"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0974" seq="2003-0974" published="2003-12-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107004362416252&amp;w=2">20031128 Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107005523025918&amp;w=2">20031128 Applied Watch Response to Bugtraq.org post - Was: Multiple Remote Issues in Applied Watch IDS Suite</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107031196324376&amp;w=2">20031201 Re: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached)</ref>
      <ref source="MISC" url="http://www.bugtraq.org/advisories/_BSSADV-0000.txt">http://www.bugtraq.org/advisories/_BSSADV-0000.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9124" adv="1" patch="1">9124</ref>
    </refs>
    <vuln_soft>
      <prod name="applied_watch_command_center" vendor="applied_watch_technologies">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0975" seq="2003-0975" published="2003-12-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00042.html">http://lists.apple.com/mhonarc/security-announce/msg00042.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106917674428552&amp;w=2">20031118 Apple Safari 1.1 (v100)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7973">mozilla-netscape-steal-cookies(7973)</ref>
    </refs>
    <vuln_soft>
      <prod name="safari" vendor="apple">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.1"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0976" seq="2003-0976" published="2003-12-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm" adv="1" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10089375.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13915">netware-nfs-share-access(13915)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="6.5" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0977" seq="2003-0977" published="2004-01-05" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONFIRM" url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1" patch="1">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&amp;JServSessionIdservlets=8u3x1myav1</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000808">CLA-2004:808</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107168035515554&amp;w=2">20031217 [OpenPKG-SA-2003.052] OpenPKG Security Advisory (cvs)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107540163908129&amp;w=2">20040129 [FLSA-2004:1207] Updated cvs resolves security vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-422" adv="1" patch="1">DSA-422</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:112">MDKSA-2003:112</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-003.html">RHSA-2004:003</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-004.html">RHSA-2004:004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13929">cvs-module-file-manipulation(13929)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528">oval:org.mitre.oval:def:11528</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855">oval:org.mitre.oval:def:855</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866">oval:org.mitre.oval:def:866</ref>
    </refs>
    <vuln_soft>
      <prod name="cvs" vendor="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.1_p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="8.1"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0978" seq="2003-0978" published="2004-01-05" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107047470625214&amp;w=2">20031203 GnuPG 1.2.3, 1.3.3 external HKP interface format string issue</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_048_gpg.html">SuSE-SA:2003:048</ref>
      <ref source="MISC" url="http://www.s-quadra.com/advisories/Adv-20031203.txt">http://www.s-quadra.com/advisories/Adv-20031203.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13892">gnupg-gpgkeyshkp-format-string(13892)</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2" edition="rc1"/>
        <vers num="1.2.3"/>
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0979" seq="2003-0979" published="2004-01-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
      <ref source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" adv="1" patch="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="visitorbook" vendor="freescripts">
        <vers num="le"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0980" seq="2003-0980" published="2004-01-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" parameter from a host with a malicious reverse DNS name, (3) via quote marks or ampersands in other parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
      <ref source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" adv="1" patch="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="visitorbook" vendor="freescripts">
        <vers num="le"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0981" seq="2003-0981" published="2004-01-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107107840622493&amp;w=2">20031210 Visitorbook LE Multiple Vulnerabilities</ref>
      <ref source="MISC" url="http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt" adv="1" patch="1">http://www.westpoint.ltd.uk/advisories/wp-03-0001.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="visitorbook" vendor="freescripts">
        <vers num="le"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0982" seq="2003-0982" published="2004-01-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml" adv="1" patch="1">20031210 Vulnerability in Authentication Library for ACNS</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/352462">VU#352462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9187" adv="1" patch="1">9187</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13945">cisco-acns-password-bo(13945)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_and_content_networking_software" vendor="cisco">
        <vers num="4.0.3"/>
        <vers num="4.1.1"/>
        <vers num="4.1.3"/>
        <vers num="4.2"/>
        <vers num="4.2.7"/>
        <vers num="4.2.9"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.3"/>
      </prod>
      <prod name="content_distribution_manager_4630" vendor="cisco">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="content_distribution_manager_4650" vendor="cisco">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="content_distribution_manager_4670" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_engine" vendor="cisco">
        <vers num="507"/>
        <vers num="507_2.2_.0"/>
        <vers num="507_3.1"/>
        <vers num="507_4.0"/>
        <vers num="507_4.1"/>
        <vers num="560"/>
        <vers num="560_2.2_.0"/>
        <vers num="560_3.1"/>
        <vers num="560_4.0"/>
        <vers num="560_4.1"/>
        <vers num="590"/>
        <vers num="590_2.2_.0"/>
        <vers num="590_3.1"/>
        <vers num="590_4.0"/>
        <vers num="590_4.1"/>
        <vers num="7320"/>
        <vers num="7320_2.2_.0"/>
        <vers num="7320_3.1"/>
        <vers num="7320_4.0"/>
        <vers num="7320_4.1"/>
      </prod>
      <prod name="content_engine_module" vendor="cisco">
        <vers num="for_cisco_router_2600_series"/>
        <vers num="for_cisco_router_3600_series"/>
        <vers num="for_cisco_router_3700_series"/>
      </prod>
      <prod name="enterprise_content_delivery_network_software" vendor="cisco">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="content_router_4430" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_router_4450" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0983" seq="2003-0983" published="2004-01-05" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031210-unity.shtml" adv="1" patch="1">20031210 Unity Vulnerabilities on IBM-based Servers</ref>
    </refs>
    <vuln_soft>
      <prod name="80-7111-01_for_the_unity-svrx255-1a" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="80-7112-01_for_the_unity-svrx255-2a" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0984" seq="2003-0984" published="2004-01-05" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799">CLA-2004:799</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html">ESA-20040105-001</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:001">MDKSA-2004:001</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html">SuSE-SA:2003:049</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00000.html">FEDORA-2003-046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-417.html">RHSA-2003:417</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html" adv="1" patch="1">RHSA-2004:188</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9154" adv="1">9154</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008594">1008594</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13943">linux-rtc-memory-leak(13943)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1013">oval:org.mitre.oval:def:1013</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A859">oval:org.mitre.oval:def:859</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9406">oval:org.mitre.oval:def:9406</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0985" seq="2003-0985" published="2004-01-20" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040102-01-U">20040102-01-U</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0070.html">20040108 [slackware-security] Slackware 8.1 kernel security update (SSA:2004-008-01)</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000799">CLA-2004:799</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.3/updates/IMNX-2004-73-001-01">IMNX-2004-73-001-01</ref>
      <ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0013-mremap.txt">http://isec.pl/vulnerabilities/isec-0013-mremap.txt</ref>
      <ref source="CONFIRM" url="http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap">http://klecker.debian.org/~joey/security/kernel/patches/patch.CAN-2005-0528.mremap</ref>
      <ref source="TRUSTIX" url="http://marc.info/?l=bugtraq&amp;m=107332754521495&amp;w=2">2004-0001</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107332782121916&amp;w=2">20040105 Linux kernel mremap vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107340358402129&amp;w=2">20040105 Linux kernel do_mremap() proof-of-concept exploit code</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107340814409017&amp;w=2">20040106 Linux mremap bug correction</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107350348418373&amp;w=2">20040107 [slackware-security]  Kernel security update  (SSA:2004-006-01)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107394143105081&amp;w=2">20040112 SmoothWall Project Security Advisory SWP-2004:001</ref>
      <ref source="CONFIRM" url="http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0">http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2005-0528?op=file&amp;rev=0&amp;sc=0</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-045.shtml">O-045</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-413">DSA-413</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-417">DSA-417</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-427">DSA-427</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-439">DSA-439</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-440">DSA-440</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-450">DSA-450</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-470">DSA-470</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-475">DSA-475</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/490620">VU#490620</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html" adv="1" patch="1">ESA-20040105-001</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:001">MDKSA-2004:001</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_03_linux_kernel.html">SuSE-SA:2004:003</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-416.html">RHSA-2003:416</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-417.html" adv="1" patch="1">RHSA-2003:417</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-418.html">RHSA-2003:418</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-419.html">RHSA-2003:419</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9356" adv="1" patch="1">9356</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14135">linux-domremap-gain-privileges(14135)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A860">oval:org.mitre.oval:def:860</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A867">oval:org.mitre.oval:def:867</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0986" seq="2003-0986" published="2003-12-31" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="1.7" CVSS_base_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ" adv="1" patch="1">http://linux.bkbits.net:8080/linux-2.4/cset@3fdd54b3u9Eq0Wny2Nn1HGfI3pofOQ</ref>
      <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw" adv="1" patch="1">http://linux.bkbits.net:8080/linux-2.6/cset@3ffcf122S7e3xPZCpibrXq6KRRjwqw</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-017.html" adv="1" patch="1">RHSA-2004:017</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9707">oval:org.mitre.oval:def:9707</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0987" seq="2003-0987" published="2004-03-03" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008920">1008920</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1">101841</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref>
      <ref source="CONFIRM" url="http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html" patch="1">http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html</ref>
      <ref source="CONFIRM" url="http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html" adv="1">http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-600.html">RHSA-2004:600</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-816.html">RHSA-2005:816</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9571" adv="1" patch="1">9571</ref>
      <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15041">apache-moddigest-response-replay(15041)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100108">oval:org.mitre.oval:def:100108</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4416">oval:org.mitre.oval:def:4416</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0988" seq="2003-0988" published="2004-02-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000810">CLA-2004:810</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107412130407906&amp;w=2">20040114 KDE Security Advisory: VCF file information reader vulnerability</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-02.xml">GLSA-200404-02</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820798">VU#820798</ref>
      <ref source="CONFIRM" url="http://www.kde.org/info/security/advisory-20040114-1.txt" adv="1" patch="1">http://www.kde.org/info/security/advisory-20040114-1.txt</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:003">MDKSA-2004:003</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-005.html" adv="1" patch="1">RHSA-2004:005</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-006.html">RHSA-2004:006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9419" adv="1" patch="1">9419</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14833">kde-kdepim-bo(14833)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A858">oval:org.mitre.oval:def:858</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A865">oval:org.mitre.oval:def:865</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0989" seq="2003-0989" published="2004-02-17" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt">CSSA-2004-008.0</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt">SCOSA-2004.9</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
      <ref source="TRUSTIX" url="http://lwn.net/Alerts/66445/">2004-0004</ref>
      <ref source="ENGARDE" url="http://lwn.net/Alerts/66805/">ESA-20040119-002</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-425" adv="1" patch="1">DSA-425</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/738518" adv="1">VU#738518</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html">FEDORA-2004-090</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html">FEDORA-2004-092</ref>
      <ref source="MLIST" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-007.html" adv="1" patch="1">RHSA-2004:007</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/350238/30/21640/threaded">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9507">9507</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008716">1008716</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10599">oval:org.mitre.oval:def:10599</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A847">oval:org.mitre.oval:def:847</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A852">oval:org.mitre.oval:def:852</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="redhat">
        <vers num="3.8.0" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="9.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0990" seq="2003-0990" published="2004-01-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107247236124180&amp;w=2">20031224 Bugtraq Security Systems ADV-0001</ref>
      <ref source="MISC" url="http://www.bugtraq.org/advisories/_BSSADV-0001.txt">http://www.bugtraq.org/advisories/_BSSADV-0001.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348366" adv="1">20031226 Re: Reported Command Injection in Squirrelmail GPG</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9296" adv="1">9296</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14079">squirrelmail-parseaddress-command-execution(14079)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-0991" seq="2003-0991" published="2004-03-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842">CLA-2004:842</ref>
      <ref source="MLIST" url="http://mail.python.org/pipermail/mailman-announce/2004-February/000067.html" adv="1" patch="1">[Mailman-Announce] 20040208 RELEASED: Mailman 2.0.14 patch-only release</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-436" adv="1" patch="1">DSA-436</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013">MDKSA-2004:013</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-019.html" adv="1" patch="1">RHSA-2004:019</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9620" adv="1" patch="1">9620</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15106">mailman-command-handler-dos(15106)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="beta4"/>
        <vers num="2.0" edition="beta5"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.1"/>
      </prod>
      <prod name="propack" vendor="sgi">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0992" seq="2003-0992" published="2004-02-17" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842">CLA-2004:842</ref>
      <ref source="CONFIRM" url="http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html" adv="1" patch="1">http://mail.python.org/pipermail/mailman-announce/2003-September/000061.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:013">MDKSA-2004:013</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-020.html" adv="1" patch="1">RHSA-2004:020</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A815">oval:org.mitre.oval:def:815</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.1.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0993" seq="2003-0993" published="2004-03-29" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref>
      <ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=23850">http://issues.apache.org/bugzilla/show_bug.cgi?id=23850</ref>
      <ref source="MLIST" url="http://marc.info/?l=apache-cvs&amp;m=107869603013722">[apache-cvs] 20040307 cvs commit: apache-1.3/src/modules/standard mod_access.c</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1">101841</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/features/security-13" adv="1">http://www.apacheweek.com/features/security-13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9829" adv="1" patch="1">9829</ref>
      <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15422">apache-modaccess-obtain-information(15422)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100111">oval:org.mitre.oval:def:100111</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4670">oval:org.mitre.oval:def:4670</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7" edition=":dev"/>
        <vers num="1.3.9"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0994" seq="2003-0994" published="2004-02-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015510.html">20040112 SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107393473928245&amp;w=2">20040112 Re:   SRT2004-01-9-1022 - Symantec LiveUpdate allows local users to become SYSTEM</ref>
      <ref source="MISC" url="http://www.secnetops.biz/research/SRT2004-01-09-1022.txt">http://www.secnetops.biz/research/SRT2004-01-09-1022.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="2.1" edition=":ms_exchange"/>
        <vers num="2001" edition=":pro"/>
        <vers num="2002" edition=":pro"/>
        <vers num="2003" edition=":pro"/>
        <vers num="2004" edition=":pro"/>
        <vers num="v3.0" edition=":handhelds"/>
      </prod>
      <prod name="norton_internet_security" vendor="symantec">
        <vers num="2001" edition=":pro"/>
        <vers num="2002" edition=":pro"/>
        <vers num="2003" edition=":pro"/>
        <vers num="2004" edition=":pro"/>
      </prod>
      <prod name="norton_system_works" vendor="symantec">
        <vers num="2001"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
      <prod name="windows_liveupdate" vendor="symantec">
        <vers num="1.70.x"/>
        <vers num="1.90.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0995" seq="2003-0995" published="2004-01-05" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-039">MS03-039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13131">win2k-message-queue-bo(13131)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0996" seq="2003-0996" published="2004-01-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to gain privileges via the help interface.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.ca.com/techbases/rp/urc6x-secnote.html" adv="1" patch="1">http://support.ca.com/techbases/rp/urc6x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod name="unicenter_remote_control_host" vendor="ca">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0997" seq="2003-0997" published="2004-01-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown "Denial of Service Attack" vulnerability in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers to cause a denial of service (CPU consumption in URC host service).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.ca.com/techbases/rp/urc6x-secnote.html" adv="1" patch="1">http://support.ca.com/techbases/rp/urc6x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod name="unicenter_remote_control_host" vendor="ca">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0998" seq="2003-0998" published="2004-01-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2, and ControlIT 5.0 and 5.1, may allow attackers to gain privileges to the local system account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.ca.com/techbases/rp/urc5x-secnote.html" adv="1" patch="1">http://support.ca.com/techbases/rp/urc5x-secnote.html</ref>
    </refs>
    <vuln_soft>
      <prod name="controlit" vendor="ca">
        <vers num="5.0" edition=":advanced"/>
        <vers num="5.0" edition=":enterprise"/>
        <vers num="5.1" edition=":enterprise"/>
      </prod>
      <prod name="unicenter_remote_control" vendor="ca">
        <vers num="5.2"/>
        <vers num="6.0"/>
      </prod>
      <prod name="unicenter_remote_control_option" vendor="ca">
        <vers num="5.0"/>
        <vers num="5.1" edition="::de"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-0999" seq="2003-0999" published="2004-01-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57451" adv="1" patch="1">57451</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4098">oval:org.mitre.oval:def:4098</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1000" seq="2003-1000" published="2004-01-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html" adv="1" patch="1">http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107152093419276&amp;w=2">20031214 GLSA: Malformed dcc send requests in xchat-2.0.6 lead to a denial of service</ref>
    </refs>
    <vuln_soft>
      <prod name="xchat" vendor="xchat">
        <vers num="2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1001" seq="2003-1001" published="2004-01-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" adv="1" patch="1">20031215 Cisco FWSM Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_6500" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_6500_ws-svc-nam-1" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_6500_ws-svc-nam-2" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_6500_ws-x6380-nam" vendor="cisco">
        <vers num="2.1(2)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-svc-nam-1" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-svc-nam-2" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-x6380-nam" vendor="cisco">
        <vers num="2.1(2)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="firewall_services_module" vendor="cisco">
        <vers num="1.1.2"/>
      </prod>
      <prod name="catos" vendor="cisco">
        <vers num="5.4(1)"/>
        <vers num="7.5(1)"/>
        <vers num="7.6(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1002" seq="2003-1002" published="2004-01-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml" adv="1" patch="1">20031215 Cisco FWSM Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_6500" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_6500_ws-svc-nam-1" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_6500_ws-svc-nam-2" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_6500_ws-x6380-nam" vendor="cisco">
        <vers num="2.1(2)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-svc-nam-1" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-svc-nam-2" vendor="cisco">
        <vers num="2.2(1a)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="catalyst_7600_ws-x6380-nam" vendor="cisco">
        <vers num="2.1(2)"/>
        <vers num="3.1(1a)"/>
      </prod>
      <prod name="firewall_services_module" vendor="cisco">
        <vers num="1.1.2"/>
      </prod>
      <prod name="catos" vendor="cisco">
        <vers num="5.4(1)"/>
        <vers num="7.5(1)"/>
        <vers num="7.6(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1003" seq="2003-1003" published="2004-01-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" adv="1" patch="1">20031215 Cisco PIX Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall" vendor="cisco">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.1(4)"/>
        <vers num="5.1(4.206)"/>
        <vers num="5.2"/>
        <vers num="5.2(1)"/>
        <vers num="5.2(2)"/>
        <vers num="5.2(3.210)"/>
        <vers num="5.2(5)"/>
        <vers num="5.2(6)"/>
        <vers num="5.2(7)"/>
        <vers num="5.2(9)"/>
        <vers num="5.3"/>
        <vers num="5.3(1)"/>
        <vers num="5.3(1.200)"/>
        <vers num="5.3(2)"/>
        <vers num="5.3(3)"/>
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.0(3)"/>
        <vers num="6.0(4)"/>
        <vers num="6.0(4.101)"/>
        <vers num="6.1"/>
        <vers num="6.1(1)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1(3)"/>
        <vers num="6.1(4)"/>
        <vers num="6.1(5)"/>
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.2(3.100)"/>
        <vers num="6.3"/>
        <vers num="6.3(1)"/>
        <vers num="6.3(3.102)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1004" seq="2003-1004" published="2004-01-05" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20031215-pix.shtml" adv="1" patch="1">20031215 Cisco PIX Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall" vendor="cisco">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.2(3.100)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1005" seq="2003-1005" published="2003-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2003/Dec/msg00001.html" adv="1" patch="1">APPLE-SA-2003-12-19</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3704" patch="1">ESB-2003.0867</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9266">9266</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1006" seq="2003-1006" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/878526" adv="1">VU#878526</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/347578" adv="1">20031215 Buffer overflow/privilege escalation in MacOS X</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/347707">20031216 Re: Buffer overflow/privilege escalation in MacOS X</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348097">20031219 Re: Buffer overflow/privilege escalation in MacOS X - hfs.util also</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9228" adv="1" patch="1">9228</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13995">macos-cd9660-bo(13995)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1007" seq="2003-1007" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008532">1008532</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9264" adv="1">9264</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14051">applefileserver-dos(14051)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1008" seq="2003-1008" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14195">macos-screen-saver-bypass(14195)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1009" seq="2003-1009" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://docs.info.apple.com/article.html?artnum=32478">http://docs.info.apple.com/article.html?artnum=32478</ref>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="MISC" url="http://www.carrel.org/dhcp-vuln.html">http://www.carrel.org/dhcp-vuln.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9110" adv="1">9110</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13874">macos-dhcp-gain-privileges(13874)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
      <prod name="mac_os_x_server" vendor="apple">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1010" seq="2003-1010" published="2004-03-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9265" adv="1">9265</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14193">macos-fsusage-gain-privileges(14193)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1011" seq="2003-1011" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1" patch="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343087" adv="1">20031031 Console Root On OSX up to 10.2.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8945" adv="1">8945</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13573">macos-ctrlc-gain-access(13573)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1012" seq="2003-1012" published="2004-01-05" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801">CLA-2004:801</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-407" adv="1" patch="1">DSA-407</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00012.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00012.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002">MDKSA-2004:002</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-001.html" adv="1" patch="1">RHSA-2004:001</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-002.html">RHSA-2004:002</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10202">oval:org.mitre.oval:def:10202</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A856">oval:org.mitre.oval:def:856</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1013" seq="2003-1013" published="2004-01-05" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000801">CLA-2004:801</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-407">DSA-407</ref>
      <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00012.html" adv="1" patch="1">http://www.ethereal.com/appnotes/enpa-sa-00012.html</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:002">MDKSA-2004:002</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-001.html" adv="1" patch="1">RHSA-2004:001</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-002.html">RHSA-2004:002</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10097">oval:org.mitre.oval:def:10097</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A857">oval:org.mitre.oval:def:857</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1014" seq="2003-1014" published="2004-10-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use multiple MIME fields with the same name, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109517732328759&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME field multiple occurrence issue</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/17333">mime-field-filtering-bypass(17333)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1015" seq="2003-1015" published="2004-10-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109525252118936&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME field whitespace issue</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/9273">mime-tools-incorrect-concatenation(9273)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
      </prod>
      <prod name="internet_gatekeeper" vendor="f-secure">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
      </prod>
      <prod name="ripmime" vendor="paul_l_daniels">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1016" seq="2003-1016" published="2004-10-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=109521027007616&amp;w=2">20040914 Corsaire Security Advisory - Multiple vendor MIME field quoting issue</ref>
      <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/17336">mime-quote-filtering-bypass(17336)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
      </prod>
      <prod name="internet_gatekeeper" vendor="f-secure">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
      </prod>
      <prod name="ripmime" vendor="paul_l_daniels">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1017" seq="2003-1017" published="2004-01-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html" adv="1" patch="1">http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8900" adv="1" patch="1">8900</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14013">flash-file-predictable-location(14013)</ref>
    </refs>
    <vuln_soft>
      <prod name="director" vendor="macromedia">
        <vers num="5.0"/>
      </prod>
      <prod name="flash_player" vendor="macromedia">
        <vers num="4.0_r12"/>
        <vers num="5.0"/>
        <vers num="5.0_r50"/>
        <vers num="6.0"/>
        <vers num="6.0.29.0"/>
        <vers num="6.0.40.0"/>
        <vers num="6.0.47.0"/>
        <vers num="6.0.65.0"/>
        <vers num="6.0.79.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1018" seq="2003-1018" published="2004-03-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/9254" adv="1" patch="1">9254</ref>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-20">MSS-OAR-E01-20</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14037">aix-enq-format-string(14037)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1020" seq="2003-1020" published="2004-01-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:117">MDKSA-2003:117</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/347218" adv="1">20031211 irssi - potential remote crash</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13973">irssi-dos(13973)</ref>
    </refs>
    <vuln_soft>
      <prod name="irssi" vendor="irssi">
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
        <vers num="0.8.7"/>
        <vers num="0.8.8"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="9.1" edition=":ppc"/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1021" seq="2003-1021" published="2005-01-26" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5/SCOSA-2005.5.txt">SCOSA-2005.5</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/972598" adv="1" patch="1">VU#972598</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/12372" adv="1">12372</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/19479">openserver-scosession-gain-privilege(19479)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1022" seq="2003-1022" published="2004-01-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-048.shtml" adv="1" patch="1">O-048</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-416" adv="1" patch="1">DSA-416</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9377" adv="1" patch="1">9377</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14154">fspsuite-dot-directory-traversal(14154)</ref>
    </refs>
    <vuln_soft>
      <prod name="fsp" vendor="debian">
        <vers num="2.81.b18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1023" seq="2003-1023" published="2004-01-20" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt">CSSA-2004-014.0</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/09/msg00309.html">20030919 uninitialized buffer in midnight commander</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000833">CLA-2004:833</ref>
      <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-058.shtml">FEDORA-2004-058</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108118433222764&amp;w=2">20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-034.html">RHSA-2004:034</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-035.html">RHSA-2004:035</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-09.xml" adv="1">GLSA-200403-09</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-424">DSA-424</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:007">MDKSA-2004:007</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2004-May/msg00002.html">FLSA:1224</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8658" adv="1">8658</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13247">midnight-commander-vfssresolvesymlink-bo(13247)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A822">oval:org.mitre.oval:def:822</ref>
    </refs>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4.5.52"/>
        <vers num="4.5.55"/>
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1024" seq="2003-1024" published="2004-01-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57455" adv="1" patch="1">57455</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/281356">VU#281356</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9280" adv="1" patch="1">9280</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14065">solaris-lsf-gain-privileges(14065)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1528">oval:org.mitre.oval:def:1528</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1025" seq="2003-1025" published="2004-01-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652278" adv="1">VU#652278</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/346948" adv="1">20031209 Internet Explorer URL parsing vulnerability</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html">TA04-033A</ref>
      <ref source="MISC" url="http://www.zapthedingbat.com/security/ex01/vun1.htm" adv="1">http://www.zapthedingbat.com/security/ex01/vun1.htm</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004">MS04-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13935">ie-domain-url-spoofing(13935)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A490">oval:org.mitre.oval:def:490</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A491">oval:org.mitre.oval:def:491</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A510">oval:org.mitre.oval:def:510</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A511">oval:org.mitre.oval:def:511</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A512">oval:org.mitre.oval:def:512</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A513">oval:org.mitre.oval:def:513</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A526">oval:org.mitre.oval:def:526</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1026" seq="2003-1026" published="2004-01-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106979349517578&amp;w=2">20031125 BackToFramedJpu - a successor of BackToJpu attack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/784102" adv="1">VU#784102</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu">http://www.safecenter.net/UMBRELLAWEBV4/BackToFramedJpu</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html">TA04-033A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004">MS04-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13846">ie-subframe-xss(13846)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A630">oval:org.mitre.oval:def:630</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A643">oval:org.mitre.oval:def:643</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A687">oval:org.mitre.oval:def:687</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A689">oval:org.mitre.oval:def:689</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A745">oval:org.mitre.oval:def:745</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A774">oval:org.mitre.oval:def:774</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A805">oval:org.mitre.oval:def:805</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1027" seq="2003-1027" published="2004-01-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106979479719446&amp;w=2">20031125 HijackClickV2 - a successor of HijackClick attack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/413886" adv="1">VU#413886</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2">http://www.safecenter.net/UMBRELLAWEBV4/HijackClickV2</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006036">1006036</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-033A.html">TA04-033A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-004">MS04-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13844">ie-method-perform-actions(13844)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A527">oval:org.mitre.oval:def:527</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A529">oval:org.mitre.oval:def:529</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A530">oval:org.mitre.oval:def:530</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A531">oval:org.mitre.oval:def:531</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A532">oval:org.mitre.oval:def:532</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A534">oval:org.mitre.oval:def:534</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A629">oval:org.mitre.oval:def:629</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1028" seq="2003-1028" published="2004-01-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106979428718705&amp;w=2">20031125 Note for "Invalid ContentType may disclose cache directory"</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106979624321665&amp;w=2">20031125 Invalid ContentType may disclose cache directory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107038202225587&amp;w=2">20031201 Comments on 5 IE vulnerabilities</ref>
      <ref source="MISC" url="http://www.safecenter.net/UMBRELLAWEBV4/threadid10008">http://www.safecenter.net/UMBRELLAWEBV4/threadid10008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13847">ie-download-directory-disclosure(13847)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1029" seq="2003-1029" published="2004-02-17" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ENGARDE" url="http://lwn.net/Alerts/66805/">ESA-20040119-002</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107193841728533&amp;w=2">20031220 Remote crash in tcpdump from OpenBSD</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107213553214985&amp;w=2">20031221 Re: Remote crash in tcpdump from OpenBSD</ref>
      <ref source="MLIST" url="http://marc.info/?l=tcpdump-workers&amp;m=107228187124962&amp;w=2">[tcpdump-workers] 20031224 Seg fault of tcpdump (v 3.8.1 and below) with malformed l2tp packets</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-425" adv="1" patch="1">DSA-425</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/350238/30/21640/threaded">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008748">1008748</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1030" seq="2003-1030" published="2004-02-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107152094119279&amp;w=2">20031214 DameWare Mini Remote Control Server &lt;= 3.72 Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107187110617266&amp;w=2">20031219 [Exploit]: DameWare Mini Remote Control Server Overflow Exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107392603615840&amp;w=2">20040110 DameWare Mini Remote Control &lt; v3.73 remote exploit by kralor]</ref>
      <ref source="MISC" url="http://sh0dan.org/files/dwmrcs372.txt">http://sh0dan.org/files/dwmrcs372.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/909678" adv="1">VU#909678</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9213" adv="1" patch="1">9213</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14001">dameware-spoof-packet-bo(14001)</ref>
    </refs>
    <vuln_soft>
      <prod name="mini_remote_control_server" vendor="dameware_development">
        <vers num="3.70_.0.0"/>
        <vers num="3.71_.0.0"/>
        <vers num="3.72_.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1031" seq="2003-1031" published="2004-02-17" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0078.html" adv="1">20030808 VBulletin New Member XSS Vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1032" seq="2003-1032" published="2004-02-17" modified="2016-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105465813729100&amp;w=2">20030602 Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105484265218325&amp;w=2">20030605 Re: Tripbit Advisory TA-2003-05 Buffer Overflow Vulnerability in Pi3 Web</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006913">1006913</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7787" adv="1" patch="1">7787</ref>
    </refs>
    <vuln_soft>
      <prod name="pi3web" vendor="pi3">
        <vers num="2.0.2_beta_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1033" seq="2003-1033" published="2004-04-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://listserv.sap.com/pipermail/sapdb.sources/2003-April/000143.html">[SAP DB Dev] 20030422 Security Alert: Development Tools</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105103613727471&amp;w=2">20030422 SRT2003-04-22-1336 - SAP DB Development Tools install flaw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7407" adv="1" patch="1">7407</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7408">7408</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11842">sap-db-gain-privileges(11842)</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_db" vendor="sap">
        <vers num="7.3.00"/>
        <vers num="7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1034" seq="2003-1034" published="2004-04-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104914778303805&amp;w=2">20030331 SRT2003-03-31-1219 - SAP world writable server binaries</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7242" adv="1" patch="1">7242</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11669">sap-db-world-writable(11669)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1035" seq="2003-1035" published="2004-04-15" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004039.html">20030304 SAP R/3, account locking and RFC SDK</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/451378/100/0/threaded">20061112 Old SAP exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7007" adv="1">7007</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11487">sap-sapinfo-lockout-bypass(11487)</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_r_3" vendor="sap">
        <vers num=""/>
      </prod>
      <prod name="sapgui" vendor="sap">
        <vers num="4.6c" edition=":windows"/>
        <vers num="4.6d" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1036" seq="2003-1036" published="2004-04-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14186">sap-multiple-bo(14186)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4.6_pl463" prev="1"/>
        <vers num="6.10_pl30" prev="1"/>
        <vers num="6.20_pl7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1037" seq="2003-1037" published="2004-04-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1009453">1009453</ref>
      <ref source="MISC" url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15514">sap-wgate-format-string(15514)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4.6_pl463" prev="1"/>
        <vers num="6.10_pl30" prev="1"/>
        <vers num="6.20_pl7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1038" seq="2003-1038" published="2004-04-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15516">sap-agate-path-disclosure(15516)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_transaction_server" vendor="sap">
        <vers num="4.6_pl463" prev="1"/>
        <vers num="6.10_pl30" prev="1"/>
        <vers num="6.20_pl7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1039" seq="2003-1039" published="2004-04-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.phenoelit.de/stuff/Phenoelit20c3.pd">http://www.phenoelit.de/stuff/Phenoelit20c3.pd</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15513">mysap-host-header-bo(15513)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysap_business_suite" vendor="sap">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1040" seq="2003-1040" published="2004-04-15" modified="2018-08-13" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040204-01-U.asc">20040204-01-U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLSA-2004:820</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_049_kernel.html">SuSE-SA:2003:049</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">RHSA-2004:069</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html">RHSA-2004:188</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15577">linux-kmod-signals-dos(15577)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9423">oval:org.mitre.oval:def:9423</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1041" seq="2003-1041" published="2004-06-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/187196">VU#187196</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348521" adv="1">20031230 IE 5.x-6.0 allows executing arbitrary programs using showHelp()</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9320" adv="1">9320</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" adv="1">TA04-196A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023">MS04-023</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14105">ie-showhelp-directory-traversal(14105)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1186">oval:org.mitre.oval:def:1186</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1943">oval:org.mitre.oval:def:1943</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3514">oval:org.mitre.oval:def:3514</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A956">oval:org.mitre.oval:def:956</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1042" seq="2003-1042" published="2004-08-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=214290">http://bugzilla.mozilla.org/show_bug.cgi?id=214290</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" adv="1">CLA-2003:774</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343185">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8953" adv="1" patch="1">8953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13594">bugzilla-productname-sql-injection(13594)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1043" seq="2003-1043" published="2004-08-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=219044">http://bugzilla.mozilla.org/show_bug.cgi?id=219044</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774" adv="1">CLA-2003:774</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343185">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8953" adv="1" patch="1">8953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13596">bugzilla-url-sql-injection(13596)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1044" seq="2003-1044" published="2004-08-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=219690">http://bugzilla.mozilla.org/show_bug.cgi?id=219690</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774">CLA-2003:774</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343185">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8953" adv="1" patch="1">8953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13597">bugzilla-groupid-gain-privileges(13597)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1045" seq="2003-1045" published="2004-08-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=209376" adv="1" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=209376</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000774">CLA-2003:774</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343185">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8953" adv="1" patch="1">8953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13600">bugzilla-obtain-information(13600)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1046" seq="2003-1046" published="2004-08-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=209742">http://bugzilla.mozilla.org/show_bug.cgi?id=209742</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343185">20031103 [BUGZILLA] Security Advisory - SQL injection, information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8953" adv="1" patch="1">8953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13602">bugzilla-describecomponents-obtain-info(13602)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.17.1"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1047" seq="2003-1047" published="2004-08-06" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0540.  Reason: This candidate is a duplicate of CVE-2004-0540.  Notes: All CVE users should reference CVE-2004-0540 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1048" seq="2003-1048" published="2004-07-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009445.html">20030902 New Microsoft Internet Explorer mshtml.dll Denial of Service?</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009473.html">20040902 AW: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009506.html">20040903 Re: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll Denial of Service?</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-191.shtml">O-191</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/685364" adv="1">VU#685364</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8530" adv="1">8530</ref>
      <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html">TA04-212A</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025">MS04-025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16804">ie-mshtml-gif-bo(16804)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1793">oval:org.mitre.oval:def:1793</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A206">oval:org.mitre.oval:def:206</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2100">oval:org.mitre.oval:def:2100</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A212">oval:org.mitre.oval:def:212</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A236">oval:org.mitre.oval:def:236</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A509">oval:org.mitre.oval:def:509</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A517">oval:org.mitre.oval:def:517</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1049" seq="2003-1049" published="2004-09-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/9243" adv="1" patch="1">9243</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44841&amp;apar=only" adv="1">IY44841</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY44842&amp;apar=only">IY44842</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14030">db2-dms-insecure-permissions(14030)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.0" edition=":linux"/>
        <vers num="8.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1050" seq="2003-1050" published="2004-09-28" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343804" adv="1" patch="1">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8990" adv="1" patch="1">8990</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13633">db2-multiple-binaries-bo(13633)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1051" seq="2003-1051" published="2004-09-28" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt">http://www.secnetops.com/research/advisories/SRT2003-11-06-0710.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343804" adv="1">20031108 SRT2003-11-06-0710 - IBM DB2 Multiple local security issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8989" adv="1" patch="1">8989</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13633">db2-multiple-binaries-bo(13633)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2" vendor="ibm">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1052" seq="2003-1052" published="2004-09-28" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/331904" adv="1" patch="1">20030805 Slight privilege elevation from bin to root in IBM DB2 7.1 - 8.1 all binaries</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8346" adv="1" patch="1">8346</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12826">ibm-db2-gain-privileges(12826)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2" vendor="ibm">
        <vers num="9.0"/>
      </prod>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="6.0"/>
        <vers num="7.0" edition=":linux"/>
        <vers num="7.1" edition=":linux"/>
        <vers num="7.2" edition=":linux"/>
        <vers num="8.0" edition=":linux"/>
        <vers num="8.1" edition=":aix"/>
        <vers num="8.2" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1053" seq="2003-1053" published="2003-10-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957" adv="1" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=213957</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8770" adv="1" patch="1">8770</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8776" adv="1" patch="1">8776</ref>
      <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html" adv="1">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13358">xshisen-kconv-bo(13358)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13359">xshisen-xshisenlib-bo(13359)</ref>
    </refs>
    <vuln_soft>
      <prod name="xshisen" vendor="xshisen">
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1054" seq="2003-1054" published="2003-04-16" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html" adv="1" patch="1">20030416 [VulnWatch] Apache mod_access_referer denial of service issue</ref>
      <ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=151905" patch="1">http://sourceforge.net/project/shownotes.php?release_id=151905</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7375" adv="1" patch="1">7375</ref>
      <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html" adv="1">http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_access_referer" vendor="mod_access_referer">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1055" seq="2003-1055" published="2003-07-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52222-1" adv="1" patch="1">52222</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3224" adv="1">ESB-2003.0461</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-113.shtml" adv="1" patch="1">N-113</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7064" adv="1" patch="1">7064</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006401">1006401</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11641">solaris-nssldapso1-bo(11641)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1056" seq="2003-1056" published="2003-12-11" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57443-1" adv="1" patch="1">57443</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3688" adv="1" patch="1">ESB-2003.0851</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9199" adv="1" patch="1">9199</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13952">solaris-ed1-tmpfile-insecure(13952)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1057" seq="2003-1057" published="2003-12-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57441-1" adv="1" patch="1">57441</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3675" adv="1" patch="1">ESB-2003.0844</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-035.shtml" adv="1" patch="1">O-035</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9170">9170</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13914">cde-dtprintinfo-gain-privileges(13914)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1058" seq="2003-1058" published="2003-12-03" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57419-1" adv="1" patch="1">57419</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-033.shtml" adv="1" patch="1">O-033</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9147">9147</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13890">solaris-xsun-gain-privileges(13890)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1059" seq="2003-1059" published="2003-11-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57360-1" adv="1" patch="1">57360</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-029.shtml" adv="1" patch="1">O-029</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9076" adv="1" patch="1">9076</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13792">solaris-pgx32-gain-privileges(13792)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1060" seq="2003-1060" published="2003-10-27" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57406-1" adv="1" patch="1">57406</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8929" adv="1" patch="1">8929</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13547">solaris-nfs-ufs-dos(13547)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1061" seq="2003-1061" published="2003-10-14" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57080-1" adv="1" patch="1">57080</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8836" adv="1" patch="1">8836</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13434">solaris-race-dos(13434)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1062" seq="2003-1062" published="2003-10-15" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57340-1" adv="1" patch="1">57340</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8831" adv="1" patch="1">8831</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13435">solaris-sysinfo-read-memory(13435)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1063" seq="2003-1063" published="2003-08-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56300-1" adv="1" patch="1">56300</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-134.shtml" adv="1" patch="1">N-134</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8461" adv="1" patch="1">8461</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12942">solaris-cachefs-inetdconf-overwrite(12942)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1064" seq="2003-1064" published="2003-07-23" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Solaris 8 with IPv6 enabled allows remote attackers to cause a denial of service (kernel panic) via a crafted IPv6 packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55301-1" adv="1" patch="1">55301</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/370060" adv="1" patch="1">VU#370060</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8250" adv="1" patch="1">8250</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12680">solaris-ipv6-packet-dos(12680)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1065" seq="2003-1065" published="2003-07-23" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55340-1" adv="1" patch="1">55340</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8253" adv="1" patch="1">8253</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/19437">automountd-dos(19437)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/19441">openssh-ldap-dos(19441)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1066" seq="2003-1066" published="2003-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55440-1" adv="1">55440</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324015">20030604 Solaris syslogd overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7820" patch="1">7820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12194">sun-syslogd-bo(12194)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1067" seq="2003-1067" published="2003-06-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55420-1" adv="1" patch="1">55420</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-108.shtml" adv="1" patch="1">N-108</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html">http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/64758">64758</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7991" adv="1" patch="1">7991</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12379">sun-database-functions-bo(12379)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1068" seq="2003-1068" published="2003-06-06" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55260-1" adv="1" patch="1">55260</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-105.shtml">N-105</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7835">7835</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11083">solaris-utmp-update-bo(11083)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1069" seq="2003-1069" published="2003-06-03" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54181-1" adv="1">54181</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7794" patch="1">7794</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12140">sun-intelnetd-dos(12140)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1070" seq="2003-1070" published="2003-04-28" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50922-1" adv="1" patch="1">50922</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7455" adv="1" patch="1">7455</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11906">sun-rpcbind-dos(11906)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1071" seq="2003-1071" published="2003-01-03" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1" adv="1" patch="1">51980</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/944241" adv="1">VU#944241</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305105" adv="1">20030103 Solaris 2.x /usr/sbin/wall Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6509">6509</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005882">1005882</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006682">1006682</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11608">solaris-wall-message-spoofing(11608)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1072" seq="2003-1072" published="2003-04-28" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54100-1" adv="1">54100</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7454">7454</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11895">sun-lofiadm-dos(11895)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1073" seq="2003-1073" published="2003-12-31" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0044.html">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</ref>
      <ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0008-sun-at.txt">http://isec.pl/vulnerabilities/isec-0008-sun-at.txt</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50161-1" adv="1">50161</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-070.shtml">N-070</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308577">20030127 Sun Microsystems Solaris at -r job name handling and race condition vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6692">6692</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6693">6693</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005994">1005994</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11179">solaris-at-directory-traversal(11179)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11180">solaris-at-race-condition(11180)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1074" seq="2003-1074" published="2003-03-28" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52111-1" adv="1">52111</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7252">7252</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006411">1006411</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11657">solaris-newtask-root-access(11657)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1075" seq="2003-1075" published="2003-01-27" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50240-1" adv="1" patch="1">50240</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6709">6709</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005996">1005996</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11186">solaris-ftpd-dos(11186)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1076" seq="2003-1076" published="2003-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50904-1" adv="1">50904</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-050.shtml">N-050</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7033">7033</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006234">1006234</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11496">solaris-sendmail-forward-privileges(11496)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1077" seq="2003-1077" published="2003-03-05" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51300-1" adv="1" patch="1">51300</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7032">7032</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006233">1006233</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11481">solaris-ufs-logging-dos(11481)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1078" seq="2003-1078" published="2003-02-28" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1" adv="1" patch="1">51081</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6989">6989</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006195">1006195</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11436">solaris-ftp-plaintext-password(11436)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1079" seq="2003-1079" published="2003-02-18" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50626-1" adv="1" patch="1">50626</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6883">6883</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006131">1006131</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11368">solaris-udp-rpc-dos(11368)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1080" seq="2003-1080" published="2003-02-11" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50751-1" adv="1" patch="1">50751</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6838">6838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006084">1006084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11303">solaris-mail-unauthorized-access(11303)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1081" seq="2003-1081" published="2003-09-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-46903-1" adv="1" patch="1">46903</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3411&amp;cid=1" adv="1">ESB-2003.0621</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-001.shtml" adv="1">O-001</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/464817" adv="1">VU#464817</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5698">5698</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10105">solaris-aspppls-tmpfile-symlink(10105)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1082" seq="2003-1082" published="2003-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50008-1" adv="1">50008</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-105.shtml">N-105</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/596748" adv="1">VU#596748</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6639">6639</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005935">1005935</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11083">solaris-utmp-update-bo(11083)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1083" seq="2003-1083" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-14.xml" patch="1">GLSA-200403-14</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/623854">VU#623854</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/345417" adv="1">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9099" patch="1">9099</ref>
      <ref source="CONFIRM" url="http://www.tildeslash.com/monit/dist/CHANGES.txt">http://www.tildeslash.com/monit/dist/CHANGES.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13817">monit-http-bo(13817)</ref>
    </refs>
    <vuln_soft>
      <prod name="monit" vendor="tildeslash">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1084" seq="2003-1084" published="2003-11-24" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-14.xml" adv="1">GLSA-200403-14</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206382" adv="1">VU#206382</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/345417" adv="1" patch="1">20031124 Monit 4.1 HTTP interface multiple security vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9098" adv="1" patch="1">9098</ref>
      <ref source="CONFIRM" url="http://www.tildeslash.com/monit/dist/CHANGES.txt" adv="1">http://www.tildeslash.com/monit/dist/CHANGES.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13818">monit-negative-content-dos(13818)</ref>
    </refs>
    <vuln_soft>
      <prod name="monit" vendor="tildeslash">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1085" seq="2003-1085" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014062.html">20031123 Thomnson TCM315 Denial of service</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014068.html">20031124 Thomnson TCM315 Denial of service</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=110888093214678&amp;w=2">20050219 Re: [Full-Disclosure] Thomson TCW690 Denial Of Service Vulnerability</ref>
      <ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=110880725322192&amp;w=2">20050219 Thomson TCW690 Denial Of Service Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/345414">20031123 Thomnson TCM315 Denial of service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9091">9091</ref>
      <ref source="MISC" url="http://www.shellsec.net/leer_advisory.php?id=2">http://www.shellsec.net/leer_advisory.php?id=2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13815">thomson-http-get-dos(13815)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1086" seq="2003-1086" published="2003-06-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105638414205498&amp;w=2">20030623 pMachine (PHP) : Include() Security Hole</ref>
      <ref source="CONFIRM" url="http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C" patch="1">http://www.pmachine.com/forum/threads.php?id=7274_0_13_0_C</ref>
    </refs>
    <vuln_soft>
      <prod name="pmachine_free" vendor="pmachine">
        <vers num=""/>
      </prod>
      <prod name="pmachine_pro" vendor="pmachine">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1087" seq="2003-1087" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=109292319608851&amp;w=2">SSRT3460</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7827" patch="1">7827</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12199">hp-diagmond-dos(12199)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1088" seq="2003-1088" published="2003-08-11" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106063199925536&amp;w=2">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1013365" adv="1">1013365</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8388" adv="1">8388</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12867">zorum-index-xss(12867)</ref>
    </refs>
    <vuln_soft>
      <prod name="zorum" vendor="phpoutsourcing">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1089" seq="2003-1089" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106063199925536&amp;w=2">20030811 ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1013365">1013365</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8396">8396</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12868">zorum-index-path-disclosure(12868)</ref>
    </refs>
    <vuln_soft>
      <prod name="zorum" vendor="phpoutsourcing">
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1090" seq="2003-1090" published="2003-02-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104454984001076&amp;w=2">20030206 AbsoluteTelnet 2.00 buffer overflow.</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/666073" adv="1" patch="1">VU#666073</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6785" adv="1" patch="1">6785</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11265">absolutetelnet-title-bar-bo(11265)</ref>
    </refs>
    <vuln_soft>
      <prod name="absolutetelnet" vendor="celestial_software">
        <vers num="2.0"/>
        <vers num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1091" seq="2003-1091" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0245.html">20030522 QuickTime/Darwin Streaming Server security issues</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006822">1006822</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/148564" adv="1">VU#148564</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7660">7660</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12054">darwin-mp3broadcaster-code-execution(12054)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1092" seq="2003-1092" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/100937" adv="1">VU#100937</ref>
      <ref source="OPENPKG" url="http://www.securityfocus.com/archive/1/313847">OpenPKG-SA-2003.017</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7009">7009</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11488">file-afctr-memory-allocation(11488)</ref>
    </refs>
    <vuln_soft>
      <prod name="file_1" vendor="christos_zoulas">
        <vers num="3.28"/>
        <vers num="3.30"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="3.37"/>
        <vers num="3.39"/>
        <vers num="3.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1093" seq="2003-1093" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-24.jsp</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/331937" adv="1">VU#331937</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6586" patch="1">6586</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11057">weblogic-error-password-disclosure(11057)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="6.1" edition="sp1"/>
        <vers num="6.1" edition="sp2"/>
        <vers num="6.1" edition="sp3"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1094" seq="2003-1094" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-35.jsp</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/999788" adv="1">VU#999788</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8320" patch="1">8320</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12799">weblogic-gain-privileges(12799)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1095" seq="2003-1095" published="2003-03-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/691153" adv="1" patch="1">VU#691153</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7130" adv="1" patch="1">7130</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11555">weblogic-app-reauthentication-bypass(11555)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1096" seq="2003-1096" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=108135227731965&amp;w=2">20040407 Release of Cisco Attack tool Asleap</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml" adv="1">20030803 Dictionary Attack on Cisco LEAP Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/473108" adv="1">VU#473108</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/340119">20031003 Dictionary attack against Cisco's LEAP, Wireless LANs vulnerable</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/340365">20031006 Weaknesses in LEAP Challenge/Response</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8755">8755</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12804">cisco-leap-dictionary(12804)</ref>
    </refs>
    <vuln_soft>
      <prod name="leap" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1097" seq="2003-1097" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0374.html">20030429 HPUX rexec buffer overflow vulnerability</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-088.shtml" patch="1">N-088</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/322540" adv="1">VU#322540</ref>
      <ref source="HP" url="http://www.kb.cert.org/vuls/id/CRDY-5MJKM4" adv="1" patch="1">HPSBUX0304-257</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7459" patch="1">7459</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11890">hp-rexec-command-bo(11890)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5611">oval:org.mitre.oval:def:5611</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1098" seq="2003-1098" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/862401" adv="1">VU#862401</ref>
      <ref source="HP" url="http://www.kb.cert.org/vuls/id/IAFY-5HVQDJ" adv="1" patch="1">HPSBUX0301-238</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6638" patch="1">6638</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005936">1005936</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11094">hp-xserver-gain-privileges(11094)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5765">oval:org.mitre.oval:def:5765</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1099" seq="2003-1099" published="2003-12-31" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-032.shtml" patch="1">O-032</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/509454" adv="1">VU#509454</ref>
      <ref source="HP" url="http://www.kb.cert.org/vuls/id/CRDY-5VFQA3" adv="1" patch="1">HPSBUX0312-304</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9141" patch="1">9141</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13882">hp-shar-tmpfile-symlink(13882)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5788">oval:org.mitre.oval:def:5788</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1100" seq="2003-1100" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/488684" adv="1" patch="1">VU#488684</ref>
      <ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0305.html">http://www.procheckup.com/security_info/vuln_pr0305.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8815">8815</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13399">hummingbird-docsfusionserver-multiple-xss(13399)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberdocs" vendor="hummingbird">
        <vers num="3.5.1"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1101" seq="2003-1101" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/715548" adv="1" patch="1">VU#715548</ref>
      <ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0303.html">http://www.procheckup.com/security_info/vuln_pr0303.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8816">8816</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13398">Hummingbird-docsfusionserver-disclose-path(13398)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberdocs" vendor="hummingbird">
        <vers num="3.5.1"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1102" seq="2003-1102" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/989580" adv="1" patch="1">VU#989580</ref>
      <ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0302.html">http://www.procheckup.com/security_info/vuln_pr0302.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13397">Hummingbird-docsfusionserver-file-access(13397)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1103" seq="2003-1103" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/368300" adv="1">VU#368300</ref>
      <ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0304.html">http://www.procheckup.com/security_info/vuln_pr0304.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8800">8800</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13401">hummingbird-docsfusionserver-sql-injection(13401)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberdocs" vendor="hummingbird">
        <vers num="3.1"/>
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1104" seq="2003-1104" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0307.html" patch="1">20030320 IBM Tivoli Firewall Security Toolbox buffer overflow vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/210937" adv="1" patch="1">VU#210937</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7154" patch="1">7154</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11584">tivoli-tfst-relay-bo(11584)</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_firewall_toolbox" vendor="ibm">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1105" seq="2003-1105" published="2003-12-31" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/813208" adv="1">VU#813208</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-032">MS03-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13029">ie-input-type-dos(13029)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01" edition="sp3"/>
        <vers num="5.5"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1106" seq="2003-1106" published="2003-12-31" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?kbid=330716">330716</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/155252" adv="1">VU#155252</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8195">8195</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1107" seq="2003-1107" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;en-us;828026" patch="1">828026</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/222044">VU#222044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13375">mediaplayer-dhtml-code-execution(13375)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
        <vers num="7"/>
        <vers num="7.1"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1108" seq="2003-1108" published="2003-12-31" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5831">oval:org.mitre.oval:def:5831</ref>
    </refs>
    <vuln_soft>
      <prod name="omnipcx" vendor="alcatel-lucent">
        <vers num="5.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1109" seq="2003-1109" published="2003-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml" patch="1">20030221 Multiple Product Vulnerabilities Found by PROTOS SIP Test Suite</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904" patch="1">6904</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006143">1006143</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006144">1006144</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006145">1006145</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="ip_phone_7940" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ip_phone_7960" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="12.2(1)xa"/>
        <vers num="12.2(1)xd"/>
        <vers num="12.2(1)xd1"/>
        <vers num="12.2(1)xd3"/>
        <vers num="12.2(1)xd4"/>
        <vers num="12.2(1)xe"/>
        <vers num="12.2(1)xe2"/>
        <vers num="12.2(1)xe3"/>
        <vers num="12.2(1)xh"/>
        <vers num="12.2(1)xq"/>
        <vers num="12.2(1)xs"/>
        <vers num="12.2(1)xs1"/>
        <vers num="12.2(2)t4"/>
        <vers num="12.2(2)xa"/>
        <vers num="12.2(2)xa1"/>
        <vers num="12.2(2)xa5"/>
        <vers num="12.2(2)xb"/>
        <vers num="12.2(2)xb3"/>
        <vers num="12.2(2)xb4"/>
        <vers num="12.2(2)xf"/>
        <vers num="12.2(2)xg"/>
        <vers num="12.2(2)xh"/>
        <vers num="12.2(2)xh2"/>
        <vers num="12.2(2)xh3"/>
        <vers num="12.2(2)xi"/>
        <vers num="12.2(2)xi1"/>
        <vers num="12.2(2)xi2"/>
        <vers num="12.2(2)xj"/>
        <vers num="12.2(2)xj1"/>
        <vers num="12.2(2)xk"/>
        <vers num="12.2(2)xk2"/>
        <vers num="12.2(2)xn"/>
        <vers num="12.2(2)xt"/>
        <vers num="12.2(2)xt3"/>
        <vers num="12.2(2)xu"/>
        <vers num="12.2(2)xu2"/>
        <vers num="12.2(11)t"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xw"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="5.2(1)"/>
        <vers num="5.2(2)"/>
        <vers num="5.2(3.210)"/>
        <vers num="5.2(5)"/>
        <vers num="5.2(6)"/>
        <vers num="5.2(7)"/>
        <vers num="5.3"/>
        <vers num="5.3(1)"/>
        <vers num="5.3(1.200)"/>
        <vers num="5.3(2)"/>
        <vers num="5.3(3)"/>
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.1(2)"/>
        <vers num="6.2(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1110" seq="2003-1110" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006167" patch="1">1006167</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="CONFIRM" url="http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html" patch="1">http://www.cs.columbia.edu/~xiaotaow/sipc/ouspg.html</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="sipc" vendor="columbia_university">
        <vers num="1.74"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1111" seq="2003-1111" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="CONFIRM" url="http://www.dynamicsoft.com/support/advisory/ca-2003-06.php" adv="1">http://www.dynamicsoft.com/support/advisory/ca-2003-06.php</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="appengine" vendor="dynamicsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1112" seq="2003-1112" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904" patch="1">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="ingate_firewall" vendor="ingate">
        <vers num=""/>
      </prod>
      <prod name="ingate_siparator" vendor="ingate">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1113" seq="2003-1113" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CONFIRM" url="http://www.iptel.org/ser/security/">http://www.iptel.org/ser/security/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904" patch="1">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="sip_express_router" vendor="iptel">
        <vers num="0.8.8"/>
        <vers num="0.8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1114" seq="2003-1114" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="voip_access_devices_and_gateways" vendor="mediatrix_telecom">
        <vers num="sipv2.3"/>
        <vers num="sipv2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1115" seq="2003-1115" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-06.html" adv="1">CA-2003-06</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/528719" adv="1">VU#528719</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6904" patch="1">6904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11379">sip-invite(11379)</ref>
    </refs>
    <vuln_soft>
      <prod name="succession_communication_server_2000" vendor="nortel">
        <vers num="" edition=":compact"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1116" seq="2003-1116" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105012832418415&amp;w=2">20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006550" patch="1">1006550</ref>
      <ref source="MISC" url="http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm">http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/168873" adv="1">VU#168873</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7325" patch="1">7325</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11768">oracle-rra-authentication-bypass(11768)</ref>
    </refs>
    <vuln_soft>
      <prod name="e-business_suite" vendor="oracle">
        <vers num="10.7"/>
        <vers num="11.0"/>
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.3"/>
        <vers num="11.4"/>
        <vers num="11.5"/>
        <vers num="11.6"/>
        <vers num="11.7"/>
        <vers num="11.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1117" seq="2003-1117" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1003604" patch="1">1003604</ref>
      <ref source="CONFIRM" url="http://service.real.com/help/faq/security/bufferoverflow.html" patch="1">http://service.real.com/help/faq/security/bufferoverflow.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/143627" adv="1" patch="1">VU#143627</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/912219">VU#912219</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11362">realsystem-malformed-url-bo(11362)</ref>
    </refs>
    <vuln_soft>
      <prod name="realsystem_proxy" vendor="realnetworks">
        <vers num="8"/>
      </prod>
      <prod name="realsystem_server" vendor="realnetworks">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1118" seq="2003-1118" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004383.html">20030406 Seti@home information leakage and remote compromise</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/146785" adv="1" patch="1">VU#146785</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7292" patch="1">7292</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11731">seti@home-newline-bo(11731)</ref>
    </refs>
    <vuln_soft>
      <prod name="seti_at_home" vendor="university_of_california">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1119" seq="2003-1119" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/333980" adv="1">VU#333980</ref>
      <ref source="CONFIRM" url="http://www.ssh.com/company/newsroom/article/476/" patch="1">http://www.ssh.com/company/newsroom/article/476/</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_shell" vendor="ssh">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1120" seq="2003-1120" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Mar/1009532.html">1009532</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/814198" adv="1" patch="1">VU#814198</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9956" patch="1">9956</ref>
      <ref source="CONFIRM" url="http://www.ssh.com/company/newsroom/article/520/" patch="1">http://www.ssh.com/company/newsroom/article/520/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15585">sshtectiaserver-passwdplugin-race-condition(15585)</ref>
    </refs>
    <vuln_soft>
      <prod name="tectia_server" vendor="ssh">
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1121" seq="2003-1121" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/231705" adv="1">VU#231705</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/609137" adv="1">VU#609137</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-5EXQRP" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5EXQRP</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-5EXQSV" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5EXQSV</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7475" patch="1">7475</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7477" patch="1">7477</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11920">scriptlogic-rpc-modify-registry(11920)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11921">scriptlogic-runadmin-admin-access(11921)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1122" seq="2003-1122" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/813737">VU#813737</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/CRDY-5EXQT9">http://www.kb.cert.org/vuls/id/CRDY-5EXQT9</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7476" patch="1">7476</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11922">scriptlogic-logs$-insecure-permissions(11922)</ref>
    </refs>
    <vuln_soft>
      <prod name="scriptlogic" vendor="scriptlogic">
        <vers num="4.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1123" seq="2003-1123" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006935">1006935</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55100-1" adv="1" patch="1">55100</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/393292" adv="1" patch="1">VU#393292</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7824" patch="1">7824</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12189">sun-applet-access-information(12189)</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="sun">
        <vers num="1.2.2" edition=":solaris"/>
        <vers num="1.2.2_10" edition=":linux"/>
        <vers num="1.2.2_10" edition=":solaris"/>
        <vers num="1.2.2_10" edition=":windows"/>
        <vers num="1.2.2_11" edition=":linux"/>
        <vers num="1.2.2_11" edition=":solaris"/>
        <vers num="1.2.2_11" edition=":windows"/>
        <vers num="1.2.2_12" edition=":windows"/>
        <vers num="1.3" edition=":solaris"/>
        <vers num="1.3.0_02" edition=":linux"/>
        <vers num="1.3.0_02" edition=":solaris"/>
        <vers num="1.3.0_02" edition=":windows"/>
        <vers num="1.3.0_05" edition=":linux"/>
        <vers num="1.3.0_05" edition=":solaris"/>
        <vers num="1.3.0_05" edition=":windows"/>
        <vers num="1.3.1_01" edition=":linux"/>
        <vers num="1.3.1_01" edition=":solaris"/>
        <vers num="1.3.1_01a" edition=":windows"/>
        <vers num="1.3.1_03" edition=":linux"/>
        <vers num="1.3.1_03" edition=":solaris"/>
        <vers num="1.3.1_03" edition=":windows"/>
        <vers num="1.3.1_04" edition=":windows"/>
        <vers num="1.4" edition=":linux"/>
        <vers num="1.4" edition=":solaris"/>
        <vers num="1.4" edition=":windows"/>
        <vers num="1.4.0_01" edition=":windows"/>
      </prod>
      <prod name="jre" vendor="sun">
        <vers num="1.2.2" edition=":solaris"/>
        <vers num="1.2.2" edition=":windows"/>
        <vers num="1.2.2" edition="update10:linux"/>
        <vers num="1.2.2" edition="update10:solaris"/>
        <vers num="1.2.2" edition="update10:windows"/>
        <vers num="1.2.2_003" edition=":linux"/>
        <vers num="1.2.2_011" edition=":linux"/>
        <vers num="1.2.2_011" edition=":solaris"/>
        <vers num="1.2.2_011" edition=":windows"/>
        <vers num="1.2.2_012" edition=":solaris"/>
        <vers num="1.3.0" edition=":linux"/>
        <vers num="1.3.0" edition=":solaris"/>
        <vers num="1.3.0" edition=":windows"/>
        <vers num="1.3.0" edition="update2:linux"/>
        <vers num="1.3.0" edition="update2:solaris"/>
        <vers num="1.3.0" edition="update2:windows"/>
        <vers num="1.3.0" edition="update4:windows"/>
        <vers num="1.3.0" edition="update5:linux"/>
        <vers num="1.3.0" edition="update5:solaris"/>
        <vers num="1.3.0" edition="update5:windows"/>
        <vers num="1.3.1" edition=":linux"/>
        <vers num="1.3.1" edition="update1:linux"/>
        <vers num="1.3.1" edition="update1:solaris"/>
        <vers num="1.3.1" edition="update1:windows"/>
        <vers num="1.3.1" edition="update4:solaris"/>
        <vers num="1.3.1" edition="update4:windows"/>
        <vers num="1.3.1_03" edition=":linux"/>
        <vers num="1.3.1_03" edition=":solaris"/>
        <vers num="1.3.1_03" edition=":windows"/>
        <vers num="1.4" edition=":linux"/>
        <vers num="1.4" edition=":solaris"/>
        <vers num="1.4" edition=":windows"/>
        <vers num="1.4.0_01" edition=":solaris"/>
        <vers num="1.4.0_01" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1124" seq="2003-1124" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-55141-1" adv="1" patch="1">55141</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/758932" adv="1" patch="1">VU#758932</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7960" patch="1">7960</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12343">sunmc-files-writable-permissions(12343)</ref>
    </refs>
    <vuln_soft>
      <prod name="management+center" vendor="sun">
        <vers num="2.1.1"/>
        <vers num="3.0"/>
        <vers num="3.0_revenue_release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1125" seq="2003-1125" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52102-1" adv="1" patch="1">52102</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/195644" adv="1">VU#195644</ref>
    </refs>
    <vuln_soft>
      <prod name="one_directory_server" vendor="sun">
        <vers num="4.16"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1126" seq="2003-1126" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-56180-1" adv="1">56180</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/636964" adv="1">VU#636964</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="6.0" edition="sp3"/>
        <vers num="6.0" edition="sp4"/>
        <vers num="6.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1127" seq="2003-1127" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/371470" adv="1">VU#371470</ref>
      <ref source="MISC" url="http://www.procheckup.com/security_info/vuln_pr0307.html">http://www.procheckup.com/security_info/vuln_pr0307.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9431">9431</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14869">egap-url-information-disclosure(14869)</ref>
    </refs>
    <vuln_soft>
      <prod name="e-gap" vendor="whale_communications">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1128" seq="2003-1128" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583020" adv="1" patch="1">VU#583020</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7534" patch="1">7534</ref>
      <ref source="CONFIRM" url="http://www.x2studios.com/index.php?page=kb&amp;id=16">http://www.x2studios.com/index.php?page=kb&amp;id=16</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12139">xmms-remote-command-execution(12139)</ref>
    </refs>
    <vuln_soft>
      <prod name="xmms_remote" vendor="x2_studios">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1129" seq="2003-1129" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://help.yahoo.com/help/us/mesg/use/use-45.html">http://help.yahoo.com/help/us/mesg/use/use-45.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/272644" adv="1">VU#272644</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/323439" patch="1">20030530 Yahoo! Security Advisory: Yahoo! Voice Chat</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7561">7561</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12130">yahoo-audio-bo(12130)</ref>
    </refs>
    <vuln_soft>
      <prod name="audio_conferencing_activex_control" vendor="yahoo">
        <vers num="1.0.0.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1130" seq="2003-1130" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-1071.  Reason: This candidate is a duplicate of CVE-2003-1071.  Notes: All CVE users should reference CVE-2003-1071 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1131" seq="2003-1131" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=111066494323543&amp;w=2">20050312 KnowledgeBase</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348359">20031224 Remote Code Execution in Knowledge Builder.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9292" patch="1">9292</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14078">knowledgebuilder-indexphp-file-include(14078)</ref>
    </refs>
    <vuln_soft>
      <prod name="knowledgebuilder" vendor="activecampaign">
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.4"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1132" seq="2003-1132" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030430-dns.shtml" adv="1">20041008 Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/714121">VU#714121</ref>
    </refs>
    <vuln_soft>
      <prod name="content_services_switch_11000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_services_switch_11500" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1133" seq="2003-1133" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008004">1008004</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342485">20031025 Some serious security holes in 'The Bat!'</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8891">8891</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13527">thebat-access-email(13527)</ref>
    </refs>
    <vuln_soft>
      <prod name="the_bat" vendor="ritlabs">
        <vers num="1.1"/>
        <vers num="1.5"/>
        <vers num="1.011"/>
        <vers num="1.14"/>
        <vers num="1.015"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.028"/>
        <vers num="1.029"/>
        <vers num="1.031"/>
        <vers num="1.032"/>
        <vers num="1.33"/>
        <vers num="1.34"/>
        <vers num="1.035"/>
        <vers num="1.036"/>
        <vers num="1.037"/>
        <vers num="1.039"/>
        <vers num="1.041"/>
        <vers num="1.42"/>
        <vers num="1.42f"/>
        <vers num="1.043"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.51"/>
        <vers num="1.52"/>
        <vers num="1.53d"/>
        <vers num="1.101"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1134" seq="2003-1134" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012773.html">20031026 Java 1.4.2_02 InsecurityManager JVM crash</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8892">8892</ref>
    </refs>
    <vuln_soft>
      <prod name="java" vendor="sun">
        <vers num="1.3.1"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1135" seq="2003-1135" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342472">20031026 Buffer Overflow in Yahoo messenger Client</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8894">8894</ref>
    </refs>
    <vuln_soft>
      <prod name="messenger" vendor="yahoo">
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1136" seq="2003-1136" published="2003-10-23" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008006" adv="1">1008006</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342475" adv="1">20031026 New Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8895" adv="1">8895</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8896" adv="1">8896</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13522">guestbook-html-xss(13522)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13523">guestbook-doublequotation-xss(13523)</ref>
    </refs>
    <vuln_soft>
      <prod name="chi_kien_uong_guestbook" vendor="chi_kien_uong">
        <vers num="1.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1137" seq="2003-1137" published="2003-10-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342473" adv="1" patch="1">20031027 sh-httpd `wildcard character' vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342766" patch="1">20031028 Re: sh-httpd `wildcard character' vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8897" adv="1" patch="1">8897</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13519">shtttpd-get-information-disclosure(13519)</ref>
    </refs>
    <vuln_soft>
      <prod name="sh-httpd" vendor="charles_steinkuehler">
        <vers num="0.3"/>
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1138" seq="2003-1138" published="2003-10-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342578" adv="1">20031027 Root Directory Listing on RH default apache</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8898" adv="1">8898</ref>
    </refs>
    <vuln_soft>
      <prod name="interchange" vendor="redhat">
        <vers num="2.0.40_21.5" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1139" seq="2003-1139" published="2003-10-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008014" adv="1">1008014</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342476" adv="1">20031027 Musicqueue multiple local vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8899" adv="1">8899</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13520">musicqueue-tmpfile-symlink(13520)</ref>
    </refs>
    <vuln_soft>
      <prod name="musicqueue" vendor="musicqueue">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1140" seq="2003-1140" published="2003-10-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0021.html">20031027 Musicqueue multiple local vulnerabilities</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008014" adv="1">1008014</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342476" adv="1">20031027 Musicqueue multiple local vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8903" adv="1">8903</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13521">musicqueue-getconf-bo(13521)</ref>
    </refs>
    <vuln_soft>
      <prod name="musicqueue" vendor="musicqueue">
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1141" seq="2003-1141" published="2003-11-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343257" adv="1">20031104 SRT2003-11-02-0115 - NIPrint LPD-LPR Remote overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343318">20031104 NIPrint remote exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8968" adv="1">8968</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13591">niprint-bo(13591)</ref>
    </refs>
    <vuln_soft>
      <prod name="niprint_lpd-lpr_print_server" vendor="network_instruments">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1142" seq="2003-1142" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343258" adv="1">20031104 SRT2003-11-02-0218 - NIPrint LPD-LPR Local Help API SYSTEM exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8969" adv="1">8969</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13592">niprint-helpapi-gain-privileges(13592)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1143" seq="2003-1143" published="2003-10-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342957" adv="1" patch="1">20031030 Serious Sam is not so serious</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8936" adv="1" patch="1">8936</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13618">serioussam-games-packet-dos(13618)</ref>
    </refs>
    <vuln_soft>
      <prod name="serioussam" vendor="croteam">
        <vers num="test_2_2.1_a"/>
        <vers num="the_first_encounter_1.0.5"/>
        <vers num="the_second_encounter_1.0.5"/>
        <vers num="the_second_encounter_demo"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1144" seq="2003-1144" published="2003-11-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008093" adv="1">1008093</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343322" adv="1">20031104 Liteserve Buffer Overflow in Handling Server's Log.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8971" adv="1">8971</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13599">liteserve-log-entry-bo(13599)</ref>
    </refs>
    <vuln_soft>
      <prod name="liteserve" vendor="perception">
        <vers num="1.25"/>
        <vers num="1.28"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1145" seq="2003-1145" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343806" adv="1">20031107 OpenAutoClassifieds XSS attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8972" adv="1">8972</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13604">openautoclassifieds-friendmail-xss(13604)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1146" seq="2003-1146" published="2003-05-11" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://security.nnov.ru/docs5347.html" adv="1">http://security.nnov.ru/docs5347.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8977" adv="1">8977</ref>
    </refs>
    <vuln_soft>
      <prod name="easy_php_photo_album" vendor="john_beatty">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1147" seq="2003-1147" published="2003-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0955.  Reason: This candidate is a duplicate of CVE-2003-0955.  Notes: All CVE users should reference CVE-2003-0955 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1148" seq="2003-1148" published="2003-10-25" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0262.html" patch="1">20031026 Les Visiteurs v2.0.1 code injection vulnerability</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008011" patch="1">1008011</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1017065">1017065</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8902" adv="1">8902</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13529">les-visiteurs-file-include(13529)</ref>
    </refs>
    <vuln_soft>
      <prod name="les_visiteurs" vendor="les_visiteurs">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1149" seq="2003-1149" published="2003-10-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2003.10.27.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342548" adv="1">20031027 Norton Internet Security 2003 XSS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8904" adv="1" patch="1">8904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13528">norton-is-blocked-xss(13528)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_internet_security" vendor="symantec">
        <vers num="2003_6.0.4.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1150" seq="2003-1150" published="2003-10-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8907" adv="1">8907</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13564">novell-portmapper-bo(13564)</ref>
    </refs>
    <vuln_soft>
      <prod name="zenworks_desktops" vendor="novell">
        <vers num="3.2" edition="sp2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="6.0" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1151" seq="2003-1151" published="2003-10-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008020" adv="1">1008020</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342678" adv="1">20031028 Fastream NetFile FTP/WebServer 6.0 CSS Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8908" adv="1">8908</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13535">fastream-nonexistent-url-xss(13535)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1152" seq="2003-1152" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012811.html">20031028 STG Security Advisory: [SSA-20031025-05] InfronTech WebTide 7.04 Directory and File Disclosure Vulnerability</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008016">1008016</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8909">8909</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13533">webtide-file-disclosure(13533)</ref>
    </refs>
    <vuln_soft>
      <prod name="webtide" vendor="infrontech">
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1153" seq="2003-1153" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012801.html">20031027 Bytehoard File Disclosure VUlnerability Sequel</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8910">8910</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13531">bytehoard-view-file(13531)</ref>
    </refs>
    <vuln_soft>
      <prod name="bytehoard" vendor="bytehoard">
        <vers num="0.7"/>
        <vers num="0.71"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1154" seq="2003-1154" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=">http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&amp;More=</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8982">8982</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13611">mailsweeper-zip-virus-bypass(13611)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.6_sp1"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1155" seq="2003-1155" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008094" patch="1">1008094</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8983" patch="1">8983</ref>
      <ref source="CONFIRM" url="http://www.xcdroast.org/xcdr098/changelog-a15.html">http://www.xcdroast.org/xcdr098/changelog-a15.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13612">xcdroast-symlink(13612)</ref>
    </refs>
    <vuln_soft>
      <prod name="x-cd-roast" vendor="x-cd-roast">
        <vers num="0.98_alpha10"/>
        <vers num="0.98_alpha11"/>
        <vers num="0.98_alpha12"/>
        <vers num="0.98_alpha13"/>
        <vers num="0.98_alpha14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1156" seq="2003-1156" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343038">20031031 Advisory: Sun's jre/jdk 1.4.2 multiple vulernabilities in linuxinstallers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8937">8937</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13570">sun-jre-java-symlink(13570)</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="sun">
        <vers num="1.4.2" edition=":linux"/>
        <vers num="1.4.2_02" edition=":linux"/>
      </prod>
      <prod name="jre" vendor="sun">
        <vers num="1.4.2" edition=":linux"/>
        <vers num="1.4.2" edition="update2:linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1157" seq="2003-1157" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343040">20031031 IRM 008: Citrix Metaframe XP is vulnerable to Cross Site Scripting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/27948">27948</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8939">8939</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13569">metaframe-error-message-xss(13569)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/40782">citrix-webmanager-login-xss(40782)</ref>
    </refs>
    <vuln_soft>
      <prod name="metaframe" vendor="citrix">
        <vers num="1.0" edition=":xp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1158" seq="2003-1158" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0275.html">20030917 Denial Of Service in Plug &amp; Play Web (FTP) Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8667">8667</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13219">plugandplaywebserver-multiple-commands-dos(13219)</ref>
    </refs>
    <vuln_soft>
      <prod name="plug_and_play_web_server" vendor="plug_and_play_software">
        <vers num="1.0.002c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1159" seq="2003-1159" published="2003-10-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0343.html" adv="1">20031031 DoS in Plug and Play Web Server Proxy Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8941" adv="1">8941</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13572">plugandplaywebserver-get-dos(13572)</ref>
    </refs>
    <vuln_soft>
      <prod name="plug_and_play_web_server_proxy" vendor="plug_and_play">
        <vers num="1.0002c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1160" seq="2003-1160" published="2003-10-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt">http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008049">1008049</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8942">8942</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13567">flexwatch-slash-admin-access(13567)</ref>
    </refs>
    <vuln_soft>
      <prod name="flexwatch_network_video_server" vendor="seyeon">
        <vers num="2.2"/>
        <vers num="model_132"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1161" seq="2003-1161" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8987">8987</ref>
      <ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0621.html">[linux-kernel] 20031105 BK2CVS problem</ref>
      <ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0627.html">[linux-kernel] 20031105 Re: BK2CVS problem</ref>
      <ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0311.0/0630.html">[linux-kernel] 20031105 Re: BK2CVS problem</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1162" seq="2003-1162" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0348.html">20031031 Virginity Security Advisory 2003-002 : Tritanium Bulletin Board - Read and write from/to internal (protected) Threads</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8944">8944</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13587">tritanium-threadid-view-messages(13587)</ref>
    </refs>
    <vuln_soft>
      <prod name="tritanium_bulletin_board" vendor="tritanium_scripts">
        <vers num="0.993_beta"/>
        <vers num="0.994_beta"/>
        <vers num="0.999_beta"/>
        <vers num="1.0_beta"/>
        <vers num="1.1_final"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1163" seq="2003-1163" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://ganglia.sourceforge.net/">http://ganglia.sourceforge.net/</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343689">20031106 DoS for Ganglia</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8988">8988</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13631">ganglia-gmond-dos(13631)</ref>
    </refs>
    <vuln_soft>
      <prod name="gmond" vendor="ganglia">
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1164" seq="2003-1164" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/013070.html">20031031 XSS In mldonkey - But....</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8946">8946</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13615">mldonkey-xss(13615)</ref>
    </refs>
    <vuln_soft>
      <prod name="mldonkey" vendor="mldonkey">
        <vers num="2.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1165" seq="2003-1165" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343111">20031101 BRS WebWeaver 1.06 remote DoS vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8947">8947</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13571">brswebweaver-useragent-bo(13571)</ref>
    </refs>
    <vuln_soft>
      <prod name="webweaver" vendor="brs">
        <vers num="0.49_beta"/>
        <vers num="0.50_beta"/>
        <vers num="0.51_beta"/>
        <vers num="0.52_beta"/>
        <vers num="0.60_beta"/>
        <vers num="0.61_beta"/>
        <vers num="0.62_beta"/>
        <vers num="0.63_beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1166" seq="2003-1166" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.http-com.com/Default.asp?section=Features">http://www.http-com.com/Default.asp?section=Features</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8948">8948</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13622">http-commander-directory-traversal(13622)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_commander" vendor="http_commander">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1167" seq="2003-1167" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342736">20031028 Local root vuln in kpopup</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8915" patch="1">8915</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13540">kpopup-systemcall-execute-code(13540)</ref>
    </refs>
    <vuln_soft>
      <prod name="kpopup" vendor="gernot_stocker">
        <vers num="0.9.1"/>
        <vers num="0.9.5_pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1168" seq="2003-1168" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8949">8949</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1169" seq="2003-1169" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013113.html" patch="1">20031101 DATEV Nutzungskontrolle Bypassing (REG)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8950" patch="1">8950</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13589">nutzungskontrolle-registry-security-bypass(13589)</ref>
    </refs>
    <vuln_soft>
      <prod name="nutzungskontrolle" vendor="datev">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1170" seq="2003-1170" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342736" patch="1">20031028 Local root vuln in kpopup</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8918">8918</ref>
    </refs>
    <vuln_soft>
      <prod name="kpopup" vendor="gernot_stocker">
        <vers num="0.9.1"/>
        <vers num="0.9.5_pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1171" seq="2003-1171" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://adsystems.com.pl/adg-mod_security171.txt">http://adsystems.com.pl/adg-mod_security171.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008025" patch="1">1008025</ref>
      <ref source="CONFIRM" url="http://www.modsecurity.org/download/CHANGES">http://www.modsecurity.org/download/CHANGES</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342767" patch="1">20031028 mod_security 1.7RC1 to 1.7.1 vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8919" patch="1">8919</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13543">mod-security-secfilterout-bo(13543)</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_security" vendor="mod_security">
        <vers num="1.7"/>
        <vers num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1172" seq="2003-1172" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=23949">http://issues.apache.org/bugzilla/show_bug.cgi?id=23949</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007993">1007993</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/6W00L0U8KC.html" patch="1">http://www.securiteam.com/securitynews/6W00L0U8KC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8883">8883</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13499">apachecocoon-directory-traversal-bootini(13499)</ref>
    </refs>
    <vuln_soft>
      <prod name="cocoon" vendor="apache">
        <vers num="2.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1173" seq="2003-1173" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342765">20031028 FirstClass 7.1 HTTP Server: Remote Directory Listing</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342909">20031030 Re: FirstClass 7.1 HTTP Server: Remote Directory Listing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8920" patch="1">8920</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13546">firstclass-view-unauthorized-files(13546)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1174" seq="2003-1174" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008080">1008080</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343177">20031102 ShoutCast server 1.9.2/win32</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8954">8954</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13586">shoutcast-long-icy-dos(13586)</ref>
    </refs>
    <vuln_soft>
      <prod name="shoutcast_server" vendor="nullsoft">
        <vers num="1.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1175" seq="2003-1175" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834374&amp;group_id=64442&amp;atid=507493</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8956">8956</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13630">sympoll-indexphp-xss(13630)</ref>
    </refs>
    <vuln_soft>
      <prod name="sympoll" vendor="synthetic_reality">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1176" seq="2003-1176" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008100">1008100</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343175">20031102 Unauthorized access in Web Wiz Forum</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343314" patch="1">20031104 Re: Unauthorized access in Web Wiz Forum</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8957">8957</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13581">webwizforums-quotemode-message-access(13581)</ref>
    </refs>
    <vuln_soft>
      <prod name="web_wiz_forums" vendor="bdc_enterprises">
        <vers num="6.34"/>
        <vers num="7.01"/>
        <vers num="7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1177" seq="2003-1177" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q4/1459.html">20031024 Vulnerability in MERCUR Mail Server v4.2 SP3 and below</ref>
      <ref source="CONFIRM" url="http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html">http://www.atrium-software.com/mail%20server/pub/mcr42sp3a.html</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html">http://www.securiteam.com/windowsntfocus/6U00N1P8KC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8861">8861</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8889">8889</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13468">mercur-auth-command-dos(13468)</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur_mailserver" vendor="atrium_software">
        <vers num="3.3"/>
        <vers num="3.3_sp1"/>
        <vers num="3.3_sp2"/>
        <vers num="4.1"/>
        <vers num="4.1_sp1"/>
        <vers num="4.2"/>
        <vers num="4.2_sp1"/>
        <vers num="4.2_sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1178" seq="2003-1178" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VIM" url="http://attrition.org/pipermail/vim/2006-October/001080.html">Advanced Poll v2.02 :) &lt;= Remote File Inclusion</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342493">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/448007/100/0/threaded">20061008 Advanced Poll v2.02 :) &lt;= Remote File Inclusion</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8890">8890</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13513">advancedpoll-php-injection(13513)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/29396">advanced-poll-comments-file-include(29396)</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_poll" vendor="advanced_poll">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1179" seq="2003-1179" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt">http://www.phpsecure.info/v2/tutos/frog/AdvancedPoll2.0.2.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342493">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/440780/100/0/threaded">20060721 SolpotCrew Advisory #2 - Advanced Poll ver 2.02 (base_path) Remote File Inclusion</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/19105">19105</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8890">8890</ref>
      <ref source="MISC" url="http://www.solpotcrew.org/adv/solpot-adv-02.txt">http://www.solpotcrew.org/adv/solpot-adv-02.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13514">advancedpoll-php-file-include(13514)</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_poll" vendor="advanced_poll">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1180" seq="2003-1180" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342493">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8890">8890</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13514">advancedpoll-php-file-include(13514)</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_poll" vendor="advanced_poll">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1181" seq="2003-1181" published="2003-10-25" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342493" patch="1">20031025 Advanced Poll : PHP Code Injection, File Include, Phpinfo</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8890" adv="1">8890</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13515">advancedpoll-phpinfo-obtain-information(13515)</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_poll" vendor="advanced_poll">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1182" seq="2003-1182" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8958">8958</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13575">mpmguestbook-ing-xss(13575)</ref>
    </refs>
    <vuln_soft>
      <prod name="mpm_guestbook" vendor="mpm">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1183" seq="2003-1183" published="2003-10-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Files, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf" patch="1">http://www.oracle.com/technology/deploy/security/pdf/2003alert60.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8923" adv="1" patch="1">8923</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13545">oraclecollaborationsuite-file-access(13545)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle_files" vendor="oracle">
        <vers num="9.0.3.1.0"/>
        <vers num="9.0.3.2.0"/>
        <vers num="9.0.3.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1184" seq="2003-1184" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=195009" adv="1">http://sourceforge.net/project/shownotes.php?release_id=195009</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8959" patch="1">8959</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13582">thwboard-multiple-fields-xss(13582)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1185" seq="2003-1185" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=195009" adv="1">http://sourceforge.net/project/shownotes.php?release_id=195009</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8961" patch="1">8961</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13583">thwboard-multiple-sql-injection(13583)</ref>
    </refs>
    <vuln_soft>
      <prod name="thwboard" vendor="thwboard">
        <vers num="2.8_beta"/>
        <vers num="2.81_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1186" seq="2003-1186" published="2003-10-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 2.13.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342785" patch="1">20031029 TelCondex SimpleWebserver Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8925" patch="1">8925</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13549">simplewebserver-referer-bo(13549)</ref>
    </refs>
    <vuln_soft>
      <prod name="simplewebserver" vendor="telcondex">
        <vers num="2.12.30210_build3285"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1187" seq="2003-1187" published="2003-11-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://badwebmasters.net/advisory/017/" adv="1">http://badwebmasters.net/advisory/017/</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013139.html" adv="1">20031102 [bWM#017] Cross-Site-Scripting @ PHPKIT</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8960">8960</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13590">phpkit-include-xss(13590)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpkit" vendor="phpkit">
        <vers num="1.6.02"/>
        <vers num="1.6.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1188" seq="2003-1188" published="2003-11-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343182">20031102 Unichat Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8962">8962</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13610">unichat-nonalphanumeric-character-dos(13610)</ref>
    </refs>
    <vuln_soft>
      <prod name="unichat" vendor="unichat">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1189" seq="2003-1189" published="2003-10-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007992" patch="1">1007992</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8928" patch="1">8928</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13539">nokia-ipso-ipcluster-dos(13539)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipso" vendor="nokia">
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1190" seq="2003-1190" published="2003-11-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in PHPRecipeBook 2.18.</sol>
    </sols>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=193940">http://sourceforge.net/project/shownotes.php?release_id=193940</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8963" patch="1">8963</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13574">phprecipebook-recipe-xss(13574)</ref>
    </refs>
    <vuln_soft>
      <prod name="phprecipebook" vendor="phprecipebook">
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.26a"/>
        <vers num="1.27"/>
        <vers num="1.27a"/>
        <vers num="1.30"/>
        <vers num="1.30a"/>
        <vers num="1.31"/>
        <vers num="2.04"/>
        <vers num="2.05"/>
        <vers num="2.06"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1191" seq="2003-1191" published="2003-10-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0313.html">20031029 E107 DoS vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8930" patch="1">8930</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13553">e107chatboxdos(13553)</ref>
    </refs>
    <vuln_soft>
      <prod name="e107" vendor="e107">
        <vers num="0.545"/>
        <vers num="0.603"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1192" seq="2003-1192" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008075">1008075</ref>
      <ref source="VULNWATCH" url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2003-11/0001.html">20031103 IA WebMail Server 3.x Buffer Overflow Vulnerability</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6B002158UQ.html">http://www.securiteam.com/windowsntfocus/6B002158UQ.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8965">8965</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13580">iawebmailserver-get-bo(13580)</ref>
    </refs>
    <vuln_soft>
      <prod name="ia_webmail_server" vendor="truenorth_software">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1193" seq="2003-1193" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf" patch="1">http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/343520" adv="1" patch="1">20031105 Multiple SQL Injection Vulnerabilities in Oracle Application Server 9i and RDBMS (#NISR05112003)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8966" adv="1">8966</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13593">oracle-portal-sql-injection(13593)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server_portal" vendor="oracle">
        <vers num="3.0.9.8.5"/>
        <vers num="9.0.2.3"/>
        <vers num="9.0.2.3a"/>
        <vers num="9.0.2.3b"/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num="9.0.2"/>
        <vers num="9.0.2.0.0"/>
        <vers num="9.0.2.0.1"/>
        <vers num="9.0.2.1"/>
        <vers num="9.0.2.2"/>
        <vers num="9.0.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1194" seq="2003-1194" published="2003-10-30" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 0.2.4.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008056" patch="1">1008056</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=193878" adv="1">http://sourceforge.net/project/shownotes.php?release_id=193878</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8932" patch="1">8932</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13557">booby-error-message-xss(13557)</ref>
    </refs>
    <vuln_soft>
      <prod name="booby" vendor="booby">
        <vers num="0.1"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1195" seq="2003-1195" published="2003-11-23" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014065.html">20031123 VieNuke VieBoard SQL Injection Vulnerability... again</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13819">vieboard-getmember-sql-injection(13819)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1196" seq="2003-1196" published="2003-11-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8967" patch="1">8967</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13629">vieboard-viewtopic-sql-injection(13629)</ref>
    </refs>
    <vuln_soft>
      <prod name="vieboard" vendor="vienuke">
        <vers num="2.6"/>
        <vers num="2.6_beta_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1197" seq="2003-1197" published="2003-10-30" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342913" adv="1">20031030 Multiple Vulnerabilities in Led-Forums</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8934">8934</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13562">ledforums-indexphp-xss(13562)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13563">ledforums-topicfield-redirect(13563)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1198" seq="2003-1198" published="2003-12-26" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 0.4.6-20040101.</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog" adv="1">http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9345" patch="1">9345</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14119">cherokee-post-request-dos(14119)</ref>
    </refs>
    <vuln_soft>
      <prod name="cherokee_httpd" vendor="cherokee">
        <vers num="0.1"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.2"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
        <vers num="0.4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1199" seq="2003-1199" published="2004-03-11" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107902444305344&amp;w=2">20030311 XSS in MyProxy 20030629</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9846" adv="1">9846</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15438">myproxy-xss(15438)</ref>
    </refs>
    <vuln_soft>
      <prod name="myproxy" vendor="myproxy">
        <vers num="2003-06-29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1200" seq="2003-1200" published="2003-12-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107936753929354&amp;w=2">20040314 Rosiello Security's exploit for MDaemon</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348454" adv="1">20031229 [Hat-Squad] Remote buffer overflow in Mdaemon Raw message Handler</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9317" adv="1">9317</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14097">mdaemon-form2raw-from-bo(14097)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="6.5.2"/>
        <vers num="6.7.5"/>
        <vers num="6.7.9"/>
        <vers num="6.8.0"/>
        <vers num="6.8.1"/>
        <vers num="6.8.2"/>
        <vers num="6.8.3"/>
        <vers num="6.8.4"/>
        <vers num="6.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1201" seq="2003-1201" published="2003-03-20" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in OpenLDAP version 2.1.17.</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685" patch="1">CLSA-2003:685</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-12.xml" patch="1">GLSA-200403-12</ref>
      <ref source="CONFIRM" url="http://www.openldap.org/its/index.cgi?findid=2390" patch="1">http://www.openldap.org/its/index.cgi?findid=2390</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7656" patch="1">7656</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12520">openldap-back-ldbm-dos(12520)</ref>
    </refs>
    <vuln_soft>
      <prod name="openldap" vendor="openldap">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.11_9"/>
        <vers num="2.0.11_11"/>
        <vers num="2.0.11_11s"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.25"/>
        <vers num="2.0.27"/>
        <vers num="2.1.4"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.1.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1202" seq="2003-1202" published="2003-08-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in version 0.98.5. However, there is a report that version 0.98.5 is still affected by this vulnerability.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106132514828641&amp;w=2">20030821 Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106149679129042&amp;w=2">20030821 Re: Remote Execution of Commands in Omail Webmail 0.98.4 and earlier</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8451" patch="1">8451</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12948">omailwebmail-checklogin-code-execution(12948)</ref>
    </refs>
    <vuln_soft>
      <prod name="omail_webmail" vendor="omail">
        <vers num="0.97.3"/>
        <vers num="0.98.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1203" seq="2003-1203" published="2003-03-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html">20030318 Some XSS vulns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7135">7135</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11601">mambo-option-index-xss(11601)</ref>
    </refs>
    <vuln_soft>
      <prod name="mambo_site_server" vendor="mambo">
        <vers num="4.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1204" seq="2003-1204" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) navigation.php, or (4) uploadimage.php, the path parameter in (5) view.php, (6) the choice parameter in upload.php, (7) the sitename parameter in mambosimple.php, (8) the type parameter in upload.php, or the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11) emailnews.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306206">20030110 Mambo Site Server Remote Code Execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6571">6571</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11050">mambo-multiple-scripts-xss(11050)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1205" seq="2003-1205" published="2003-08-06" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106019292611151&amp;w=2">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
      <ref source="MISC" url="http://www.crob.net/studio/ftpserver/">http://www.crob.net/studio/ftpserver/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12838">crob-rename-file-dos(12838)</ref>
    </refs>
    <vuln_soft>
      <prod name="crob_ftp_server" vendor="crob">
        <vers num="2.60.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1206" seq="2003-1206" published="2003-06-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106019292611151&amp;w=2">20030806 DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
      <ref source="MISC" url="http://www.crob.net/studio/ftpserver/">http://www.crob.net/studio/ftpserver/</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-08/0087.html">20030807 Re: DoS Vulnerabilities in Crob FTP Server 2.60.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12834">crob-login-dos(12834)</ref>
    </refs>
    <vuln_soft>
      <prod name="crob_ftp_server" vendor="crob">
        <vers num="2.60.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1207" seq="2003-1207" published="2004-02-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008908">1008908</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/352329">20040201 Vulnerabilities in Crob FTP Server V3.5.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9549">9549</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15105">crob-dir-dos(15105)</ref>
    </refs>
    <vuln_soft>
      <prod name="crob_ftp_server" vendor="crob">
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1208" seq="2003-1208" published="2004-12-03" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in Oracle 9i Database Release 2, version 9.2.0.3.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html" adv="1">20040205 Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-093.shtml" adv="1" patch="1">O-093</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240174" adv="1" patch="1">VU#240174</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/399806" adv="1" patch="1">VU#399806</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/819126" adv="1" patch="1">VU#819126</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/846582" adv="1" patch="1">VU#846582</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora_from_tz.txt" patch="1">http://www.nextgenss.com/advisories/ora_from_tz.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora_numtodsinterval.txt" patch="1">http://www.nextgenss.com/advisories/ora_numtodsinterval.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora_numtoyminterval.txt" patch="1">http://www.nextgenss.com/advisories/ora_numtoyminterval.txt</ref>
      <ref source="MISC" url="http://www.nextgenss.com/advisories/ora_time_zone.txt">http://www.nextgenss.com/advisories/ora_time_zone.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9587" adv="1" patch="1">9587</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15060">oracle-multiple-function-bo(15060)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle9i" vendor="oracle">
        <vers num="enterprise_9.0.1"/>
        <vers num="enterprise_9.2.0"/>
        <vers num="enterprise_9.2.0.1"/>
        <vers num="enterprise_9.2.0.2"/>
        <vers num="personal_9.0.1"/>
        <vers num="personal_9.2"/>
        <vers num="personal_9.2.0.1"/>
        <vers num="personal_9.2.0.2"/>
        <vers num="standard_9.0"/>
        <vers num="standard_9.0.1"/>
        <vers num="standard_9.0.1.2"/>
        <vers num="standard_9.0.1.3"/>
        <vers num="standard_9.0.1.4"/>
        <vers num="standard_9.0.2"/>
        <vers num="standard_9.2"/>
        <vers num="standard_9.2.0.1"/>
        <vers num="standard_9.2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1209" seq="2003-1209" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://monkeyd.sourceforge.net/Changelog.txt">http://monkeyd.sourceforge.net/Changelog.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7201" patch="1">7201</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11650">monkey-content-type-dos(11650)</ref>
    </refs>
    <vuln_soft>
      <prod name="monkey_http_daemon" vendor="monkey-project">
        <vers num="0.1.1"/>
        <vers num="0.5.2"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1210" seq="2003-1210" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html">20030513 More and More SQL injection on PHP-Nuke 6.5.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7588">7588</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11984">phpnuke-multiple-sql-injection(11984)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="6.5" prev="1"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1211" seq="2003-1211" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7837" patch="1">7837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12277">maxwebportal-search-xss(12277)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1212" seq="2003-1212" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7837" patch="1">7837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12278">maxwebportal-form-field-modify(12278)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1213" seq="2003-1213" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0048.html" patch="1">20030606 Critical Vulnerabilities In Max Web Portal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7837" patch="1">7837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12279">maxwebportal-database-access(12279)</ref>
    </refs>
    <vuln_soft>
      <prod name="maxwebportal" vendor="maxwebportal">
        <vers num="1.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1214" seq="2003-1214" published="2004-02-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ezcontents.org/forum/viewtopic.php?t=361" patch="1">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15136">ezcontents-login-bypass(15136)</ref>
    </refs>
    <vuln_soft>
      <prod name="ezcontents" vendor="visualshapers">
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.45b"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1215" seq="2003-1215" published="2003-12-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107273069130885&amp;w=2">20031229 SQL Injection in phpBB's groupcp.php</ref>
      <ref source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943" adv="1" patch="1">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9314" adv="1" patch="1">9314</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14096">phpbb-groupcp-sql-injection(14096)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.0.0"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1216" seq="2003-1216" published="2003-11-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106997132425576&amp;w=2">20031127 phpBB 2.06 search.php SQL injection</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107005608726609&amp;w=2">20031128 [Hat-Squad] phpBB search_id injection exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107196735102970&amp;w=2">20031220 phpBB v2.06 search_id sql injection exploit</ref>
      <ref source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?t=153818" adv="1" patch="1">http://www.phpbb.com/phpBB/viewtopic.php?t=153818</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9122" adv="1" patch="1">9122</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13867">phpbb-searchphp-sql-injection(13867)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.0.0"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1217" seq="2003-1217" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1218" seq="2003-1218" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1219" seq="2003-1219" published="2003-12-31" modified="2012-12-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://osdir.com/ml/web.oscommerce.cvs/2003-12/msg00024.html">[tep-commits] 20031217 [TEP-COMMIT] CVS: catalog/catalog/includes/functions html_output.php,1.58,1.59</ref>
      <ref source="CONFIRM" url="http://www.oscommerce.com/community/bugs,1546">http://www.oscommerce.com/community/bugs,1546</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/347831">20031217 osCommerce Malformed Session ID XSS Vuln</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9238">9238</ref>
    </refs>
    <vuln_soft>
      <prod name="oscommerce" vendor="oscommerce">
        <vers num="2.2_ms2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1220" seq="2003-1220" published="2003-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/25">BEA03-39.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9034" patch="1">9034</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="6.1" edition=":express"/>
        <vers num="6.1" edition=":win32"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp1:win32"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp2:win32"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="6.1" edition="sp4:win32"/>
        <vers num="6.1" edition="sp5:express"/>
        <vers num="6.1" edition="sp5:win32"/>
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition="sp1:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1221" seq="2003-1221" published="2003-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/32">BEA03-40.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9034" patch="1">9034</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp2:win32"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition="sp1:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1222" seq="2003-1222" published="2003-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/63">BEA03-41.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9034" patch="1">9034</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition="sp1:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1223" seq="2003-1223" published="2003-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/48">BEA03-42.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9034" patch="1">9034</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="6.1" edition=":express"/>
        <vers num="6.1" edition=":win32"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp1:win32"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp2:win32"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp3:win32"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="6.1" edition="sp4:win32"/>
        <vers num="6.1" edition="sp5:express"/>
        <vers num="6.1" edition="sp5:win32"/>
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp2:win32"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition="sp1:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1224" seq="2003-1224" published="2003-12-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/22">BEA03-30.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7563" patch="1">7563</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp2:win32"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1225" seq="2003-1225" published="2003-12-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/22">BEA03-30.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7563" patch="1">7563</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp2:win32"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1226" seq="2003-1226" published="2003-12-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/22">BEA03-30.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7563" patch="1">7563</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7587" patch="1">7587</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1227" seq="2003-1227" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.  NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341044" adv="1" patch="1">20031011 Gallery 1.4 including file vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341094">20031011 RE: Gallery 1.4 including file vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341098">20031012 Re: Gallery 1.4 including file vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8814" patch="1">8814</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13419">gallery-indexphp-file-include(13419)</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery" vendor="gallery_project">
        <vers num="1.4"/>
        <vers num="1.4_pl1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1228" seq="2003-1228" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107064887507504&amp;w=2">20031205 [Fwd: Security Alert; possible buffer overflow in all Mathopd versions]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107090601705839&amp;w=2">20031208 Re: [Fwd: Security Alert; possible buffer overflow in all Mathopd</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/5FP0C1FCAW.html" patch="1">http://www.securiteam.com/unixfocus/5FP0C1FCAW.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9871" patch="1">9871</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/15474">mathopd-preparereply-bo(15474)</ref>
    </refs>
    <vuln_soft>
      <prod name="mathopd" vendor="mathopd">
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3_p4"/>
        <vers num="1.3_p5"/>
        <vers num="1.3_p6"/>
        <vers num="1.3_p7"/>
        <vers num="1.3_p8"/>
        <vers num="1.3_p17"/>
        <vers num="1.3_p18"/>
        <vers num="1.4"/>
        <vers num="1.4_p1"/>
        <vers num="1.5_b13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1229" seq="2003-1229" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0334.html">20030128 Incorrect Certificate Validation in Java Secure Socket Extension</ref>
      <ref source="CONFIRM" url="http://java.sun.com/products/jsse/CHANGES.txt">http://java.sun.com/products/jsse/CHANGES.txt</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006007">1006007</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007483">1007483</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50081-1" adv="1" patch="1">50081</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6682" patch="1">6682</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006001">1006001</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0301-239">HPSBUX0301-239</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11182">sun-java-improper-validation(11182)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5883">oval:org.mitre.oval:def:5883</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1230" seq="2003-1230" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://www.securityfocus.com/advisories/5013" adv="1" patch="1">FreeBSD-SA-03:03</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6920" patch="1">6920</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11397">freebsd-syncookie-brute-force(11397)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1231" seq="2003-1231" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008522">1008522</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6D00F2A95C.html" adv="1">http://www.securiteam.com/unixfocus/6D00F2A95C.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9244">9244</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14032">ecwshop-cat-xss(14032)</ref>
    </refs>
    <vuln_soft>
      <prod name="ecw-shop" vendor="ecw-shop">
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1232" seq="2003-1232" published="2003-12-31" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183</ref>
      <ref source="MISC" url="http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f">http://groups.google.com/group/gnu.emacs.bug/browse_frm/thread/9424ec1b2fdae321/c691a2da8904db0f?hl=en&amp;lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;rnum=1&amp;prev=/groups%3Fq%3Dguninski%2Bemacs%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3Dmailman.763.1041357806.19936.bug-gnu-emacs%2540gnu.org%26rnum%3D1#c691a2da8904db0f</ref>
      <ref source="MISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html" patch="1">http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html</ref>
      <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:208">MDKSA-2005:208</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/15375">15375</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="21.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1233" seq="2003-1233" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" patch="1">20030103 Pedestal Software Security Notice</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" patch="1">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</ref>
      <ref source="MISC" url="http://www.phrack.org/show.php?p=59&amp;a=16">http://www.phrack.org/show.php?p=59&amp;a=16</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6511" patch="1">6511</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10979">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</ref>
    </refs>
    <vuln_soft>
      <prod name="integrity_protection_driver" vendor="pedestal_software">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1234" seq="2003-1234" published="2003-12-31" modified="2018-10-19" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:44.filedesc.asc" adv="1">FreeBSD-SA-02:44</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0057.html" patch="1">20030107 FreeBSD Security Advisory FreeBSD-SA-02:44.filedesc</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0006.html">20030106 PDS: Integer overflow in FreeBSD kernel</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10993.php" patch="1">freebsd-kernel-integer-overflow(10993)</ref>
      <ref source="MISC" url="http://www.pine.nl/press/pine-cert-20030101.txt">http://www.pine.nl/press/pine-cert-20030101.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305308/30/26420/threaded">20030106 PDS: Integer overflow in FreeBSD kernel</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6524" patch="1">6524</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005898">1005898</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2" edition="current"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1" edition="release"/>
        <vers num="4.2"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.4"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.9" edition="releng"/>
        <vers num="4.10" edition="release"/>
        <vers num="4.10" edition="release_p8"/>
        <vers num="4.10" edition="releng"/>
        <vers num="4.11" edition="release_p3"/>
        <vers num="4.11" edition="releng"/>
        <vers num="4.11" edition="stable"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1235" seq="2003-1235" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0014.html">20030331 BRS WebWeaver: full disclosure</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11686.php">webweaver-testcgi-info-disclosure(11686)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7283">7283</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1236" seq="2003-1236" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html" patch="1">20030107 [INetCop Security Advisory] Remote format string vulnerability in Tanne.</ref>
      <ref source="CONFIRM" url="http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2" patch="1">http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11006.php">tanne-logger-format-string(11006)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305460" patch="1">20030107 [INetCop Security Advisory] Remote format string vulnerability in    Tanne.</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305663">20030108 Tanne Remote format string exploit (Proof of Concept)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6553" patch="1">6553</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005900">1005900</ref>
    </refs>
    <vuln_soft>
      <prod name="tanne" vendor="tanne">
        <vers num="0.6.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1237" seq="2003-1237" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0274.html">20030222 [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11383.php">wwwboard-message-xss(11383)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6918">6918</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1238" seq="2003-1238" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html">20030318 Some XSS vulns</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11420.php">nuked-klan-team-xss(11420)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6916">6916</ref>
    </refs>
    <vuln_soft>
      <prod name="nuked-klan" vendor="nuked-klan">
        <vers num="1.2"/>
        <vers num="1.2_beta"/>
        <vers num="1.3"/>
        <vers num="1.3_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1239" seq="2003-1239" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html" patch="1">20030223 WihPhoto (PHP)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11429.php">wihphoto-sendphoto-file-disclosure(11429)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312966" patch="1">20030223 WihPhoto (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6929" patch="1">6929</ref>
    </refs>
    <vuln_soft>
      <prod name="wihphoto" vendor="wihphoto">
        <vers num="0.86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1240" seq="2003-1240" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0320.html">20030225 PHP code injection in CuteNews</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11417.php">cutenews-php-file-include(11417)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6935">6935</ref>
    </refs>
    <vuln_soft>
      <prod name="cutenews" vendor="cutephp">
        <vers num="0.88"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1241" seq="2003-1241" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0089.html" adv="1" patch="1">20030221 Myguestbook (PHP)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312762" adv="1" patch="1">20030221 Myguestbook (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6906">6906</ref>
    </refs>
    <vuln_soft>
      <prod name="myguestbook" vendor="levcgi.com">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1242" seq="2003-1242" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" adv="1">20030219 XSS and Path Disclosure in Sage</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11372.php">sage-module-path-disclosure(11372)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6893">6893</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1243" seq="2003-1243" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0236.html" adv="1">20030219 XSS and Path Disclosure in Sage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6894">6894</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11371">sage-mod-xss(11371)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1244" seq="2003-1244" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html" adv="1">20030220 phpBB Security Bugs</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11376.php" patch="1">phpbb-pageheader-sql-injection(11376)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6888" patch="1">6888</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1245" seq="2003-1245" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0302.html" adv="1">20030224 Mambo SiteServer exploit gains administrative privileges</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6926" patch="1">6926</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11398">mambo-sessionid-gain-privileges(11398)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1246" seq="2003-1246" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0017.html" adv="1" patch="1">20030103 Pedestal Software Security Notice</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0018.html" adv="1" patch="1">20030103 Another way to bypass Integrity Protection Driver ('subst' vuln)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10979.php" patch="1">ipd-ntcreatesymboliclinkobject-subs-symlink(10979)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6511" patch="1">6511</ref>
    </refs>
    <vuln_soft>
      <prod name="integrity_protection_driver" vendor="pedestal_software">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1247" seq="2003-1247" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://psoft.net/misc/webshell_patch.html" patch="1">http://psoft.net/misc/webshell_patch.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10999.php" patch="1">hsphere-webshell-readfile-bo(10999)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11002.php" patch="1">hsphere-webshell-diskusage-bo(11002)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11003.php" patch="1">hsphere-webshell-flist-bo(11003)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305313" adv="1" patch="1">20030106 Remote root vuln in HSphere WebShell</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6527">6527</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6537" patch="1">6537</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6538" patch="1">6538</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6540" patch="1">6540</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005893">1005893</ref>
    </refs>
    <vuln_soft>
      <prod name="h-sphere" vendor="positive_software">
        <vers num="2.3_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1248" seq="2003-1248" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://psoft.net/misc/webshell_patch.html" patch="1">http://psoft.net/misc/webshell_patch.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11001.php" patch="1">hsphere-webshell-encodefilename-execution(11001)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305313" adv="1" patch="1">20030106 Remote root vuln in HSphere WebShell</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6537" patch="1">6537</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6539" patch="1">6539</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005893">1005893</ref>
    </refs>
    <vuln_soft>
      <prod name="h-sphere" vendor="positive_software">
        <vers num="2.3_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1249" seq="2003-1249" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0014.html" adv="1" patch="1">20030109 WebIntelligence session hijacking vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11026.php">webintelligence-session-hijacking(11026)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305991" adv="1" patch="1">20030109 WebIntelligence session hijacking vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6569" patch="1">6569</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005906">1005906</ref>
    </refs>
    <vuln_soft>
      <prod name="webintelligence" vendor="businessobjects">
        <vers num="2.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1250" seq="2003-1250" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0015.html" adv="1">20030110 Efficient Networks 5861 DSL Router</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1005980">1005980</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11032.php">efficient-dsl-portscan-dos(11032)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306081" adv="1">20030110 Efficient Networks 5861 DSL Router</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308008">20030123 5861 IP Filtering issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6573">6573</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005910">1005910</ref>
    </refs>
    <vuln_soft>
      <prod name="5861_dsl_router" vendor="efficient_networks">
        <vers num="5.3.80_firmware"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1251" seq="2003-1251" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0005.html" patch="1">20030102 N/X (PHP)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10969.php">nx-file-include(10969)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6500">6500</ref>
    </refs>
    <vuln_soft>
      <prod name="n_x_web_content_management_system_2002" vendor="nx">
        <vers num="prerelease1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1252" seq="2003-1252" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0004.html" adv="1">20030105 A security vulnerability in S8Forum</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10974.php">s8forum-register-command-execution(10974)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305406" adv="1">20030105 A security vulnerability in S8Forum</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6547">6547</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005881">1005881</ref>
    </refs>
    <vuln_soft>
      <prod name="s8forum" vendor="kelli_shaver">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1253" seq="2003-1253" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" adv="1">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11009.php">bookmark4u-file-include(11009)</ref>
    </refs>
    <vuln_soft>
      <prod name="bookmark4u" vendor="sangwan_kim">
        <vers num="1.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1254" seq="2003-1254" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html" patch="1">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11010.php">apb-apbsettings-file-include(11010)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6545">6545</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1255" seq="2003-1255" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0049.html">20030106 Bookmar4U and Active PHP Bookmarks Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6546">6546</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11011">apb-addbookmark-authentication-bypass(11011)</ref>
    </refs>
    <vuln_soft>
      <prod name="active_php_bookmarks" vendor="active_php_bookmarks">
        <vers num="1.1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1256" seq="2003-1256" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" patch="1">20030106 E-theni (PHP)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11013.php">etheni-afflistelangue-file-include(11013)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305381" patch="1">20030106 E-theni (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6970">6970</ref>
    </refs>
    <vuln_soft>
      <prod name="e-theni" vendor="e-theni">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1257" seq="2003-1257" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0009.html" patch="1">20030106 E-theni (PHP)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11012.php">etheni-findthenihome-information-disclosure(11012)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305381" patch="1">20030106 E-theni (PHP)</ref>
    </refs>
    <vuln_soft>
      <prod name="e-theni" vendor="e-theni">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1258" seq="2003-1258" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0017.html" patch="1">20030110 vulnerability in versatile BulletinBoard  Allows Gaining Administrative Privileges.</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11044.php">vbb-unauthorized-privileges(11044)</ref>
    </refs>
    <vuln_soft>
      <prod name="versatilebulletinboard" vendor="versatilebulletinboard">
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1259" seq="2003-1259" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0026.html" adv="1">20030104 CuteFTP: buffer overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10984.php">cuteftp-ftp-banner-bo(10984)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/325659" patch="1">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6518">6518</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1260" seq="2003-1260" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0123.html">20030118 CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2003/Jan/0126.html">20030107 CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11093.php">cuteftp-list-command-bo(11093)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/325659" patch="1">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6642">6642</ref>
    </refs>
    <vuln_soft>
      <prod name="cuteftp" vendor="globalscape">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1261" seq="2003-1261" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0087.html">20030205 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11275.php" patch="1">cuteftp-url-clipboard-bo(11275)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310710">20030206 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/325659">20030618 Re: CuteFTP 5.0 XP, Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6786" patch="1">6786</ref>
    </refs>
    <vuln_soft>
      <prod name="cuteftp" vendor="globalscape">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1262" seq="2003-1262" published="2003-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104195613529429&amp;w=2">20030107 GLSA:  http-fetcher</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11000.php">http-fetcher-httpfetch-bo(11000)</ref>
      <ref source="GENTOO" url="http://www.linuxsecurity.com/content/view/104480/104/">GLSA-200301-6</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305340" patch="1">20030106 [INetCop Security Advisory] Buffer Overflow vulnerability in HTTP Fetcher Library.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6531" patch="1">6531</ref>
    </refs>
    <vuln_soft>
      <prod name="http_fetcher_library" vendor="http_fetcher">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1263" seq="2003-1263" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0011.html" adv="1">20030103 ical 3.7 remote dos</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10973.php">ical-icalexe-port-dos(10973)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6505">6505</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6506" patch="1">6506</ref>
    </refs>
    <vuln_soft>
      <prod name="ical" vendor="brown_bear_software">
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1264" seq="2003-1264" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10997.php">longshine-ap-tftp-access(10997)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305344">20030106 Longshine WLAN Access-Point LCS-883R VU#310201</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305391">20030106 Re: Longshine WLAN Access-Point LCS-883R VU#310201</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6533">6533</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005897">1005897</ref>
    </refs>
    <vuln_soft>
      <prod name="di-614+" vendor="d-link">
        <vers num="2.0"/>
      </prod>
      <prod name="longshine_wireless_ethernet_access_point" vendor="longshine_technologie">
        <vers num="lcs-883r-ac-b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1265" seq="2003-1265" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2002-12/0277.html" adv="1">20030101 Potential disclosure of sensitive information in Netscape 7.0 email client</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10963.php">netscape-email-deletion-failure(10963)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6499">6499</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005871">1005871</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="5.0"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1266" seq="2003-1266" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0022.html" patch="1">20030104 EServ/2.97 remote DoS</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10975.php" patch="1">eserv-remote-data-dos(10975)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6519" patch="1">6519</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6520" patch="1">6520</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6521" patch="1">6521</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6522" patch="1">6522</ref>
    </refs>
    <vuln_soft>
      <prod name="eserv" vendor="etype">
        <vers num="2.92"/>
        <vers num="2.93"/>
        <vers num="2.94"/>
        <vers num="2.95"/>
        <vers num="2.96"/>
        <vers num="2.97"/>
        <vers num="2.98"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1267" seq="2003-1267" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10964.php">guildftpd-aux-port-dos(10964)</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5SP030A8UO.html">http://www.securiteam.com/windowsntfocus/5SP030A8UO.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005864">1005864</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.999"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1268" seq="2003-1268" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.centaura.com.ar/infosec/adv/ashopkart.txt">http://www.centaura.com.ar/infosec/adv/ashopkart.txt</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11029.php">ashopkart-multiple-sql-injection(11029)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305685" adv="1">20030108 a.shopKart Shopping Cart remote vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6558">6558</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005903">1005903</ref>
    </refs>
    <vuln_soft>
      <prod name="a.shop.kart" vendor="urlogy">
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1269" seq="2003-1269" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10976.php">an-http-path-disclosure(10976)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305234" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6528">6528</ref>
    </refs>
    <vuln_soft>
      <prod name="an-http" vendor="an">
        <vers num="1.41e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1270" seq="2003-1270" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10978.php">an-http-script-dos(10978)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305234" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
    </refs>
    <vuln_soft>
      <prod name="an-http" vendor="an">
        <vers num="1.41e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1271" seq="2003-1271" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10977.php">an-http-script-xss(10977)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305234" adv="1">20030104 AN HTTPd v.1.41e: DoS, CSS, real patch attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6529" patch="1">6529</ref>
    </refs>
    <vuln_soft>
      <prod name="an-http" vendor="an">
        <vers num="1.41e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1272" seq="2003-1272" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10980.php">winamp-b4s-playlistname-bo(10980)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6515">6515</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6516">6516</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10981">winamp-b4s-path-bo(10981)</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1273" seq="2003-1273" published="2003-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6517">6517</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10982">winamp-b4s-playlistname-dos(10982)</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1274" seq="2003-1274" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0025.html" adv="1">20030104 WinAmp v.3.0: buffer overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10983">winamp-b4s-path-dos(10983)</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1275" seq="2003-1275" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0013.html" adv="1">20030103 JS Bug makes it possible to deliberately crash Pocket PC IE</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11004.php">pie-javascript-objectinnerhtml-dos(11004)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6507">6507</ref>
    </refs>
    <vuln_soft>
      <prod name="pocket_ie" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1276" seq="2003-1276" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0046.html" adv="1">20030103 Multiple Issues in Nettelephone Dialer</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11007.php">nettelephone-insecure-account-information(11007)</ref>
    </refs>
    <vuln_soft>
      <prod name="nettelephone" vendor="nettelephone">
        <vers num="3.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1277" seq="2003-1277" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10989.php">yabb-newstemplate-xss(10989)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10990.php">yabb-se-index-xss(10990)</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/5BP051F8VE.html" adv="1">http://www.securiteam.com/unixfocus/5BP051F8VE.html</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/5BP061F8US.html" adv="1">http://www.securiteam.com/unixfocus/5BP061F8US.html</ref>
    </refs>
    <vuln_soft>
      <prod name="yabb" vendor="yabb">
        <vers num="1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1278" seq="2003-1278" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/10985.php">opentopic-img-xss(10985)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305232" adv="1">20030104 OpenTopic security hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6523">6523</ref>
    </refs>
    <vuln_soft>
      <prod name="opentopic" vendor="infopop">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1279" seq="2003-1279" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11005.php">splus-tmp-file-symlink(11005)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305342" adv="1">20030105 S-plus /tmp usage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6530">6530</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005896">1005896</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1280" seq="2003-1280" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11022.php">cgihtml-dotdot-directory-traversal(11022)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305469" adv="1">20030107 Multiple cgihtml vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6550">6550</ref>
    </refs>
    <vuln_soft>
      <prod name="cgihtml" vendor="eekim">
        <vers num="1.69"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1281" seq="2003-1281" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11023.php">cgihtml-tmpfile-symlink(11023)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305469" adv="1">20030107 Multiple cgihtml vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6552">6552</ref>
    </refs>
    <vuln_soft>
      <prod name="cgihtml" vendor="eekim">
        <vers num="1.69"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1282" seq="2003-1282" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/11016.php">ibm-netdata-view-variables(11016)</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/5CP061F8VS.html" adv="1">http://www.securiteam.com/securitynews/5CP061F8VS.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005890">1005890</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1283" seq="2003-1283" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0056.html">20030107 KaZaA - Bad Zone</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11031.php">kazaa-ad-local-zone(11031)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6543">6543</ref>
    </refs>
    <vuln_soft>
      <prod name="kazaa_media_desktop" vendor="kazaa">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1284" seq="2003-1284" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007819" patch="1">1007819</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.sambar.com/security.htm" adv="1">http://www.sambar.com/security.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13305">sambar-multiple-vulnerabilities(13305)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1285" seq="2003-1285" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the query string to dumpenv.pl, and (8) the E-Mail field of the guestbook script (book.pl).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007819" patch="1">1007819</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.sambar.com/security.htm" adv="1">http://www.sambar.com/security.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13305">sambar-multiple-vulnerabilities(13305)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16056">sambar-multiple-xss(16056)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="beta5"/>
        <vers num="5.0" edition="beta6"/>
        <vers num="5.1" edition="beta1"/>
        <vers num="5.1" edition="beta2"/>
        <vers num="5.1" edition="beta3"/>
        <vers num="5.1" edition="beta4"/>
        <vers num="5.1" edition="beta5"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0" edition="beta1"/>
        <vers num="6.0" edition="beta2"/>
        <vers num="6.0" edition="beta3"/>
        <vers num="6.0" edition="beta4"/>
        <vers num="6.0" edition="beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1286" seq="2003-1286" published="2003-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" adv="1">20040430 SECURITY.NNOV: Sambar security quest</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007819" patch="1">1007819</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.sambar.com/security.htm" adv="1">http://www.sambar.com/security.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10256" patch="1">10256</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16054">sambar-http-gain-access(16054)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="beta5"/>
        <vers num="5.0" edition="beta6"/>
        <vers num="5.1" edition="beta1"/>
        <vers num="5.1" edition="beta2"/>
        <vers num="5.1" edition="beta3"/>
        <vers num="5.1" edition="beta4"/>
        <vers num="5.1" edition="beta5"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0" edition="beta1"/>
        <vers num="6.0" edition="beta2"/>
        <vers num="6.0" edition="beta3"/>
        <vers num="6.0" edition="beta4"/>
        <vers num="6.0" edition="beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1287" seq="2003-1287" published="2003-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html" adv="1">20040430 SECURITY.NNOV: Sambar security quest</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007819" patch="1">1007819</ref>
      <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=103&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030925 Sambar Server Multiple Vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.sambar.com/security.htm" adv="1">http://www.sambar.com/security.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16059">sambar-post-code-execution(16059)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="beta5"/>
        <vers num="5.0" edition="beta6"/>
        <vers num="5.1" edition="beta1"/>
        <vers num="5.1" edition="beta2"/>
        <vers num="5.1" edition="beta3"/>
        <vers num="5.1" edition="beta4"/>
        <vers num="5.1" edition="beta5"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0" edition="beta1"/>
        <vers num="6.0" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1288" seq="2003-1288" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux-vserver.org/ChangeLog">http://linux-vserver.org/ChangeLog</ref>
      <ref source="MLIST" url="http://list.linux-vserver.org/archive/vserver/msg05630.html">[Vserver] 20031218 SMP oops 2.4.23 v1.22</ref>
      <ref source="MLIST" url="http://list.linux-vserver.org/archive/vserver/msg05631.html">[Vserver] 20031219 Re: SMP oops 2.4.23 v1.22</ref>
      <ref source="MLIST" url="http://list.linux-vserver.org/archive/vserver/msg05658.html">[Vserver] 20031220 Re: SMP oops 2.4.23 v1.22</ref>
    </refs>
    <vuln_soft>
      <prod name="linux-vserver" vendor="vserver">
        <vers num="1.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1289" seq="2003-1289" published="2003-12-31" modified="2017-07-19" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:10.ibcs2.asc">FreeBSD-SA-03:10</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007460" adv="1" patch="1">1007460</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12892">freebsd-ibcs2-kernel-memory(12892)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1290" seq="2003-1290" published="2003-12-31" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/162" adv="1">BEA03-43.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/16215">16215</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9034" patch="1">9034</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13752">weblogic-mbeanhome-obtain-information(13752)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0" edition="sp1:express"/>
        <vers num="6.0" edition="sp1:win32"/>
        <vers num="6.0" edition="sp2:express"/>
        <vers num="6.0" edition="sp2:win32"/>
        <vers num="6.1" edition=":win32"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp1:win32"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp2:win32"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp3:win32"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="6.1" edition="sp4:win32"/>
        <vers num="6.1" edition="sp5:express"/>
        <vers num="6.1" edition="sp5:win32"/>
        <vers num="6.1" edition="sp6:win32"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp1:win32"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp2:win32"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp3:win32"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp4:win32"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp5:win32"/>
        <vers num="7.0.0.1" edition=":win32"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
        <vers num="7.0.0.1" edition="sp1:win32"/>
        <vers num="7.0.0.1" edition="sp2:express"/>
        <vers num="7.0.0.1" edition="sp2:win32"/>
        <vers num="7.0.0.1" edition="sp3:express"/>
        <vers num="7.0.0.1" edition="sp4:express"/>
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition=":win32"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp1:win32"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp2:win32"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp3:win32"/>
        <vers num="8.1" edition="sp4:express"/>
        <vers num="8.1" edition="sp4:win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1291" seq="2003-1291" published="2003-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.vmware.com/download/esx/esx152-patch4.html" patch="1">http://www.vmware.com/download/esx/esx152-patch4.html</ref>
      <ref source="CONFIRM" url="http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk*BWh&amp;p_lva=&amp;p_faqid=1108">http://www.vmware.com/support/kb/enduser/std_adp.php?p_sid=dsxk*BWh&amp;p_lva=&amp;p_faqid=1108</ref>
    </refs>
    <vuln_soft>
      <prod name="esx" vendor="vmware">
        <vers num="1.5.2" edition="patch1"/>
        <vers num="1.5.2" edition="patch2"/>
        <vers num="1.5.2" edition="patch3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1292" seq="2003-1292" published="2003-12-31" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html">20060130 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0980.html">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref>
      <ref source="CONFIRM" url="http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0">http://forums.ashwebstudio.com/viewtopic.php?t=353&amp;start=0</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/329910">20030720 sorry, wrong file</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/16436">16436</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/18248">18248</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/1864">1864</ref>
    </refs>
    <vuln_soft>
      <prod name="ashnews" vendor="ashwebstudio">
        <vers num="0.83"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1293" seq="2003-1293" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/326506" adv="1">20030724 GuestBookHost : Cross Site Scripting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8025">8025</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbookhost" vendor="nukedweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1294" seq="2003-1294" published="2003-12-31" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc">20060602-01-U</ref>
      <ref source="MISC" url="http://jwz.livejournal.com/310943.html">http://jwz.livejournal.com/310943.html</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-107.htm</ref>
      <ref source="CONFIRM" url="http://www.novell.com/linux/download/updates/90_i386.html">http://www.novell.com/linux/download/updates/90_i386.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0498.html">RHSA-2006:0498</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9125">9125</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/1948">ADV-2006-1948</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=124968</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10848">oval:org.mitre.oval:def:10848</ref>
    </refs>
    <vuln_soft>
      <prod name="xscreensaver" vendor="xscreensaver">
        <vers num="4.05_5cl"/>
        <vers num="4.05_6"/>
        <vers num="4.05_6a"/>
        <vers num="4.05_150"/>
        <vers num="4.07_2"/>
        <vers num="4.08_29135cl"/>
        <vers num="4.09_0"/>
        <vers num="4.10_4"/>
        <vers num="4.10_6"/>
        <vers num="4.10_8"/>
        <vers num="4.10_15"/>
        <vers num="4.11_0"/>
        <vers num="4.12_58"/>
        <vers num="4.12_62"/>
        <vers num="4.14_0"/>
        <vers num="4.14_2"/>
        <vers num="4.14_4"/>
        <vers num="4.14_5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1295" seq="2003-1295" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/linux/download/updates/90_i386.html" patch="1">http://www.novell.com/linux/download/updates/90_i386.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9125" adv="1">9125</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1296" seq="2003-1296" published="2003-12-31" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html" adv="1">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13360">easyfilesharing-title-dos(13360)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1297" seq="2003-1297" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0083.html">20031004 Vulnerabilities in Easy File Sharing Web Server (1.2 NEW)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1298" seq="2003-1298" published="2003-12-31" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.." (dot slash dot dot).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152">http://nger.org/anyportal/forum/read.php?f=1&amp;i=152&amp;t=152#reply_152</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/17197">17197</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/1053">ADV-2006-1053</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/25396">anyportalphp-siteman-directory-traversal(25396)</ref>
    </refs>
    <vuln_soft>
      <prod name="anyportal_php" vendor="anyportal_php">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1299" seq="2003-1299" published="2003-12-31" modified="2016-11-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.org/0305-exploits/baby.txt">http://packetstormsecurity.org/0305-exploits/baby.txt</ref>
      <ref source="CONFIRM" url="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" patch="1">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7749">7749</ref>
    </refs>
    <vuln_soft>
      <prod name="baby_ftp_server" vendor="pablo_software_solutions">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1300" seq="2003-1300" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.org/0305-exploits/baby.txt">http://packetstormsecurity.org/0305-exploits/baby.txt</ref>
      <ref source="CONFIRM" url="http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html" patch="1">http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html</ref>
    </refs>
    <vuln_soft>
      <prod name="baby_ftp_server" vendor="pablo_software_solutions">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1301" seq="2003-1301" published="2003-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4396719</ref>
      <ref source="MISC" url="http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300">http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4944300</ref>
      <ref source="MISC" url="http://www.illegalaccess.org/exploit/ObjectStackOverflow.html">http://www.illegalaccess.org/exploit/ObjectStackOverflow.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/434705/100/0/threaded">20060521 Generic Browser Crash with Java 1.4.2_11, Java 1.5.0_06</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/18058">18058</ref>
    </refs>
    <vuln_soft>
      <prod name="jre" vendor="sun">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.4.2_10"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1302" seq="2003-1302" published="2003-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.php.net/bug.php?id=22048">http://bugs.php.net/bug.php?id=22048</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.2" edition=":dev"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1303" seq="2003-1303" published="2003-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.php.net/bug.php?id=24150">http://bugs.php.net/bug.php?id=24150</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040" patch="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10346">oval:org.mitre.oval:def:10346</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1304" seq="2003-1304" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/0081.html">20030705 [Vulnerability] : ProductCart database file can be downloaded remotely</ref>
      <ref source="MISC" url="http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf">http://www.earlyimpact.com/pdf/ProductCart_Security_Tips.pdf</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/438189/100/200/threaded">20060622 productcart soltan_defacer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8112">8112</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/9816">shopping-cart-database-access(9816)</ref>
    </refs>
    <vuln_soft>
      <prod name="productcart" vendor="early_impact">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6_b"/>
        <vers num="1.6_b001"/>
        <vers num="1.6_b002"/>
        <vers num="1.6_b003"/>
        <vers num="1.6_br"/>
        <vers num="1.6_br001"/>
        <vers num="1.6_br003"/>
        <vers num="1.6b"/>
        <vers num="1.6b001"/>
        <vers num="1.6b002"/>
        <vers num="1.6b003"/>
        <vers num="1.6br"/>
        <vers num="1.6br001"/>
        <vers num="1.6br003"/>
        <vers num="1.5002"/>
        <vers num="1.5003"/>
        <vers num="1.5003r"/>
        <vers num="1.5004"/>
        <vers num="1.6002"/>
        <vers num="1.6003"/>
        <vers num="2"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1305" seq="2003-1305" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2003/07/msg00068.html">20030707 Internet Explorer Crash</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1306" seq="2003-1306" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the RemoveServerHeader option is enabled.</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://archives.neohapsis.com/archives/sf/www-mobile/2003-q3/0021.html">[WWW-Mobile-Code] 20030706 can - IIS Version Disclosure</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1307" seq="2003-1307" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">** DISPUTED **  The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port.  NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugs.php.net/38915">http://bugs.php.net/38915</ref>
      <ref source="MISC" url="http://hackerdom.ru/~dimmo/phpexpl.c">http://hackerdom.ru/~dimmo/phpexpl.c</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348368" adv="1">20031226 Hijacking Apache https by mod_php</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/449234/100/0/threaded">20061019 PHP "exec", "system", "popen" problem</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/449298/100/0/threaded">20061020 Re: PHP "exec", "system", "popen" (+small POC)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9302">9302</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0"/>
        <vers num="2.0.9"/>
        <vers num="2.0.28" edition="beta:win32"/>
        <vers num="2.0.32" edition="beta:win32"/>
        <vers num="2.0.34" edition="beta:win32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46" edition=":win32"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1308" seq="2003-1308" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fvwm.org/news/">http://www.fvwm.org/news/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9161" patch="1">9161</ref>
    </refs>
    <vuln_soft>
      <prod name="fvwm" vendor="fvwm">
        <vers num="2.4.17" prev="1"/>
        <vers num="2.5.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1309" seq="2003-1309" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0070.html" adv="1">20030805 Local ZoneAlarm Firewall (probably all versions - tested on v3.1)</ref>
      <ref source="CONFIRM" url="http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html">http://download.zonelabs.com/bin/free/information/znalm/zaReleaseHistory.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8342" adv="1">8342</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12824">device-driver-gain-privileges(12824)</ref>
    </refs>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="3.7.202"/>
        <vers num="3.7.211" edition=":plus"/>
        <vers num="3.7.211" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1310" seq="2003-1310" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8329">8329</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12824">device-driver-gain-privileges(12824)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1311" seq="2003-1311" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://curl.haxx.se/mail/archive-2003-05/0172.html">[curl-users] 20030529 Re: https, redirection and authentication using POST</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1312" seq="2003-1312" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://curl.haxx.se/mail/archive-2003-05/0172.html">[curl-users] 20030529 Re: https, redirection and authentication using POST</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1313" seq="2003-1313" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007884">1007884</ref>
      <ref source="VULNWATCH" url="http://www.securityfocus.com/archive/1/340244">20031004 EMML, EMGB : Include() hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8767">8767</ref>
    </refs>
    <vuln_soft>
      <prod name="mailing_list_manager" vendor="eternalmart">
        <vers num="1.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1314" seq="2003-1314" published="2003-12-31" modified="2017-10-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007885">1007885</ref>
      <ref source="VULNWATCH" url="http://www.securityfocus.com/archive/1/340244">20031004 EMML, EMGB : Include() hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/21720">21720</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8767">8767</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/2980">2980</ref>
    </refs>
    <vuln_soft>
      <prod name="eternalmart_guestbook" vendor="eternalmart">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1315" seq="2003-1315" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008416">1008416</ref>
      <ref source="MISC" url="http://www.neocrome.net/index.php?m=single&amp;id=76">http://www.neocrome.net/index.php?m=single&amp;id=76</ref>
      <ref source="MISC" url="http://www.neocrome.net/page.php?id=1250">http://www.neocrome.net/page.php?id=1250</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9168">9168</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13922">landdownunder-auth-sql-injection(13922)</ref>
    </refs>
    <vuln_soft>
      <prod name="land_down_under" vendor="neocrome">
        <vers num="701"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1316" seq="2003-1316" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mod.php in eNdonesia 8.2 allows remote attackers to obtain sensitive information via a ' (quote) value in the lng parameter, which reveals the path in an error message.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007592" adv="1">1007592</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8507" adv="1">8507</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13042">endonesia-mod-path-disclosure(13042)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1317" seq="2003-1317" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007592" adv="1">1007592</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8506" adv="1">8506</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13041">endonesia-mod-xss(13041)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1318" seq="2003-1318" published="2003-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820430209748&amp;w=2">20030713 TA-2003-07 Denial of Service Attack against Twilight WebServer v1.3.3.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/22090">22090</ref>
      <ref source="MISC" url="http://www.tripbit.org/advisories/twilight_advisory.txt">http://www.tripbit.org/advisories/twilight_advisory.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2003-1319" seq="2003-1319" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0083.html" adv="1">20030608 [SmartFTP] Two Buffer Overflow Vulnerabilities</ref>
      <ref source="MISC" url="http://security.nnov.ru/docs4679.html" adv="1">http://security.nnov.ru/docs4679.html</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006956" adv="1">1006956</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7858" patch="1">7858</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7861" patch="1">7861</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12228">smartftp-pwd-directory-bo(12228)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12231">smartftp-long-list-bo(12231)</ref>
    </refs>
    <vuln_soft>
      <prod name="smartftp" vendor="smartftp">
        <vers num="1.0.973" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1320" seq="2003-1320" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/287771">VU#287771</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/AAMN-5L74VD">http://www.kb.cert.org/vuls/id/AAMN-5L74VD</ref>
    </refs>
    <vuln_soft>
      <prod name="firmware" vendor="sonicwall">
        <vers num="6.4.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1321" seq="2003-1321" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=106150462504484&amp;w=2">20030821 Buffer overflow in Avant Browser 8.02</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8471">8471</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12974">avantbrowser-http-bo(12974)</ref>
    </refs>
    <vuln_soft>
      <prod name="avant_browser" vendor="avant_force">
        <vers num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1322" seq="2003-1322" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/12203.php">mercur-multiple-bo(12203)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324136" adv="1" patch="1">20030606 Multiple Buffer Overflow Vulnerabilities Found in MERCUR Mail server v.4.2 (SP2) - IMAP protocol</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7842">7842</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur_mailserver" vendor="atrium_software">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1323" seq="2003-1323" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" patch="1">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1324" seq="2003-1324" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz" patch="1">http://www.elmme-mailer.org/elm-2.4ME+PL109S.patch.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="elm_me+" vendor="elmme-mailer">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1325" seq="2003-1325" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.2" CVSS_base_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="MISC" url="http://aluigi.altervista.org/adv/csdos.txt">http://aluigi.altervista.org/adv/csdos.txt</ref>
      <ref source="MISC" url="http://packetstormsecurity.org/0304-exploits/hl-headnut.c">http://packetstormsecurity.org/0304-exploits/hl-headnut.c</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life_cstrike_dedicated_server" vendor="valve_software">
        <vers num="1.1.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1326" seq="2003-1326" published="2003-02-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11258.php" adv="1">ie-dialog-zone-bypass(11258)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6779">6779</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-004">MS03-004</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A126">oval:org.mitre.oval:def:126</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A178">oval:org.mitre.oval:def:178</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A49">oval:org.mitre.oval:def:49</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1327" seq="2003-1327" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the option "MAIL_ADMIN" has been enabled (not default), that anonymous users have write permissions on a folder, and that the program has been compiled on a system where very long paths are permitted.</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-09/0348.html">20030922 Wu_ftpd all versions (not) vulnerability.</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007775">1007775</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8668">8668</ref>
      <ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2003&amp;m=slackware-security.365971">SSA:2003-259-03</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13269">wuftp-mailadmin-sockprintf-bo(13269)</ref>
    </refs>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1328" seq="2003-1328" published="2003-02-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0083.html">20030206 showHelp("file:") disables security in IE - Sandblad advisory #11</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11259.php" adv="1">ie-showhelp-zone-bypass(11259)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/400577">VU#400577</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6780">6780</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-004">MS03-004</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A57">oval:org.mitre.oval:def:57</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.0.1" edition="sp3"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1329" seq="2003-1329" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch" patch="1">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/connect-dos.patch</ref>
    </refs>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1330" seq="2003-1330" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/7226">7226</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11745">mailsweeper-onstrip-bypass-filter(11745)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift_limited">
        <vers num="4.3.6_sp1" edition=":smtp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1331" seq="2003-1331" published="2003-12-31" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html">20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.</ref>
      <ref source="CONFIRM" url="http://bugs.mysql.com/bug.php?id=564">http://bugs.mysql.com/bug.php?id=564</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7887">7887</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12337">mysql-mysqlrealconnect-bo(12337)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="4.0.9" prev="1" edition="gamma"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1332" seq="2003-1332" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref>
      <ref source="MISC" url="http://www.securiteam.com/exploits/5TP0M2AAKS.html">http://www.securiteam.com/exploits/5TP0M2AAKS.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12749">samba-reply-nttrans-bo(12749)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.2.7a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1333" seq="2003-1333" published="2003-12-31" modified="2010-06-23" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43">http://groups.google.com/group/intersystems-public-cache/browse_thread/thread/8bdc0e496226edd1/60e9179edb4a4d43</ref>
    </refs>
    <vuln_soft>
      <prod name="cache_database" vendor="intersystems">
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="5"/>
        <vers num="5.0.3"/>
        <vers num="5.0.5"/>
        <vers num="5.0.12"/>
        <vers num="5.0.17"/>
        <vers num="5.0.19"/>
        <vers num="5.0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1334" seq="2003-1334" published="2003-12-31" modified="2010-06-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.bitfolge.de/snif-en.html">http://www.bitfolge.de/snif-en.html</ref>
    </refs>
    <vuln_soft>
      <prod name="simple_and_nice_index_file" vendor="kai_blankenhorn_bitfolge">
        <vers num="1.2.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1335" seq="2003-1335" published="2003-12-31" modified="2010-06-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.bitfolge.de/snif-en.html">http://www.bitfolge.de/snif-en.html</ref>
    </refs>
    <vuln_soft>
      <prod name="simple_and_nice_index_file" vendor="kai_blankenhorn_bitfolge">
        <vers num="1.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1336" seq="2003-1336" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0060.html" patch="1">20031015 mIRC Buffer Overflow in irc protocol handler</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html" patch="1">http://www.securiteam.com/windowsntfocus/6M00B0U8KE.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8819" patch="1">8819</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13405">mirc-ircprotocol-execute-code(13405)</ref>
    </refs>
    <vuln_soft>
      <prod name="mirc" vendor="mirc">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1337" seq="2003-1337" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8062" patch="1">8062</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12466">abyss-http-get-bo(12466)</ref>
    </refs>
    <vuln_soft>
      <prod name="abyss_web_server" vendor="aprelium_technologies">
        <vers num="1.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1338" seq="2003-1338" published="2003-12-31" modified="2010-06-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/93.html

'http://cwe.mitre.org/data/definitions/93.html'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-06/0235.html">20030629 Aprelium Abyss webserver X1 arbitrary code execution and header injection</ref>
    </refs>
    <vuln_soft>
      <prod name="abyss_web_server" vendor="aprelium_technologies">
        <vers num="1.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1339" seq="2003-1339" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=107090390002654&amp;w=2">20031207 eZ Multiple Packages Stack Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2003/Dec/0195.html">20031211 eZ and eZphotoshare fixes</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008412">1008412</ref>
      <ref source="MISC" url="http://www.governmentsecurity.org/archive/t5390.html">http://www.governmentsecurity.org/archive/t5390.html</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/133">133</ref>
    </refs>
    <vuln_soft>
      <prod name="ezmeeting" vendor="ezmeeting">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1340" seq="2003-1340" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3185">3185</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/323425">20030530 Php-Nuke:users and admins password hashes vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/480866/100/0/threaded">20070927 Re: [waraxe-2007-SA#056] - Another Sql Injection in NukeSentinel 2.5.11</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="phpnuke">
        <vers num="5.6"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1341" seq="2003-1341" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html">20030114 Assorted Trend Vulns Rev 2.0</ref>
      <ref source="CONFIRM" url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6616" patch="1">6616</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11059">officescan-cgichkmasterpwd-auth-bypass(11059)</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="3.0" edition=":corporate"/>
        <vers num="3.0" edition=":corporate_for_windows_nt_server"/>
        <vers num="3.1.1" edition=":corporate_for_windows_nt_server"/>
        <vers num="3.5" edition=":corporate"/>
        <vers num="3.5" edition=":corporate_for_windows_nt_server"/>
        <vers num="3.11" edition=":corporate"/>
        <vers num="3.11" edition=":corporate_for_windows_nt_server"/>
        <vers num="3.13" edition=":corporate"/>
        <vers num="3.13" edition=":corporate_for_windows_nt_server"/>
        <vers num="3.54" edition=":corporate"/>
      </prod>
      <prod name="virus_buster" vendor="trend_micro">
        <vers num="3.52" edition=":corporate"/>
        <vers num="3.53" edition=":corporate"/>
        <vers num="3.54" edition=":corporate"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1342" seq="2003-1342" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0020.html">20030114 Assorted Trend Vulns Rev 2.0</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6617">6617</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11060">trend-vcs-activesupport-dos(11060)</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_control_system" vendor="trend_micro">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1343" seq="2003-1343" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
      <ref source="CONFIRM" url="http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352">http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6619" patch="1">6619</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11061">scanmail-smgsmxcfg30-password-bypass(11061)</ref>
    </refs>
    <vuln_soft>
      <prod name="scanmail" vendor="trend_micro">
        <vers num="3.8" prev="1" edition=":microsoft_exchange"/>
        <vers num="6.0" prev="1" edition=":microsoft_exchange"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1344" seq="2003-1344" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6618">6618</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11063">trend-vcs-weak-encryption(11063)</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_control_system" vendor="trend_micro">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1345" seq="2003-1345" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104261317218210&amp;w=2">20030114 Vulnerability in WebCollection Plus (TM)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6574">6574</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11064">webcollection-plus-directory-traversal(11064)</ref>
    </refs>
    <vuln_soft>
      <prod name="webcollection_plus" vendor="follett_software">
        <vers num="5.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1346" seq="2003-1346" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104267037431451&amp;w=2">20030114 D-Link DWL-900AP+ Security Hole</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104311601319909&amp;w=2">20030116 Re: D-Link DWL-900AP+ Security Hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6609">6609</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005926">1005926</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11074">dlink-airplus-restore-default(11074)</ref>
    </refs>
    <vuln_soft>
      <prod name="dwl-900ap+" vendor="d-link">
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1347" seq="2003-1347" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3226">3226</ref>
      <ref source="CONFIRM" url="http://www.geeklog.net/filemgmt/visit.php?lid=101" patch="1">http://www.geeklog.net/filemgmt/visit.php?lid=101</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306770">20030114 Multiple XSS in Geeklog 1.3.7</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6601">6601</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6602">6602</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6603">6603</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6604">6604</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11075">geeklog-php-scripts-xss(11075)</ref>
    </refs>
    <vuln_soft>
      <prod name="geeklog" vendor="geeklog">
        <vers num="1.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1348" seq="2003-1348" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3227">3227</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308312">20030125 ftls.org  Guestbook 1.1 Script Injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6686">6686</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11155">guestbook-multiple-field-xss(11155)</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbook" vendor="ftls">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1349" seq="2003-1349" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0022.html">20030115 Directory traversal vulnerabilities found in NITE ftp-server version 1.83</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6648">6648</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005923">1005923</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11062">niteserver-dotdot-directory-traversal(11062)</ref>
    </refs>
    <vuln_soft>
      <prod name="niteserver_ftpd" vendor="thomas_krebs">
        <vers num="1.83"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1350" seq="2003-1350" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3230">3230</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308300">20030124 List Site Pro v2 user account Hijacking vulnerablity</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6685">6685</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11156">listsitepro-account-hijacking(11156)</ref>
    </refs>
    <vuln_soft>
      <prod name="list_site_pro" vendor="list_site_pro">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1351" seq="2003-1351" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3231">3231</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308162">20030124 Vulnerability in edittag.pl</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6675">6675</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11159">edittag-dotdot-directory-traversal(11159)</ref>
    </refs>
    <vuln_soft>
      <prod name="edittag" vendor="greg_billock">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1352" seq="2003-1352" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0179.html">20030115 Gabber 0.8.7 leaks presence information without user authorization</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6624">6624</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11115">gabber-information-leak(11115)</ref>
    </refs>
    <vuln_soft>
      <prod name="gabber" vendor="gabber">
        <vers num="0.8.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1353" seq="2003-1353" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0119.html">20030116 Outreach Project Tool</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6631">6631</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11096">opt-news-post-xss(11096)</ref>
    </refs>
    <vuln_soft>
      <prod name="outreach_project_tool" vendor="lanifex">
        <vers num="0.946b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1354" seq="2003-1354" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2003/Jan/0178.html">20030122 PivX Multi-Vendor Game Server dDoS Advisory</ref>
      <ref source="MISC" url="http://www.pivx.com/kristovich/adv/mk001/">http://www.pivx.com/kristovich/adv/mk001/</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/5EP0O0K8UO.html">http://www.securiteam.com/securitynews/5EP0O0K8UO.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6636">6636</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11084">battlefield-udp-query-dos(11084)</ref>
    </refs>
    <vuln_soft>
      <prod name="gamespy_3d" vendor="gamespy3d">
        <vers num="2.62"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1355" seq="2003-1355" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0342.html">20030226 [VSA0307] Battlefield 1942 remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6967">6967</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11426">battlefield-remoteconsole-username-dos(11426)</ref>
    </refs>
    <vuln_soft>
      <prod name="battlefield_1942" vendor="electronic_arts">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1356" seq="2003-1356" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q1/0009.html">SSRT3454</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6640" patch="1">6640</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11107">hpux-sort-file-handling(11107)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5758">oval:org.mitre.oval:def:5758</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1357" seq="2003-1357" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3228">3228</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308733">20030128 ProxyView default undocumented password</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6708">6708</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11185">proxyview-administrator-default-password(11185)</ref>
    </refs>
    <vuln_soft>
      <prod name="proxyview" vendor="replicom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1358" seq="2003-1358" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3236">3236</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/4960">HPSBUX0302-240</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324381">20030710 [LSD] HP-UX security vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6837">6837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11312">hp-rsf3000-daemon-access(11312)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1359" seq="2003-1359" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3236">3236</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/4959">HPSBUX0302-241</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324381">20030610 [LSD] HP-UX security vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6836" patch="1">6836</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11313">hp-stmkfont-bo(11313)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5587">oval:org.mitre.oval:def:5587</ref>
    </refs>
    <vuln_soft>
      <prod name="predictive_dialer_system" vendor="avaya">
        <vers num="9.0"/>
        <vers num="11"/>
        <vers num="12"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
        <vers num="11.20"/>
        <vers num="11.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1360" seq="2003-1360" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3236">3236</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/4957">HPSBUX0302-243</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/324381">20030610 [LSD] HP-UX security vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6834">6834</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11314">hp-landiag-lanadmin-bo(11314)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.26"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1361" seq="2003-1361" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0333.html">20030225 VERITAS Software Technical Advisory (fwd)</ref>
      <ref source="CONFIRM" url="http://seer.support.veritas.com/docs/252933.htm" patch="1">http://seer.support.veritas.com/docs/252933.htm</ref>
      <ref source="CONFIRM" url="http://seer.support.veritas.com/docs/254442.htm">http://seer.support.veritas.com/docs/254442.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6928" patch="1">6928</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11418">veritas-bmr-root-access(11418)</ref>
    </refs>
    <vuln_soft>
      <prod name="bare_metal_restore" vendor="veritas">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1362" seq="2003-1362" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q1/0033.html">HPSBUX0302-245</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6878" patch="1">6878</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11366">hp-bastille-info-disclosure(11366)</ref>
    </refs>
    <vuln_soft>
      <prod name="bastille" vendor="hp">
        <vers num="b.02.00.05" edition=":hp-ux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1363" seq="2003-1363" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html">20030212 Abyss WebServer Brute Force Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11310.php">abyss-web-admin-bruteforce(11310)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6842">6842</ref>
    </refs>
    <vuln_soft>
      <prod name="abyss_web_server" vendor="aprelium_technologies">
        <vers num="1.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1364" seq="2003-1364" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:C)">
    <desc>
      <descript source="cve">Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0095.html">20030405 Abyss X1 1.1.2 remote crash</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7287" patch="1">7287</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11718">abyss-http-get-dos(11718)</ref>
    </refs>
    <vuln_soft>
      <prod name="abyss_web_server" vendor="aprelium_technologies">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1365" seq="2003-1365" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0065.html">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</ref>
      <ref source="CONFIRM" url="http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm">http://search.cpan.org/~smylers/CGI-Lite-2.02/Lite.pm</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3237">3237</ref>
      <ref source="MISC" url="http://use.perl.org/~cbrooks/journal/10542">http://use.perl.org/~cbrooks/journal/10542</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311414">20030211 Security bug in CGI::Lite::escape_dangerous_chars() function</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6833">6833</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11308">cgilite-shell-command-execution(11308)</ref>
    </refs>
    <vuln_soft>
      <prod name="cgi_lite" vendor="perl">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1366" seq="2003-1366" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3238">3238</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309962">20030203 ASA-0001: OpenBSD chpass/chfn/chsh file content leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6748">6748</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006035">1006035</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11233">openbsd-chpass-information-disclosure(11233)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1367" seq="2003-1367" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3235">3235</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310113">20030204 Majordomo info leakage, all versions</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6761">6761</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11243">majordomo-whichaccess-email-disclosure(11243)</ref>
    </refs>
    <vuln_soft>
      <prod name="majordomo" vendor="great_circle_associates">
        <vers num="1.94.4"/>
        <vers num="1.94.5"/>
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1368" seq="2003-1368" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html">20030204 Banner Buffer Overflows found in Multible FTP Clients</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6764">6764</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11234">32bit-ftp-banner-bo(11234)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_client" vendor="electrasoft">
        <vers num="9.49.01" edition=":32bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1369" seq="2003-1369" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0054.html">20030204 Banner Buffer Overflows found in Multible FTP Clients</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6762">6762</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11235">bytecatcher-ftp-banner-bo(11235)</ref>
    </refs>
    <vuln_soft>
      <prod name="bytecatcherftp" vendor="save_it_software_pty">
        <vers num="1.04b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1370" seq="2003-1370" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0330.html">20030127 [SCSA-003] Multiple Cross Site Scripting &amp; Script Injection Vulnerabilities in Nuked-Klan</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6697" patch="1">6697</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6699">6699</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6700" patch="1">6700</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11176">nuked-klan-index-xss(11176)</ref>
    </refs>
    <vuln_soft>
      <prod name="nuked-klan" vendor="nuked-klan">
        <vers num="1.2_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1371" seq="2003-1371" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html">20030221 [SCSA-006] XSS &amp; Function Execution Vulnerabilities in Nuked-Klan</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6917">6917</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11424">nukedklan-information-disclosure(11424)</ref>
    </refs>
    <vuln_soft>
      <prod name="nuked-klan" vendor="nuked-klan">
        <vers num="1.3_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1372" seq="2003-1372" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0231.html">20030219 myphpnuke xss</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6892">6892</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11376">phpbb-index-sql-injection(11376)</ref>
    </refs>
    <vuln_soft>
      <prod name="myphpnuke" vendor="myphpnuke">
        <vers num="1.8.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1373" seq="2003-1373" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0245.html">20030220 phpBB Security Bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6889">6889</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11407">phpbb-auth-read-files(11407)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1374" seq="2003-1374" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0156.html">20030213 HPUX disable buffer overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6845">6845</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11316">hp-lp-disable-bo(11316)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1375" seq="2003-1375" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3264">3264</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/5369">HPSBUX0305-258</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310908">20030207 HPUX Wall Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6800" patch="1">6800</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11272">hp-wall-bo(11272)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5439">oval:org.mitre.oval:def:5439</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1376" seq="2003-1376" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3265">3265</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311059">20030208 Yet another plaintext attack to ZIP encryption scheme.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6805">6805</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11296">winzip-pkzip-weak-encryption(11296)</ref>
    </refs>
    <vuln_soft>
      <prod name="winzip" vendor="winzip">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1377" seq="2003-1377" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code via a client with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312924">20030223 sircd proof-of-concept / advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6924">6924</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11409">sircd-reverse-dns-bo(11409)</ref>
    </refs>
    <vuln_soft>
      <prod name="sircd" vendor="sircd">
        <vers num="0.4.0"/>
        <vers num="0.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1378" seq="2003-1378" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="8.8" CVSS_base_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:N)">
    <desc>
      <descript source="cve">Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312910">20030223 O UT LO OK  E  XPRE SS 6 .00 : broken</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312929">20030224 Re: O UT LO OK  E  XPRE SS 6 .00 : broken</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6923">6923</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11411">outlook-codebase-execute-programs(11411)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sr1"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1379" seq="2003-1379" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313080">20030225 clarkconnect(d) information disclosure</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6934" patch="1">6934</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11419">clarkconnect-clarkconnectd-info-disclosure(11419)</ref>
    </refs>
    <vuln_soft>
      <prod name="clarkconnect" vendor="point_clark_networks">
        <vers num="1.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1380" seq="2003-1380" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312032">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6873">6873</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11347">bisonftp-ls-view-files(11347)</ref>
    </refs>
    <vuln_soft>
      <prod name="bisonftp_server_4" vendor="bisonftp">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1381" seq="2003-1381" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3258">3258</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313273">20030226 [VSA0308] Half-Life AMX-Mod remote (root) hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6968">6968</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11427">amx-amxsay-format-string(11427)</ref>
    </refs>
    <vuln_soft>
      <prod name="amx_mod" vendor="amxmod.net">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1382" seq="2003-1382" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ISMail 1.4.3 and earlier allow remote attackers to execute arbitrary code via long domain names in (1) MAIL FROM or (2) RCPT TO fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3254">3254</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313363" patch="1">20030227 ISMAIL (All Versions) Remote Buffer Overrun</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6972">6972</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11432">ismail-smtp-domain-bo(11432)</ref>
    </refs>
    <vuln_soft>
      <prod name="ismail" vendor="instantservers_inc.">
        <vers num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1383" seq="2003-1383" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3257">3257</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313575">20030301 web-erp 0.1.4 database access vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6996">6996</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11443">weberp-logicworks-ini-access(11443)</ref>
    </refs>
    <vuln_soft>
      <prod name="web_erp" vendor="logicworks">
        <vers num="0.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1384" seq="2003-1384" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0102.html">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2003/03/msg00024.html">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004015.html">20030302 [SCSA-008] Cross Site Scripting &amp; Script Injection Vulnerability in PY-Livredor</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6997">6997</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11448">pylivredor-guestbook-xss(11448)</ref>
    </refs>
    <vuln_soft>
      <prod name="py-livredor" vendor="py_software">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1385" seq="2003-1385" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0099.html" adv="1">20030227 Invision Power Board (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6976">6976</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11435">invision-ipchat-file-include(11435)</ref>
    </refs>
    <vuln_soft>
      <prod name="invision_power_board" vendor="invision_power_services">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1386" seq="2003-1386" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html">20030228 axis2400 webcams</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html">20030325 Axis Video and Camera Servers - System log access and file access/overwrite via HTTP/CGI</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6980">6980</ref>
      <ref source="MISC" url="http://www.websec.org/adv/axis2400.txt.html">http://www.websec.org/adv/axis2400.txt.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11440">axis-messages-unauth-access(11440)</ref>
    </refs>
    <vuln_soft>
      <prod name="2400_video_server" vendor="axis">
        <vers num="2.0"/>
        <vers num="2.20"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
        <vers num="2.33"/>
      </prod>
      <prod name="2401_video_server" vendor="axis">
        <vers num="2.20"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
        <vers num="2.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1387" seq="2003-1387" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3253">3253</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311194">20030209 Opera Username Buffer Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315794">20030320 Opara 6.06 Released, Security-Hole Left</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6811" patch="1">6811</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11281">opera-username-url-bo(11281)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="6.0.5" edition=":win32"/>
        <vers num="6.0.6" edition=":win32"/>
        <vers num="7.0_beta1" edition=":win32"/>
        <vers num="7.0_beta2" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1388" seq="2003-1388" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0116.html">20030407 Unchecked Buffer in Opera 7.02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11740">opera-long-url-bo(11740)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera" vendor="opera_software">
        <vers num="7.02_build_2668"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1389" seq="2003-1389" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311176">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6815">6815</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11294">cryptobuddy-truncate-weak-security(11294)</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptobuddy" vendor="research_triangle_software">
        <vers num="1.0"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1390" seq="2003-1390" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311176">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11297">cryptobuddy-plaintext-password-bytes(11297)</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptobuddy" vendor="research_triangle_software">
        <vers num="1.0"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1391" seq="2003-1391" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311176">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6810">6810</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11298">cryptobuddy-password-dictionary(11298)</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptobuddy" vendor="research_triangle_software">
        <vers num="1.0"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1392" seq="2003-1392" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.6" CVSS_base_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)">
    <desc>
      <descript source="cve">CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311176">20030210 RTS CryptoBuddy Multiple Encryption Implementation Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6812">6812</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11317">cryptobuddy-password-information-disclosure(11317)</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptobuddy" vendor="research_triangle_software">
        <vers num="1.0"/>
        <vers num="1.2"/>
      </prod>
      <prod name="all_windows" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1393" seq="2003-1393" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3256">3256</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311159">20030210 Buffer OverFlow in SQLBase 8.1.0 - NII Advisory</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/314379">20030308 NII Advisory - Buffer Overflow in SQLBase (Revised)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6808">6808</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11269">sqlbase-execute-long-bo(11269)</ref>
    </refs>
    <vuln_soft>
      <prod name="sqlbase" vendor="gupta_technologies">
        <vers num="8.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1394" seq="2003-1394" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3259">3259</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313580">20030228 Easy obtaining User+Pass+More on CoffeeCup Password Wizard All Versions</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6995">6995</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11447">coffeecup-password-file-retrieval(11447)</ref>
    </refs>
    <vuln_soft>
      <prod name="coffeecup_password_wizard" vendor="coffeecup_software">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1395" seq="2003-1395" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3252">3252</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309935">20030202 Denial of service against Kazaa Media Desktop v2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6747">6747</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11228">kazaa-automated-ad-bo(11228)</ref>
    </refs>
    <vuln_soft>
      <prod name="kazaa_media_desktop" vendor="kazaa">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1396" seq="2003-1396" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0346.html">20030427 [Opera 7/6] Long File Extension Heap Buffer Overrun Vulnerability in Download.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7450" patch="1">7450</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11894">opera-file-extension-bo(11894)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0.1" edition=":win32"/>
        <vers num="6.0.2" edition=":win32"/>
        <vers num="6.0.3" edition=":win32"/>
        <vers num="6.0.4" edition=":win32"/>
        <vers num="6.0.5" edition=":win32"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="7.0.2" edition=":win32"/>
        <vers num="7.0.3" edition=":win32"/>
        <vers num="7.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1397" seq="2003-1397" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3255">3255</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311214">20030210 Java-Applet crashes Opera 6.05 and 7.01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6814">6814</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11280">opera-plugincontextshowdocument-bo(11280)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="6.0.5" edition=":win32"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="7.0_beta1" edition=":win32"/>
        <vers num="7.0_beta2" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1398" seq="2003-1398" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0131.html">20030211 Field Notice - IOS Accepts ICMP Redirects in Non-default Configuration Settings</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006075">1006075</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6823">6823</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11306">cisco-ios-icmp-redirect(11306)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0"/>
        <vers num="12.0s"/>
        <vers num="12.0st"/>
        <vers num="12.0t"/>
        <vers num="12.1"/>
        <vers num="12.1e"/>
        <vers num="12.1t"/>
        <vers num="12.2"/>
        <vers num="12.2e"/>
        <vers num="12.2f"/>
        <vers num="12.2s"/>
        <vers num="12.2t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1399" seq="2003-1399" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0278.html">20030222 eject 2.0.10 vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6914" patch="1">6914</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11380">linux-eject-information-disclosure(11380)</ref>
    </refs>
    <vuln_soft>
      <prod name="eject" vendor="eject">
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1400" seq="2003-1400" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309959">20030203 PHP-Nuke Avatar Code injection vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310115">20030204 Re: PHP-Nuke Avatar Code injection vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6750">6750</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11229">phpnuke-avatar-code-execution(11229)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.2a"/>
        <vers num="5.3.1"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1401" seq="2003-1401" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0069.html">20030215 php-Board (php)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6862">6862</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11338">phpboard-login-plaintext-passwords(11338)</ref>
    </refs>
    <vuln_soft>
      <prod name="php_board" vendor="php_board">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1402" seq="2003-1402" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0071.html">20030215 Kietu ( PHP )</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6863">6863</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11341">kietu-hit-file-include(11341)</ref>
    </refs>
    <vuln_soft>
      <prod name="kietu" vendor="kietu">
        <vers num="2.0"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1403" seq="2003-1403" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html">20030215 DotBr (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6864">6864</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11353">dotbr-foo-info-disclosure(11353)</ref>
    </refs>
    <vuln_soft>
      <prod name="botbr" vendor="dotbr">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1404" seq="2003-1404" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html">20030215 DotBr (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6865">6865</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11354">dotbr-config-info-disclosure(11354)</ref>
    </refs>
    <vuln_soft>
      <prod name="botbr" vendor="dotbr">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1405" seq="2003-1405" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html">20030215 DotBr (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6866">6866</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6867">6867</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11355">dotbr-exec-execute-commands(11355)</ref>
    </refs>
    <vuln_soft>
      <prod name="botbr" vendor="dotbr">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1406" seq="2003-1406" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0072.html">20030216 D-Forum (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6879">6879</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11342">dform-header-file-include(11342)</ref>
    </refs>
    <vuln_soft>
      <prod name="d_forum" vendor="adalis_infomatique">
        <vers num="1.0"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1407" seq="2003-1407" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3251">3251</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311359">20030211 SECURITY.NNOV: Windows NT 4.0/2000 cmd.exe long path buffer overflow/DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6829">6829</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11329">win-cmd-cd-bo(11329)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1408" seq="2003-1408" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311660">20030212 Lotus Domino DOT Bug Allows for Source Code Viewing</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311806">20030213 Re: Lotus Domino DOT Bug Allows for Source Code Viewing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6841">6841</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11311">lotus-domino-dot-file-download(11311)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_server" vendor="lotus">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1409" seq="2003-1409" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0049.html" patch="1">20030204 TOPo 1.43 and prior - Path Disclosure (in.php, out.php)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6768">6768</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11248">topo-path-disclosure(11248)</ref>
    </refs>
    <vuln_soft>
      <prod name="topo" vendor="ej3">
        <vers num="1.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1410" seq="2003-1410" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311173">20030209 Cedric Email Reader (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6818">6818</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11278">cedric-email-file-include(11278)</ref>
    </refs>
    <vuln_soft>
      <prod name="cedric_email_reader" vendor="isoca">
        <vers num="0.2"/>
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1411" seq="2003-1411" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311173">20030209 Cedric Email Reader (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6820">6820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11278">cedric-email-file-include(11278)</ref>
    </refs>
    <vuln_soft>
      <prod name="cedric_email_reader" vendor="isoca">
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1412" seq="2003-1412" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003932.html">20030223 GOnicus System Administrator php injection</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313282/30/25760/threaded">20030224 GOnicus System Administrator php injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6922">6922</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006162">1006162</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11408">gosa-plugin-file-include(11408)</ref>
    </refs>
    <vuln_soft>
      <prod name="gonicus_system_administration" vendor="gonicus">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1413" seq="2003-1413" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3260">3260</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313517">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6992">6992</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11445">darwin-dotdot-file-existence(11445)</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1414" seq="2003-1414" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3260">3260</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313517">20030228 Re:  QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6990">6990</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11446">darwin-dotdotdot-directory-traversal(11446)</ref>
    </refs>
    <vuln_soft>
      <prod name="darwin_streaming_server" vendor="apple">
        <vers num="4.1.2"/>
      </prod>
      <prod name="quicktime_streaming_server" vendor="apple">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1415" seq="2003-1415" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3261">3261</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312187">20030218 [SecurityOffice] Netcharts XBRL Server v4.0.0 Information Leakage Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6877">6877</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11345">netcharts-chunked-encoding-bo(11345)</ref>
    </refs>
    <vuln_soft>
      <prod name="netcharts_xbrl_server" vendor="visual_mining">
        <vers num="4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1416" seq="2003-1416" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312032">20030217 [immune advisory] Mulitple vulnerabilities found in BisonFTP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6869">6869</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11346">bisonftp-ls-cwd-dos(11346)</ref>
    </refs>
    <vuln_soft>
      <prod name="bisonftp_server_4" vendor="bisonftp">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1417" seq="2003-1417" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104619088801750&amp;w=2">20030225 nCipher Advisory #7: Unexpected copies of imported software keys</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6927">6927</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11422">ncipher-duplicate-keys(11422)</ref>
    </refs>
    <vuln_soft>
      <prod name="support_software" vendor="ncipher">
        <vers num="6.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1418" seq="2003-1418" published="2003-12-31" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata32.html">[3.2] 008: SECURITY FIX: February 25, 2003</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6939">6939</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6943" patch="1">6943</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11438">apache-mime-information-disclosure(11438)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1419" seq="2003-1419" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0338.html">20030225 Re: Netscape 6/7 crashes by a simple stylesheet...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6959">6959</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11444">netscape-javascript-reformatdate-dos(11444)</ref>
    </refs>
    <vuln_soft>
      <prod name="navigator" vendor="netscape">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1420" seq="2003-1420" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313216">20030226 Secunia Research: Opera browser Cross Site Scripting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6962" patch="1">6962</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11423">opera-automatic-redirection-xss(11423)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="6.0" edition=":win32"/>
        <vers num="6.0.1" edition=":linux"/>
        <vers num="6.0.1" edition=":win32"/>
        <vers num="6.0.2" edition=":linux"/>
        <vers num="6.0.2" edition=":win32"/>
        <vers num="6.0.3" edition=":linux"/>
        <vers num="6.0.3" edition=":win32"/>
        <vers num="6.0.4" edition=":win32"/>
        <vers num="6.0.5" edition=":win32"/>
        <vers num="6.10" edition=":linux"/>
        <vers num="7.0" edition=":win32"/>
        <vers num="7.0.1" edition=":win32"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1421" seq="2003-1421" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/6854" patch="1">6854</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11340">suckbot-modmysqllogger-dos(11340)</ref>
    </refs>
    <vuln_soft>
      <prod name="suckbot" vendor="suckbot">
        <vers num="0.006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1422" seq="2003-1422" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://syslinux.zytor.com/history.php">http://syslinux.zytor.com/history.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6876" patch="1">6876</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11351">syslinux-gain-privileges(11351)</ref>
    </refs>
    <vuln_soft>
      <prod name="syslinux" vendor="gentoo">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1423" seq="2003-1423" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006117">1006117</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11358">petitforum-liste-info-disclosure(11358)</ref>
    </refs>
    <vuln_soft>
      <prod name="petitforum" vendor="petitforum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1424" seq="2003-1424" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006117">1006117</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11359">petitforum-message-auth-bypass(11359)</ref>
    </refs>
    <vuln_soft>
      <prod name="petitforum" vendor="petitforum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1425" seq="2003-1425" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6882">6882</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11356">cpanel-guestbook-command-execution(11356)</ref>
    </refs>
    <vuln_soft>
      <prod name="cpanel" vendor="cpanel">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1426" seq="2003-1426" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html">20030218 Cpanel 5 and below remote command execution and local root vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6885">6885</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11357">cpanel-scriptfilename-gain-privileges(11357)</ref>
    </refs>
    <vuln_soft>
      <prod name="cpanel" vendor="cpanel">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1427" seq="2003-1427" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311160">20030209 Bug in Netgear FM114P Wireless Router firmware</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6807">6807</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11279">netgear-fm114p-directory-traversal(11279)</ref>
    </refs>
    <vuln_soft>
      <prod name="fm114p" vendor="netgear">
        <vers num="1.4_beta_release_17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1428" seq="2003-1428" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.8" CVSS_base_score="4.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311161">20030210 Gallery 1.3.3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6809">6809</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11284">gallery-album-insecure-directory(11284)</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery" vendor="bharat_mediratta">
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1429" seq="2003-1429" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0088.html">20030219 [SCSA-005] Proxomitron Naoko Long Path Buffer Overflow/DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11364">proxomitron-parameter-length-bo(11364)</ref>
    </refs>
    <vuln_soft>
      <prod name="proxomitron_naoko" vendor="proxomitron">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1430" seq="2003-1430" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html">20030205 Unreal engine: results of my research</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6775">6775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11299">ut-file-directory-traversal(11299)</ref>
    </refs>
    <vuln_soft>
      <prod name="unreal_engine" vendor="epic_games">
        <vers num="226f"/>
        <vers num="433"/>
        <vers num="436"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1431" seq="2003-1431" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html">20030205 Unreal engine: results of my research</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6774">6774</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11301">ut-url-memory-corruption(11301)</ref>
    </refs>
    <vuln_soft>
      <prod name="unreal_engine" vendor="epic_games">
        <vers num="226f"/>
        <vers num="433"/>
        <vers num="436"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1432" seq="2003-1432" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html">20030205 Unreal engine: results of my research</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0142.html">20030513 UT2003 client passive DoS exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6770">6770</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6772">6772</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11302">ut-packet-dos(11302)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11305">ut-negative-memory-corruption(11305)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12012">ut-negative-udp-dos(12012)</ref>
    </refs>
    <vuln_soft>
      <prod name="unreal_engine" vendor="epic_games">
        <vers num="226f"/>
        <vers num="433"/>
        <vers num="436"/>
      </prod>
      <prod name="unreal_tournament_2003" vendor="epic_games">
        <vers num="2199_linux"/>
        <vers num="2199_win32"/>
        <vers num="demo_version_2206_linux"/>
        <vers num="demo_version_2206_win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1433" seq="2003-1433" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0063.html">20030205 Unreal engine: results of my research</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0142.html">20030211 Re: Epic Games threatens to sue security researchers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6771">6771</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11304">ut-join-request-dos(11304)</ref>
    </refs>
    <vuln_soft>
      <prod name="unreal_engine" vendor="epic_games">
        <vers num="226f"/>
        <vers num="433"/>
        <vers num="436"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1434" seq="2003-1434" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0244.html">20030220 login_ldap security announcement</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6903" patch="1">6903</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11374">loginldap-password-bypass(11374)</ref>
    </refs>
    <vuln_soft>
      <prod name="login_ldap" vendor="pete_werner">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1435" seq="2003-1435" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0246.html">20030220 PHPNuke SQL Injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6887">6887</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11375">phpnuke-search-sql-injection(11375)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.6"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1436" seq="2003-1436" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006031" patch="1">1006031</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6731">6731</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11217">nukebrowser-php-file-include(11217)</ref>
    </refs>
    <vuln_soft>
      <prod name="nukebrowser" vendor="crossnuke">
        <vers num="2.1"/>
        <vers num="2.3"/>
        <vers num="2.5"/>
        <vers num="2.11"/>
        <vers num="2.20"/>
        <vers num="2.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1437" seq="2003-1437" published="2003-12-31" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-25.jsp" adv="1" patch="1">BEA03-25.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6719">6719</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11220">weblogic-keystore-plaintext-passwords(11220)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="7.0" edition=":express"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0.0.1" edition=":express"/>
        <vers num="7.0.0.1" edition="sp1:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1438" seq="2003-1438" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BEA" url="http://dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-26.01.jsp" patch="1">BEA03-26.01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6717">6717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006018">1006018</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11221">weblogic-clustered-race-condition(11221)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1439" seq="2003-1439" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309775">20030201 silc question - insecure memory</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309941/30/26090/threaded">20030201 Re: silc question - insecure memory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6743">6743</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11244">silc-plaintext-account-information(11244)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_internet_live_conferencing" vendor="silc">
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1440" seq="2003-1440" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137128">http://sourceforge.net/project/shownotes.php?release_id=137128</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6739" patch="1">6739</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006038">1006038</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11247">spamprobe-newlines-href-dos(11247)</ref>
    </refs>
    <vuln_soft>
      <prod name="spamprobe" vendor="burton_computer_corporation">
        <vers num="0.8a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1441" seq="2003-1441" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/6799" patch="1">6799</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11285">posadis-dns-packet-dos(11285)</ref>
    </refs>
    <vuln_soft>
      <prod name="posadis" vendor="posadis">
        <vers num="0.50.4"/>
        <vers num="0.50.5"/>
        <vers num="0.50.6"/>
        <vers num="0.50.7"/>
        <vers num="0.50.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1442" seq="2003-1442" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0127.html">20030211 Ericsson HM220dp ADSL modem Insecure Web Administration Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104619331706574&amp;w=2">20030225 RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6824" patch="1">6824</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11290">ericsson-hm220dp-auth-bypass(11290)</ref>
    </refs>
    <vuln_soft>
      <prod name="hm220dp_adsl_modem" vendor="ericsson">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1443" seq="2003-1443" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11292">kav-device-name-bypass(11292)</ref>
    </refs>
    <vuln_soft>
      <prod name="kaspersky_anti-virus" vendor="kaspersky_lab">
        <vers num="4.0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1444" seq="2003-1444" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0130.html">20030211 SECURITY.NNOV: Kaspersky Antivirus DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11291">kav-long-path-dos(11291)</ref>
    </refs>
    <vuln_soft>
      <prod name="kaspersky_anti-virus" vendor="kaspersky_lab">
        <vers num="4.0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1445" seq="2003-1445" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3281">3281</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/311334">20030211 SECURITY.NNOV: Far buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6822">6822</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11293">far-long-path-bo(11293)</ref>
    </refs>
    <vuln_soft>
      <prod name="far_manager" vendor="rarlab">
        <vers num="1.65"/>
        <vers num="1.70_beta_1"/>
        <vers num="1.70_beta_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1446" seq="2003-1446" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0260.html">20030221 Rogue buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6912">6912</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11382">rogue-saveintofile-bo(11382)</ref>
    </refs>
    <vuln_soft>
      <prod name="rogue" vendor="rogue">
        <vers num="5.2-2"/>
        <vers num="985.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1447" seq="2003-1447" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3277">3277</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310118">20030204 Weak password protection in WebSphere 4.0.4 XML configuration export</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310796">20030206 Re: Weak password protection in WebSphere 4.0.4 XML configuration export</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6758">6758</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11245">websphere-xml-weak-encryption(11245)</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="4.0.4" edition=":advanced_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1448" seq="2003-1448" published="2003-12-31" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html">http://www.immunitysec.com/downloads/advantages_of_block_based_analysis.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6766">6766</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11274">win2k-netbios-continuation-dos(11274)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1449" seq="2003-1449" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-02/0088.html">20030206 FW-1 NG FP3 Bug - Data flow problem when transferring large files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6787">6787</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11295">esafe-gateway-filter-bypass(11295)</ref>
    </refs>
    <vuln_soft>
      <prod name="esafe_gateway" vendor="aladdin_knowledge_systems">
        <vers num="3.5.126.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1450" seq="2003-1450" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-February/003850.html">20030217 [argv] BitchX-353 Vulnerability</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3279">3279</ref>
      <ref source="GENTOO" url="http://www.linuxsecurity.com/content/view/104622/104/">200302-11</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/312133">20030217 [argv] BitchX-353 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6880">6880</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11363">bitchx-irc-namreply-dos(11363)</ref>
    </refs>
    <vuln_soft>
      <prod name="bitchx" vendor="bitchx">
        <vers num="1.0_c16"/>
        <vers num="1.0_c19"/>
        <vers num="1.0_c20cvs"/>
        <vers num="75p3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1451" seq="2003-1451" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html">http://securityresponse.symantec.com/avcenter/security/Content/2003.02.28.html</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-02/0233.html">20030219 [SNS Advisory No.61] Symantec Norton AntiVirus 2002 Buffer Overflow Vulnerability</ref>
      <ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/61_e.html">http://www.lac.co.jp/security/english/snsadv_e/61_e.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6886">6886</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11365">nav-email-filename-bo(11365)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="2002"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1452" seq="2003-1452" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0047.html">20030429 [INetCop Security Advisory] Qpopper v4.0.x poppassd local root</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3268">3268</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319811">20030428 Qpopper v4.0.x poppassd local root exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7447">7447</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11877">qpopper-poppassd-root-access(11877)</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5_fc2"/>
        <vers num="4.0_b14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1453" seq="2003-1453" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3269">3269</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319715">20030425 XOOPS MyTextSanitizer CSS 1.3x &amp; 2.x</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7434" patch="1">7434</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11872">xoops-mytextsanitizer-xss(11872)</ref>
    </refs>
    <vuln_soft>
      <prod name="xoops" vendor="xoops">
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1454" seq="2003-1454" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3276">3276</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319747">20030425 Invision Power Board Plaintext Password Disclosure Vuln</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7440">7440</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11871">invision-admin-plaintext-password(11871)</ref>
    </refs>
    <vuln_soft>
      <prod name="invision_board" vendor="invision_power_services">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1455" seq="2003-1455" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=138437" patch="1">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7582" patch="1">7582</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7590" patch="1">7590</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12101">poptop-launchbcrelay-pptpctrlc-bo(12101)</ref>
    </refs>
    <vuln_soft>
      <prod name="pptp_server" vendor="poptop">
        <vers num="1.1.4b1"/>
        <vers num="1.1.4b2"/>
        <vers num="1.1.4b3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1456" seq="2003-1456" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720" patch="1">http://perl.bobbitt.ca/yabbse/index.php?board=2;action=display;threadid=720</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3270">3270</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319763" patch="1">20030426 Album.pl Vulnerability - Remote Command Execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7444">7444</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11878">albumpl-command-execution(11878)</ref>
    </refs>
    <vuln_soft>
      <prod name="album.pl" vendor="mike_bobbitt">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1457" seq="2003-1457" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3282">3282</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319946">20030429 Auerswald COMsuite/ Back Door</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7458">7458</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11923">comsuite-runasositron-backdoor-account(11923)</ref>
    </refs>
    <vuln_soft>
      <prod name="comsuite_cti_controlcenter" vendor="auerswald">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1458" seq="2003-1458" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3278">3278</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321000">20030509 ttcms and ttforum exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7543">7543</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12273">ttcms-profile-sql-injection(12273)</ref>
    </refs>
    <vuln_soft>
      <prod name="ttcms" vendor="ttcms">
        <vers num="2.2"/>
      </prod>
      <prod name="ttforum" vendor="ttcms">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1459" seq="2003-1459" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3278">3278</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321000">20030509 ttcms and ttforum exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7542">7542</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12271">ttcms-ttforum-file-include(12271)</ref>
    </refs>
    <vuln_soft>
      <prod name="ttcms" vendor="ttcms">
        <vers num="2.2"/>
      </prod>
      <prod name="ttforum" vendor="ttcms">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1460" seq="2003-1460" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.boomerangsworld.de/worker/wchanges.php3?lang=en">http://www.boomerangsworld.de/worker/wchanges.php3?lang=en</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7460" patch="1">7460</ref>
    </refs>
    <vuln_soft>
      <prod name="worker_filemanager" vendor="ralf_hoffmann">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1461" seq="2003-1461" published="2003-12-31" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument.  NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3283">3283</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320323">20030502 HP-UX 11.0 /usr/lbin/rwrite</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320371">20030503 rwrite buffer overflow in hp-ux</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7489" patch="1">7489</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11919">hp-rwrite-bo(11919)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4897">oval:org.mitre.oval:def:4897</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1462" seq="2003-1462" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-05/0058.html">20030504 Mod_Survey SYSBASE vulnerability</ref>
      <ref source="CONFIRM" url="http://gathering.itm.mh.se/modsurvey/SA20030504.txt">http://gathering.itm.mh.se/modsurvey/SA20030504.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7498" patch="1">7498</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11861">modsurvey-nonexistent-survey-dos(11861)</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_survey" vendor="mod_survey">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.14d"/>
        <vers num="3.0.14e"/>
        <vers num="3.0.15pre1"/>
        <vers num="3.0.15pre2"/>
        <vers num="3.0.15pre3"/>
        <vers num="3.0.15pre4"/>
        <vers num="3.0.15pre5"/>
        <vers num="3.0.15pre6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1463" seq="2003-1463" published="2003-12-31" modified="2017-07-28" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3286">3286</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319735">20030425 Path disclosure and file access on WebAdmin</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7438">7438</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7439">7439</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11874">webadmin-webadmindll-path-disclosure(11874)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11875">webadmin-webadmindll-view-files(11875)</ref>
    </refs>
    <vuln_soft>
      <prod name="webadmin" vendor="alt-n">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1464" seq="2003-1464" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3287">3287</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320555">20030506 Siemens Mobile Phone - Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7507">7507</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11950">siemens-sms-image-bo(11950)</ref>
    </refs>
    <vuln_soft>
      <prod name="m45" vendor="siemens">
        <vers num=""/>
      </prod>
      <prod name="s45" vendor="siemens">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1465" seq="2003-1465" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3288">3288</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321310">20030513 Phorum Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7569" patch="1">7569</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12482">phorum-download-directory-traversal(12482)</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1466" seq="2003-1466" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3288">3288</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321310">20030513 Phorum Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7581" patch="1">7581</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7583">7583</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1467" seq="2003-1467" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3288">3288</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321310">20030513 Phorum Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7572" patch="1">7572</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7573" patch="1">7573</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7576">7576</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7577">7577</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7584" patch="1">7584</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12487">phorum-multiple-xss(12487)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12502">phorum-register-html-injection(12502)</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1468" seq="2003-1468" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321313">20030512 Re: Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7589">7589</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12436">phpnuke-weblinks-path-disclosure(12436)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1469" seq="2003-1469" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3307">3307</ref>
      <ref source="MISC" url="http://www.nii.co.in/vuln/pdmac.html">http://www.nii.co.in/vuln/pdmac.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319867">20030426 NII Advisory - Path Disclosure in Cold Fusion MX Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7443">7443</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11879">coldfusion-mx-path-disclosure(11879)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="macromedia">
        <vers num="" edition=":developer"/>
        <vers num="6.0"/>
      </prod>
      <prod name="coldfusion_professional" vendor="macromedia">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1470" seq="2003-1470" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3296">3296</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319879">20030427 MDaemon SMTP/POP/IMAP server  =>v.6.7.5: IMAP buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7446">7446</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11896">mdaemon-imap-create-bo(11896)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="6.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1471" seq="2003-1471" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/04/msg00364.html">20030428 MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-04/0359.html">20030428 RE: MDaemon SMTP/POP/IMAP server: =>6.0.7: POP remote DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11882">mdaemon-pop3-negative-dos(11882)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="6.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1472" seq="2003-1472" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3297">3297</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319818">20030428 Buffer overflow in 3D-ftp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7451">7451</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11883">3dftp-ftp-banner-bo(11883)</ref>
    </refs>
    <vuln_soft>
      <prod name="3d-ftp" vendor="3d-ftp">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1473" seq="2003-1473" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html">20030509 ltris-and-slashem-tty possible trouble</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321001">20030508 ltris-and-slashem-tty possible trouble</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7537">7537</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11978">ltris-bo(11978)</ref>
    </refs>
    <vuln_soft>
      <prod name="ltris" vendor="lgames">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1474" seq="2003-1474" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-05/0122.html">20030509 ltris-and-slashem-tty possible trouble</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11979.php">slashem-tty-insecure-permissions(11979)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321001">20030508 ltris-and-slashem-tty possible trouble</ref>
    </refs>
    <vuln_soft>
      <prod name="slashem-tty" vendor="freebsd">
        <vers num="0.0.6e.4f.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1475" seq="2003-1475" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for authentication, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3289">3289</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320980">20030509 Netbus 1.x exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7538">7538</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11982">netbus-password-authentication-bypass(11982)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbus" vendor="netbus">
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1476" seq="2003-1476" published="2003-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues">http://www.cerberusftp.com/cerberus-releasenotes.htm#KnownIssues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7556">7556</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server" vendor="cerberus">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1477" seq="2003-1477" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/7562">7562</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12052">mailsweeper-powerpoint-file-dos(12052)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper_for_smtp" vendor="clearswift">
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1478" seq="2003-1478" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320266">20030502 Re: April appeared to be a month of IE bugs. Here</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7486">7486</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11971">kde-konqueror-dos(11971)</ref>
    </refs>
    <vuln_soft>
      <prod name="konqueror" vendor="kde">
        <vers num="3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1479" seq="2003-1479" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3304">3304</ref>
      <ref source="MISC" url="http://www.frame4.com/content/advisories/FSA-2003-002.txt">http://www.frame4.com/content/advisories/FSA-2003-002.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320345">20030502 Code Injection Vulnerabilities in WebcamXP Chat Feature</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7490">7490</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11952">webcamxp-multiple-xss(11952)</ref>
    </refs>
    <vuln_soft>
      <prod name="webcam_xp" vendor="darkwet">
        <vers num="1.02.432"/>
        <vers num="1.02.535"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1480" seq="2003-1480" published="2003-12-31" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/tools/5WP031FA0U.html">http://www.securiteam.com/tools/5WP031FA0U.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7500">7500</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="mysql">
        <vers num="4.1.0" edition="alpha"/>
        <vers num="4.1.0.0"/>
      </prod>
      <prod name="mysql" vendor="oracle">
        <vers num="3.20"/>
        <vers num="3.20.32a"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="3.22.26"/>
        <vers num="3.22.27"/>
        <vers num="3.22.28"/>
        <vers num="3.22.29"/>
        <vers num="3.22.30"/>
        <vers num="3.22.32"/>
        <vers num="3.23.2"/>
        <vers num="3.23.3"/>
        <vers num="3.23.4"/>
        <vers num="3.23.5"/>
        <vers num="3.23.8"/>
        <vers num="3.23.9"/>
        <vers num="3.23.10"/>
        <vers num="3.23.22"/>
        <vers num="3.23.23"/>
        <vers num="3.23.24"/>
        <vers num="3.23.25"/>
        <vers num="3.23.26"/>
        <vers num="3.23.27"/>
        <vers num="3.23.28" edition="gamma"/>
        <vers num="3.23.29"/>
        <vers num="3.23.30"/>
        <vers num="3.23.31"/>
        <vers num="3.23.32"/>
        <vers num="3.23.33"/>
        <vers num="3.23.34"/>
        <vers num="3.23.35"/>
        <vers num="3.23.36"/>
        <vers num="3.23.37"/>
        <vers num="3.23.38"/>
        <vers num="3.23.39"/>
        <vers num="3.23.40"/>
        <vers num="3.23.41"/>
        <vers num="3.23.42"/>
        <vers num="3.23.43"/>
        <vers num="3.23.44"/>
        <vers num="3.23.45"/>
        <vers num="3.23.46"/>
        <vers num="3.23.47"/>
        <vers num="3.23.48"/>
        <vers num="3.23.49"/>
        <vers num="3.23.50"/>
        <vers num="3.23.51"/>
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.53a"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
        <vers num="3.23.55"/>
        <vers num="3.23.56"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.7" edition="gamma"/>
        <vers num="4.0.8" edition="gamma"/>
        <vers num="4.0.9" edition="gamma"/>
        <vers num="4.0.11" edition="gamma"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1481" seq="2003-1481" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3290">3290</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320438">20030504 CommuniGatePro 4.0.6 [EXPLOIT]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7501" patch="1">7501</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11932">communigate-pro-session-hijacking(11932)</ref>
    </refs>
    <vuln_soft>
      <prod name="communigate_pro" vendor="stalker">
        <vers num="3.1"/>
        <vers num="3.2.4"/>
        <vers num="3.2_b5"/>
        <vers num="3.2_b7"/>
        <vers num="3.3.2"/>
        <vers num="3.3_b1"/>
        <vers num="3.3_b2"/>
        <vers num="3.4_b3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.6"/>
        <vers num="4.0_b2"/>
        <vers num="4.0_b3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1482" seq="2003-1482" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006691">1006691</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7496">7496</ref>
    </refs>
    <vuln_soft>
      <prod name="mn-500_wireless_base_station" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1483" seq="2003-1483" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c">http://downloads.securityfocus.com/vulnerabilities/exploits/flashfxp_decrypt.c</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006730">1006730</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7499">7499</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12298">flashfxp-weak-password-encryption(12298)</ref>
    </refs>
    <vuln_soft>
      <prod name="flashfxp" vendor="flashfxp">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1484" seq="2003-1484" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3292">3292</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320544">20030505 Crash in Internet Explorer 6.0 Sp1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7502">7502</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11946">ie-anchorclick-dos(11946)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1485" seq="2003-1485" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/7568" patch="1">7568</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.6_sp1"/>
        <vers num="4.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1486" seq="2003-1486" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3288">3288</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321310">20030513 Phorum Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7571" patch="1">7571</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12499">phorum-multiple-path-disclosure(12499)</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1487" seq="2003-1487" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3288">3288</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321310">20030513 Phorum Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7574" patch="1">7574</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7578" patch="1">7578</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7579" patch="1">7579</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12500">phorum-command-execution(12500)</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1488" seq="2003-1488" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://marc.info/?l=vulnwatch&amp;m=105128431109082&amp;w=2">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7427">7427</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11886">truegalerie-verifadmin-admin-access(11886)</ref>
    </refs>
    <vuln_soft>
      <prod name="truegalerie" vendor="truelogik">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1489" seq="2003-1489" published="2003-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://marc.info/?l=vulnwatch&amp;m=105128431109082&amp;w=2">20030425 True Galerie 1.0 : Admin Access &amp; File Copy</ref>
    </refs>
    <vuln_soft>
      <prod name="truegalerie" vendor="truegalerie">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1490" seq="2003-1490" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3291">3291</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319712">20030424 SonicWall Pro DoS?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7435">7435</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11876">sonicwallpro-http-post-dos(11876)</ref>
    </refs>
    <vuln_soft>
      <prod name="pro100" vendor="sonicwall">
        <vers num="6.4.0.1"/>
      </prod>
      <prod name="pro200" vendor="sonicwall">
        <vers num="6.4.0.1"/>
      </prod>
      <prod name="pro300" vendor="sonicwall">
        <vers num="6.4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1491" seq="2003-1491" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/0352.html">20030422 UDP bypassing in Kerio Firewall 2.1.4</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/5FP0N1P9PI.html">http://www.securiteam.com/securitynews/5FP0N1P9PI.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7436">7436</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11880">kerio-pf-firewall-bypass(11880)</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_firewall" vendor="kerio">
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1492" seq="2003-1492" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319919">20030429 "netscape navigator" is cracked.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7456">7456</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11924">netscape-domain-obtain-info(11924)</ref>
    </refs>
    <vuln_soft>
      <prod name="firefox" vendor="mozilla">
        <vers num=""/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="7.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1493" seq="2003-1493" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (memory exhaustion) via crafted TCP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html">HPSBUX0310-291</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8859" patch="1">8859</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13467">openview-nnm-packet-dos(13467)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="5.0.1"/>
        <vers num="6.0.1"/>
        <vers num="6.1" edition=":hp_ux_10.x"/>
        <vers num="6.1" edition=":hp_ux_11.x"/>
        <vers num="6.1" edition=":solaris"/>
        <vers num="6.2" edition=":hp_ux_10.x"/>
        <vers num="6.2" edition=":hp_ux_11.x"/>
        <vers num="6.2" edition=":nt_4.x_windows_2000"/>
        <vers num="6.2" edition=":solaris"/>
        <vers num="6.4" edition=":hp_ux_11.x"/>
        <vers num="6.4" edition=":nt_4.x_windows_2000"/>
        <vers num="6.4" edition=":solaris"/>
        <vers num="6.10"/>
        <vers num="6.31"/>
        <vers num="6.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1494" seq="2003-1494" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q4/0019.html">HPSBUX0310-291</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8859" patch="1">8859</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13467">openview-nnm-packet-dos(13467)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="6.2"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1495" seq="2003-1495" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8878" patch="1">8878</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13496">hp-management-gain-privileges(13496)</ref>
    </refs>
    <vuln_soft>
      <prod name="insight_management_suite" vendor="hp">
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="insight_manager" vendor="hp">
        <vers num="1.0"/>
        <vers num="1.6"/>
      </prod>
      <prod name="remote_diagnostics_enabling_agent" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1496" seq="2003-1496" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="COMPAQ" url="http://www.securityfocus.com/advisories/5973">SSRT3589</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8813">8813</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13418">tru64-dtmailpr-gain-privileges(13418)</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="hp">
        <vers num="4.0f"/>
        <vers num="4.0f_pk6_bl17"/>
        <vers num="4.0f_pk7_bl18"/>
        <vers num="4.0f_pk8_bl22"/>
        <vers num="4.0g"/>
        <vers num="4.0g_pk3_bl17"/>
        <vers num="4.0g_pk4_bl22"/>
        <vers num="5.1"/>
        <vers num="5.1_pk3_bl17"/>
        <vers num="5.1_pk4_bl18"/>
        <vers num="5.1_pk5_bl19"/>
        <vers num="5.1_pk6_bl20"/>
        <vers num="5.1a"/>
        <vers num="5.1a_pk1_bl1"/>
        <vers num="5.1a_pk2_bl2"/>
        <vers num="5.1a_pk3_bl3"/>
        <vers num="5.1a_pk4_bl21"/>
        <vers num="5.1a_pk5_bl23"/>
        <vers num="5.1b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1497" seq="2003-1497" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3298">3298</ref>
      <ref source="CONFIRM" url="http://www.linksys.com/download/vertxt/befsx41_1453.txt">http://www.linksys.com/download/vertxt/befsx41_1453.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341309">20031015 LinkSys EtherFast Router Denial of Service Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8834">8834</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13436">linksys-etherfast-logpagenum-dos(13436)</ref>
    </refs>
    <vuln_soft>
      <prod name="befsx41" vendor="linksys">
        <vers num="1.43.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1498" seq="2003-1498" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0173.html" patch="1">20031014 Cross-Site Scripting Vulnerability in Wrensoft Zoom Search Engine</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8823" patch="1">8823</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13431">zoom-search-xss(13431)</ref>
    </refs>
    <vuln_soft>
      <prod name="zoom_search_engine" vendor="wrensoft">
        <vers num="2.0_build_1018" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1499" seq="2003-1499" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-10/0200.html">20031019 ByteHoard Directory Traversal Vulnerability</ref>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012430.html">20031019 ByteHoard Directory Traversal Vulnerability</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6L00L008KE.html">http://www.securiteam.com/unixfocus/6L00L008KE.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8850" patch="1">8850</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13456">bytehoard-dotdot-directory-traversal(13456)</ref>
    </refs>
    <vuln_soft>
      <prod name="bytehoard" vendor="bytehoard">
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1500" seq="2003-1500" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864">http://cpcommerce.org/forums/index.php?board=2;action=display;threadid=864</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3301">3301</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6H00E2K8KG.html">http://www.securiteam.com/unixfocus/6H00E2K8KG.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341757">20031019 ZH2003-31SA (security advisory): file inclusion vulnerability in cpCommerce</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8851">8851</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13457">cpCommerce-functionsphp-file-include(13457)</ref>
    </refs>
    <vuln_soft>
      <prod name="cpcommerce" vendor="cpcommerce">
        <vers num="0.5f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1501" seq="2003-1501" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341870">20031020 Gast Arbeiter Privilege Escalation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8858">8858</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13469">gast-arbeiter-file-upload(13469)</ref>
    </refs>
    <vuln_soft>
      <prod name="gast_arbeiter" vendor="gast_arbeiter">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1502" seq="2003-1502" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012043.html">20031015 Mod-Throttle [was: client attacks server - XSS]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8822">8822</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_throttle" vendor="snert.com">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1503" seq="2003-1503" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0059.html">20031015 Buffer Overflow in AOL Instant Messager</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8825" patch="1">8825</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13443">aim-getfile-screenname-bo(13443)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="5.2.3292"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1504" seq="2003-1504" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3302">3302</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341760">20031018 Get admin level on Goldlink script v3.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8847">8847</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13465">goldlink-variables-gain-access(13465)</ref>
    </refs>
    <vuln_soft>
      <prod name="goldlink" vendor="goldscripts">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1505" seq="2003-1505" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3295">3295</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342010">20031022 IE6 CSS-Crash</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8874">8874</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13809">ie-scrollbarbasecolor-dos(13809)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1506" seq="2003-1506" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3299">3299</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342160">20031022 CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342551">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342577">20031027 Re: CensorNet: Cross Site Scripting Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8876">8876</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13507">censornet-cgi-xss(13507)</ref>
    </refs>
    <vuln_soft>
      <prod name="dansguardian" vendor="daniel_barron">
        <vers num="3.0"/>
        <vers num="3.1_r5"/>
        <vers num="3.1_r6"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1507" seq="2003-1507" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007924">1007924</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341329">20031015 Few issues previously unpublished in English</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8837">8837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13446">wgsd-default-admin-account(13446)</ref>
    </refs>
    <vuln_soft>
      <prod name="wgsd-1020" vendor="planet_technology_corp">
        <vers num=""/>
      </prod>
      <prod name="wsw-2401" vendor="planet_technology_corp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1508" seq="2003-1508" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3303">3303</ref>
      <ref source="CONFIRM" url="http://www.irchelp.org/irchelp/mirc/exploit.html">http://www.irchelp.org/irchelp/mirc/exploit.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/342179">20031023 (Fw) : mIRC 6.12 (latest) DCC Exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8880">8880</ref>
    </refs>
    <vuln_soft>
      <prod name="mirc" vendor="mirc">
        <vers num="6.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1509" seq="2003-1509" published="2003-12-31" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://service.real.com/help/faq/security/securityupdate_october2003.html">http://service.real.com/help/faq/security/securityupdate_october2003.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8839" patch="1">8839</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13445">realoneplayer-temporary-script-execution(13445)</ref>
    </refs>
    <vuln_soft>
      <prod name="realone_enterprise_desktop" vendor="realnetworks">
        <vers num="6.0.11.774"/>
      </prod>
      <prod name="realone_player" vendor="realnetworks">
        <vers num="2.0"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1510" seq="2003-1510" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html">http://www.securiteam.com/windowsntfocus/6S0052K8LQ.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8810">8810</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13402">tinyweb-httpget-dos(13402)</ref>
    </refs>
    <vuln_soft>
      <prod name="tinyweb" vendor="rit_research_labs">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1511" seq="2003-1511" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3306">3306</ref>
      <ref source="CONFIRM" url="http://www.geocities.com/gzhangx/websrv/docs/security.html">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341452">20031016 CSS Vulnerability in Bajie HTTP JServer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8841" patch="1">8841</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="0.95" edition="d"/>
        <vers num="0.95" edition="zxc"/>
        <vers num="0.95" edition="zxe"/>
        <vers num="0.95" edition="zxe1"/>
        <vers num="0.95" edition="zxv4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1512" seq="2003-1512" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8818" patch="1">8818</ref>
    </refs>
    <vuln_soft>
      <prod name="mirc" vendor="khaled_mardam-bey">
        <vers num="6.1"/>
        <vers num="6.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1513" seq="2003-1513" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012361.html">20031019 Caucho Resin 2.x - Cross Site Scripting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8852">8852</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13460">resin-name-comment-xss(13460)</ref>
    </refs>
    <vuln_soft>
      <prod name="resin" vendor="caucho_technology">
        <vers num="2.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1514" seq="2003-1514" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">eMule 0.29c allows remote attackers to cause a denial of service (crash) via a long password, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3294">3294</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341754">20031019 eMule 2.2 [0.29c] - Web Control Panel - DOS(Denial Of Service)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8854">8854</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13464">emule-long-password-dos(13464)</ref>
    </refs>
    <vuln_soft>
      <prod name="emule" vendor="emule">
        <vers num="0.29c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1515" seq="2003-1515" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to cause a denial of service by restoring the factory defaults.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3300">3300</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341752">20031012 Origo ASR-8100 ADSL router remote factory reset</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8855">8855</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13463">origo-default-settings-restore(13463)</ref>
    </refs>
    <vuln_soft>
      <prod name="asr-8100" vendor="origo">
        <vers num="adsl_router_3.21"/>
      </prod>
      <prod name="asr-8400" vendor="origo">
        <vers num="adsl_router"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1516" seq="2003-1516" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341815">20031020 Cross Site Java applets</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8857">8857</ref>
    </refs>
    <vuln_soft>
      <prod name="java_plug-in" vendor="sun">
        <vers num="1.4.2_01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1517" seq="2003-1517" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/6T00T008KG.html">http://www.securiteam.com/securitynews/6T00T008KG.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8860">8860</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13461">dansie-cartpl-path-disclosure(13461)</ref>
    </refs>
    <vuln_soft>
      <prod name="shopping_cart" vendor="dansie">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1518" seq="2003-1518" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.adiscon.com/Common/en/advisory/2003-09-15.asp">http://www.adiscon.com/Common/en/advisory/2003-09-15.asp</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6L00F158KE.html">http://www.securiteam.com/windowsntfocus/6L00F158KE.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8821" patch="1">8821</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13428">winsyslog-long-syslog-dos(13428)</ref>
    </refs>
    <vuln_soft>
      <prod name="winsyslog" vendor="adiscon">
        <vers num="4.21_sp1"/>
        <vers num="5.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1519" seq="2003-1519" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1007955">1007955</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8862">8862</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13452">vívísimo-clustering-engine-xss(13452)</ref>
    </refs>
    <vuln_soft>
      <prod name="clustering_engine" vendor="vivisimo">
        <vers num="0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1520" seq="2003-1520" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3293" patch="1">3293</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341908" patch="1">20031021 SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8863" patch="1">8863</ref>
    </refs>
    <vuln_soft>
      <prod name="myclassifieds" vendor="fuzzymonkey">
        <vers num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1521" seq="2003-1521" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341943">20031021 IE6 &amp; Java 1.4.2_02 applet: Hardware stress on floppy drive</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8867">8867</ref>
    </refs>
    <vuln_soft>
      <prod name="java_plug-in" vendor="sun">
        <vers num="1.4"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2_01"/>
        <vers num="1.4.2_02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1522" seq="2003-1522" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.pscs.co.uk/products/vpop3/whatsnew.html">http://www.pscs.co.uk/products/vpop3/whatsnew.html</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6S00S008KW.html">http://www.securiteam.com/windowsntfocus/6S00S008KW.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8869">8869</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13459">vpop3-login-xss(13459)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpop3_web_mail_server" vendor="pscs">
        <vers num="2.0e"/>
        <vers num="2.0f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1523" seq="2003-1523" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8829" patch="1">8829</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13416">dbmail-multiple-sql-injection(13416)</ref>
    </refs>
    <vuln_soft>
      <prod name="dbmail" vendor="dbmail">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1524" seq="2003-1524" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:N)">
    <desc>
      <descript source="cve">PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html">http://www.securiteam.com/windowsntfocus/6M00L0K8KI.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8870">8870</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13490">pgpdisk-obtain-information(13490)</ref>
    </refs>
    <vuln_soft>
      <prod name="pgpdisk" vendor="pgpi">
        <vers num="6.0.2i"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1525" seq="2003-1525" published="2003-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8872">8872</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/13498">myphotogallery-unknown-vulnerabilities(13498)</ref>
    </refs>
    <vuln_soft>
      <prod name="my_photo_gallery" vendor="my_photo_gallery">
        <vers num="3.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1526" seq="2003-1526" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/341743">20031018 PHP-Nuke Path Disclosure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/8848">8848</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1527" seq="2003-1527" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/294411">20021008 Multiple Vendor PC firewall remote denial of services Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10314.php">firewall-autoblock-spoofing-dos(10314)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5917">5917</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_security_systems_blackice_defender" vendor="ibm">
        <vers num="2.9cap"/>
      </prod>
      <prod name="blackice_server_protection" vendor="iss">
        <vers num="3.5.cdf"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1528" seq="2003-1528" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3353">3353</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/350237/30/21640/threaded">20040119 Networker 6.0 - possible symlink attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9446">9446</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008801">1008801</ref>
    </refs>
    <vuln_soft>
      <prod name="siemens_networker" vendor="fujitsu">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1529" seq="2003-1529" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0357.html">20030325 IRM 005: JWalk Application Server Version 3.2c9 Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7160">7160</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006378">1006378</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11623">jwalk-dotdot-directory-traversal(11623)</ref>
    </refs>
    <vuln_soft>
      <prod name="j_walk_application_server" vendor="seagull_software_systems">
        <vers num="3.2c9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1530" seq="2003-1530" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0125.html">20030116 phpBB SQL Injection vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307212/30/26300/threaded">20030117 phpBB SQL Injection vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6634" patch="1">6634</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb">
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1531" seq="2003-1531" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104878375423320&amp;w=2">20030327 [SCSA-013] Cross Site Scripting vulnerability in testcgi.exe</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7214">7214</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006391">1006391</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11638">ceilidh-textcgi-xss(11638)</ref>
    </refs>
    <vuln_soft>
      <prod name="ceilidh" vendor="lilikoi">
        <vers num="2.70" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1532" seq="2003-1532" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3348">3348</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/309921/30/26090/threaded">20030203 phpMyShop (php)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6746">6746</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006030">1006030</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyshop" vendor="julien_desaunay">
        <vers num="1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1533" seq="2003-1533" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3349">3349</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307224/30/26300/threaded">20030113 phpPass (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6594">6594</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005948">1005948</ref>
    </refs>
    <vuln_soft>
      <prod name="phppass" vendor="phppass">
        <vers num="2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1534" seq="2003-1534" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3347">3347</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316745/30/25280/threaded">20030329 Justice Guestbook 1.3 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7233">7233</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006412">1006412</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbook" vendor="justice_media">
        <vers num="1.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1535" seq="2003-1535" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3347">3347</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316745/30/25280/threaded">20030329 Justice Guestbook 1.3 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7234">7234</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006412">1006412</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbook" vendor="justice_media">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1536" seq="2003-1536" published="2003-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html">20030318 Some XSS vulns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7141">7141</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7144">7144</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11602">dcpportal-search-calendar-xss(11602)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcp-portal" vendor="dcp-portal">
        <vers num="5.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1537" seq="2003-1537" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0117.html">20030309 Postnuke v 0.723 SQL injection and directory traversing</ref>
    </refs>
    <vuln_soft>
      <prod name="postnuke" vendor="postnuke_software_foundation">
        <vers num="0.723" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1538" seq="2003-1538" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_005_susehelp.html">SUSE-SA:2003:005</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005954" patch="1">1005954</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux_openexchange_server" vendor="suse">
        <vers num="4.0"/>
      </prod>
      <prod name="office_server" vendor="suse">
        <vers num=""/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="8" edition=":enterprise_server"/>
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1539" seq="2003-1539" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=144274">http://sourceforge.net/project/shownotes.php?release_id=144274</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=695597&amp;group_id=60333&amp;atid=493842</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7035" patch="1">7035</ref>
    </refs>
    <vuln_soft>
      <prod name="simple_file_manager" vendor="onedotoh">
        <vers num="0.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1540" seq="2003-1540" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3645">3645</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006352">1006352</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315583/30/25430/threaded">20030319 WF-Chat</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7147">7147</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11571">wf-chat-plaintext-passwords(11571)</ref>
    </refs>
    <vuln_soft>
      <prod name="wfchat" vendor="wfchat">
        <vers num="1.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1541" seq="2003-1541" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3653">3653</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315895/30/25400/threaded">20030321 Guestbook tr3.a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7167">7167</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006360">1006360</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11609">guestbooktr3a-plaintext-password-disclosure(11609)</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbook" vendor="planetmoon">
        <vers num="tr3.a.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1542" seq="2003-1542" published="2003-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://platon.sk/projects/release_view_page.php?release_id=2" patch="1">http://platon.sk/projects/release_view_page.php?release_id=2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6933">6933</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebfilemanager" vendor="ondrej_jombik">
        <vers num="0.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1543" seq="2003-1543" published="2003-12-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006428">1006428</ref>
      <ref source="MISC" url="http://www.geocities.com/gzhangx/websrv/docs/security.html">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
      <ref source="MISC" url="http://www.lucaercoli.it/advs/bajie.txt">http://www.lucaercoli.it/advs/bajie.txt</ref>
      <ref source="MISC" url="http://www.securiteam.com/securitynews/5LP10009FC.html">http://www.securiteam.com/securitynews/5LP10009FC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7344">7344</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11687">bajie-error-message-xss(11687)</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="0.95" edition="zxc"/>
        <vers num="0.95" edition="zxe"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1544" seq="2003-1544" published="2003-12-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3654">3654</ref>
      <ref source="MSKB" url="http://support.microsoft.com/kb/815225/en-us">815225</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308059">20030123 DoS attack on Windows 2000 Terminal Server</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/308164">20030124 RE: DoS attack on Windows 2000 Terminal Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6672">6672</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005986">1005986</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11141">win2k-terminal-msgina-dos(11141)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11816">win2k-terminal-msgina-permissions(11816)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp3:adv_srv"/>
        <vers num="" edition="sp3:srv"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1545" seq="2003-1545" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter.  NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316179/30/25340/threaded">20030325 PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316198/30/25340/threaded">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316209/30/25340/threaded">20030325 Re: PHPNuke viewpage.php and another SQL injections</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316233/30/25340/threaded">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316327/30/25340/threaded">20030326 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316341/30/25310/threaded">20030325 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316585/30/25310/threaded">20030327 Re: PHPNuke viewpage.php allows Remote File retrieving</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7191">7191</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006377">1006377</ref>
    </refs>
    <vuln_soft>
      <prod name="viewpage" vendor="nukestyles">
        <vers num=""/>
      </prod>
      <prod name="nukestyles_viewpage_module" vendor="phpnuke">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1546" seq="2003-1546" published="2003-12-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0219.html">20030314 Guestbook v1.1.3 CSS Vuln</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7104">7104</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006289">1006289</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11540">filebased-guestbook-gbook-xss(11540)</ref>
    </refs>
    <vuln_soft>
      <prod name="guestbook" vendor="filebased">
        <vers num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1547" seq="2003-1547" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3718">3718</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316925/30/25250/threaded">20030331 PHP-Nuke block-Forums.php subject vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/317230/30/25220/threaded">20030401 Re: PHP-Nuke block-Forums.php subject vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7248">7248</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11675">phpnuke-blockforums-subject-xss(11675)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1548" seq="2003-1548" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3717">3717</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315317/30/25460/threaded">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7126">7126</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006308">1006308</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11556">myabracadaweb-index-path-disclosure(11556)</ref>
    </refs>
    <vuln_soft>
      <prod name="myabracadaweb" vendor="myabracadaweb">
        <vers num="1.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1549" seq="2003-1549" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3717">3717</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315317/30/25460/threaded">20030317 [SCSA-010] Path Disclosure &amp; Cross Site Scripting Vulnerability in MyABraCaDaWeb</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7127">7127</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006308">1006308</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11557">myabracadaweb-index-makw-xss(11557)</ref>
    </refs>
    <vuln_soft>
      <prod name="myabracadaweb" vendor="myabracadaweb">
        <vers num="1.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1550" seq="2003-1550" published="2003-12-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104820295115420&amp;w=2">20030320 [SCSA-011] Path Disclosure Vulnerability in XOOPS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104887510828106&amp;w=2">20030328 Re: [SCSA-011] Path Disclosure Vulnerability in XOOPS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7149">7149</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11587">xoops-xoopsoption-path-disclosure(11587)</ref>
    </refs>
    <vuln_soft>
      <prod name="xoops" vendor="xoops">
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1551" seq="2003-1551" published="2003-12-31" modified="2017-08-07" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/6896">6896</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006171">1006171</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11394">groupwise-script-execution(11394)</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="6.0_sp3" prev="1" edition="revision_e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1552" seq="2003-1552" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313787/30/25670/threaded">20030304 uploader.php vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313819/30/25640/threaded">20030304 uploader.php script</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11467">uploader-uploads-file-upload(11467)</ref>
    </refs>
    <vuln_soft>
      <prod name="uploader" vendor="graeme">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1553" seq="2003-1553" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3780">3780</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315504/30/25460/threaded">20030318 SIPS (PHP)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7134">7134</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11572">sips-user-obtain-information(11572)</ref>
    </refs>
    <vuln_soft>
      <prod name="sips" vendor="sips">
        <vers num="0.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1554" seq="2003-1554" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3781">3781</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316747/30/25280/threaded">20030329 ScozBook BETA 1.1 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7235">7235</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006413">1006413</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11658">scozbook-add-xss(11658)</ref>
    </refs>
    <vuln_soft>
      <prod name="scozbook" vendor="scoznet">
        <vers num="1.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1555" seq="2003-1555" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3781">3781</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316747/30/25280/threaded">20030329 ScozBook BETA 1.1 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7236">7236</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006413">1006413</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11659">scozbook-view-path-disclosure(11659)</ref>
    </refs>
    <vuln_soft>
      <prod name="scozbook" vendor="scoznet">
        <vers num="1.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1556" seq="2003-1556" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3796">3796</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316764/30/25250/threaded">20030329 CGI-City's CCGuestBook Script Injection Vulns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7237">7237</ref>
    </refs>
    <vuln_soft>
      <prod name="cc_guestbook" vendor="cgi_city">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1557" seq="2003-1557" published="2003-12-31" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=104342896818777&amp;w=2">20030123 SpamAssassin / spamc+BSMTP remote buffer overflow</ref>
      <ref source="GENTOO" url="http://www.securityfocus.com/archive/1/309912/30/26090/threaded">GLSA-200302-01</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/310212/30/26030/threaded">20030204 Re: GLSA: Mail-SpamAssasin</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6679" patch="1">6679</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11154">spamassassin-spamc-offbyone-bo(11154)</ref>
    </refs>
    <vuln_soft>
      <prod name="spamassassin" vendor="spamassassin">
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1558" seq="2003-1558" published="2003-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in httpd.c of fnord 1.6 allows remote attackers to create a denial of service (crash) and possibly execute arbitrary code via a long CGI request passed to the do_cgi function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fefe.de/fnord/">http://www.fefe.de/fnord/</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/307400/30/26270/threaded">20030117 GLSA: fnord</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6635" patch="1">6635</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11121">fnord-httpdc-cgi-bo(11121)</ref>
    </refs>
    <vuln_soft>
      <prod name="fnord" vendor="fefe">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1559" seq="2003-1559" published="2003-12-31" modified="2009-01-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <impacts>
      <impact source="nvd">The only versions confirmed with this vulnerability are the ones listed in the CPE entry.  Other IE Versions may, and probably are, affected but have not been confirmed yet.</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/3989">3989</ref>
      <ref source="MISC" url="http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html">http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348360">20031224 IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348574">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9295">9295</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="5.22"/>
        <vers num="6" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1560" seq="2003-1560" published="2003-12-31" modified="2009-01-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/4004">4004</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348574">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
    </refs>
    <vuln_soft>
      <prod name="navigator" vendor="netscape">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1561" seq="2003-1561" published="2003-12-31" modified="2009-01-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SREASON" url="http://securityreason.com/securityalert/4004">4004</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348574">20031230 RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page</ref>
    </refs>
    <vuln_soft>
      <prod name="opera" vendor="opera">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1562" seq="2003-1562" published="2003-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320153">20030501 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320302">20030501 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/320440">20030505 Re: OpenSSH/PAM timing attack allows remote users identification</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7482">7482</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.27"/>
        <vers num="1.3"/>
        <vers num="1.5"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.9"/>
        <vers num="2.9.9"/>
        <vers num="2.9.9p2"/>
        <vers num="2.9p1"/>
        <vers num="2.9p2"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1p1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2p1"/>
        <vers num="3.0p1"/>
        <vers num="3.1"/>
        <vers num="3.1p1"/>
        <vers num="3.2"/>
        <vers num="3.2.2"/>
        <vers num="3.2.2p1"/>
        <vers num="3.2.3p1"/>
        <vers num="3.3"/>
        <vers num="3.3p1"/>
        <vers num="3.4"/>
        <vers num="3.4p1"/>
        <vers num="3.5"/>
        <vers num="3.5p1"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.1p1"/>
        <vers num="3.6.1p2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1563" seq="2003-1563" published="2003-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101393-1">101393</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-200810-1">200810</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=3672">ESB-2003.0843</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9137">9137</ref>
    </refs>
    <vuln_soft>
      <prod name="cluster" vendor="sun">
        <vers num="2.2" edition=":sparc"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.1" edition=":sparc"/>
        <vers num="3.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1564" seq="2003-1564" published="2003-12-31" modified="2008-10-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://mail.gnome.org/archives/xml/2008-August/msg00034.html">[xml] 20080820 Security fix for libxml2</ref>
      <ref source="MISC" url="http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2">http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0886.html">RHSA-2008:0886</ref>
      <ref source="MLIST" url="http://www.stylusstudio.com/xmldev/200302/post20020.html">[xml-dev] 20030202 Re: Elliotte Rusty Harold on Web Services</ref>
      <ref source="MISC" url="http://xmlsoft.org/news.html">http://xmlsoft.org/news.html</ref>
    </refs>
    <vuln_soft>
      <prod name="libxml2" vendor="xmlsoft">
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.8.9"/>
        <vers num="1.8.10"/>
        <vers num="1.8.13"/>
        <vers num="1.8.14"/>
        <vers num="1.8.16"/>
        <vers num="2.0.0"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0" edition="beta"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29"/>
        <vers num="2.4.30"/>
        <vers num="2.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1565" seq="2003-1565" published="2003-08-27" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2002-1565.  Reason: This candidate is a duplicate of CVE-2002-1565.  Notes: All CVE users should reference CVE-2002-1565 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2003-1566" seq="2003-1566" published="2009-01-14" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html">20031227 AQ-2003-02: Microsoft IIS Logging Failure</ref>
      <ref source="MISC" url="http://www.aqtronix.com/Advisories/AQ-2003-02.txt">http://www.aqtronix.com/Advisories/AQ-2003-02.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9313">9313</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14077">iis-improper-httptrack-logging(14077)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1567" seq="2003-1567" published="2009-01-14" modified="2009-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html">20031227 AQ-2003-02: Microsoft IIS Logging Failure</ref>
      <ref source="MISC" url="http://www.aqtronix.com/Advisories/AQ-2003-02.txt">http://www.aqtronix.com/Advisories/AQ-2003-02.txt</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/288308">VU#288308</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1568" seq="2003-1568" published="2009-02-06" modified="2009-02-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://data.goahead.com/Software/Webserver/2.1.8/release.htm#null-pointer-crash-in-webssafeurl">http://data.goahead.com/Software/Webserver/2.1.8/release.htm#null-pointer-crash-in-webssafeurl</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead_webserver" vendor="goahead">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
      </prod>
      <prod name="goahead_webserver" vendor="goahead_software">
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1569" seq="2003-1569" published="2009-02-06" modified="2009-02-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-aux-denial-of-service">http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-aux-denial-of-service</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead_webserver" vendor="goahead">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1570" seq="2003-1570" published="2009-03-31" modified="2017-08-16" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1021947">1021947</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/34285">34285</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/0881" adv="1">ADV-2009-0881</ref>
      <ref source="CONFIRM" url="http://www-01.ibm.com/support/docview.wss?uid=swg21375360">http://www-01.ibm.com/support/docview.wss?uid=swg21375360</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC37554" adv="1">IC37554</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/49536">tsm-consolemode-info-disclosure(49536)</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_storage_manager" vendor="ibm">
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.1.10"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1571" seq="2003-1571" published="2009-04-02" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb.  NOTE: it was later reported that 8.21 is also affected.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863">http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/7488">7488</ref>
    </refs>
    <vuln_soft>
      <prod name="web_wiz_guestbook" vendor="webwizguide">
        <vers num="6.0"/>
        <vers num="8.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1572" seq="2003-1572" published="2009-06-01" modified="2009-06-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/bugtraq/2003/06/msg00219.html">20030625 Privilege escalation applet, Java Media Framework</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1006777">1006777</ref>
      <ref source="MISC" url="http://www.illegalaccess.org/java/jmf.php">http://www.illegalaccess.org/java/jmf.php</ref>
    </refs>
    <vuln_soft>
      <prod name="jmf" vendor="sun">
        <vers num="2.1.1"/>
        <vers num="2.1.1a"/>
        <vers num="2.1.1b"/>
        <vers num="2.1.1c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1573" seq="2003-1573" published="2009-06-01" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0148.html">20040118 Proof-Of-Concept Denial-Of-Service Pointbase 4.6 Java SQL-DB</ref>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0675.html">20040118 Proof-Of-Concept Denial-Of-Service Pointbase 4.6 Java SQL-DB</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2003/Dec/0249.html">20031216 J2EE 1.4 reference implementation: database component allows remote code execution</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1008491">1008491</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9230">9230</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14008">j2ee-pointbase-sql-injection(14008)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14881">pointbase-insecure-permissions-dos(14881)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14882">pointbase-information-disclosure(14882)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/14883">pointbase-command-execution(14883)</ref>
    </refs>
    <vuln_soft>
      <prod name="j2ee" vendor="sun">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1574" seq="2003-1574" published="2009-08-24" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=748739&amp;group_id=64258&amp;atid=506846" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=748739&amp;group_id=64258&amp;atid=506846</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/14170" patch="1">14170</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/40347">tikiwiki-username-security-byass(40347)</ref>
    </refs>
    <vuln_soft>
      <prod name="tikiwiki_cms/groupware" vendor="tiki">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1575" seq="2003-1575" published="2010-01-28" modified="2010-01-31" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113207-05-1" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113207-05-1</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200161-1" adv="1" patch="1">200161</ref>
    </refs>
    <vuln_soft>
      <prod name="vxfs" vendor="symantec">
        <vers num="3.3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1576" seq="2003-1576" published="2010-01-28" modified="2010-01-31" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-201231-1



    * "SunMC Change Manager" 1.0 is an unbundled Sun Management Center (SunMC) 3.0 add-on. It is not a part of the SunMC "base" product.
    * Solaris 2.6 and 7 are not affected. Solaris on the x86 platform is not affected.
</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113105-01-1" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113105-01-1</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201231-1" adv="1" patch="1">201231</ref>
    </refs>
    <vuln_soft>
      <prod name="change_manager" vendor="sun">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1577" seq="2003-1577" published="2010-02-05" modified="2017-08-16" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201453-1" adv="1" patch="1">201453</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56632">sunone-iplanetlog-xss(56632)</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="4.1" prev="1" edition="sp1"/>
        <vers num="4.1" prev="1" edition="sp10"/>
        <vers num="4.1" prev="1" edition="sp11"/>
        <vers num="4.1" prev="1" edition="sp12"/>
        <vers num="4.1" prev="1" edition="sp2"/>
        <vers num="4.1" prev="1" edition="sp3"/>
        <vers num="4.1" prev="1" edition="sp4"/>
        <vers num="4.1" prev="1" edition="sp5"/>
        <vers num="4.1" prev="1" edition="sp6"/>
        <vers num="4.1" prev="1" edition="sp7"/>
        <vers num="4.1" prev="1" edition="sp8"/>
        <vers num="4.1" prev="1" edition="sp9"/>
        <vers num="6.0" prev="1" edition="sp1"/>
        <vers num="6.0" prev="1" edition="sp2"/>
        <vers num="6.0" prev="1" edition="sp3"/>
        <vers num="6.0" prev="1" edition="sp4"/>
        <vers num="6.0" prev="1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1578" seq="2003-1578" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201453-1" adv="1" patch="1">201453</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7012" patch="1">7012</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56633">iplanet-logpreview-security-bypass(56633)</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="4.1" prev="1" edition="sp1"/>
        <vers num="4.1" prev="1" edition="sp10"/>
        <vers num="4.1" prev="1" edition="sp11"/>
        <vers num="4.1" prev="1" edition="sp12"/>
        <vers num="4.1" prev="1" edition="sp2"/>
        <vers num="4.1" prev="1" edition="sp3"/>
        <vers num="4.1" prev="1" edition="sp4"/>
        <vers num="4.1" prev="1" edition="sp5"/>
        <vers num="4.1" prev="1" edition="sp6"/>
        <vers num="4.1" prev="1" edition="sp7"/>
        <vers num="4.1" prev="1" edition="sp8"/>
        <vers num="4.1" prev="1" edition="sp9"/>
        <vers num="6.0" prev="1" edition="sp1"/>
        <vers num="6.0" prev="1" edition="sp2"/>
        <vers num="6.0" prev="1" edition="sp3"/>
        <vers num="6.0" prev="1" edition="sp4"/>
        <vers num="6.0" prev="1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1579" seq="2003-1579" published="2010-02-05" modified="2010-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1580" seq="2003-1580" published="2010-02-05" modified="2010-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1581" seq="2003-1581" published="2010-02-05" modified="2010-02-08" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="2.0.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1582" seq="2003-1582" published="2010-02-05" modified="2019-07-03" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1583" seq="2003-1583" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56650">webtrends-domain-name-xss(56650)</ref>
    </refs>
    <vuln_soft>
      <prod name="webtrends_log_analyzer" vendor="webtrends">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1584" seq="2003-1584" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56649">surfstats-domain-name-xss(56649)</ref>
    </refs>
    <vuln_soft>
      <prod name="surfstats" vendor="surfstats">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1585" seq="2003-1585" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56647">weblogexpert-domain-name-xss(56647)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblog_expert" vendor="alentum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1586" seq="2003-1586" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56646">webexpert-useragent-xss(56646)</ref>
    </refs>
    <vuln_soft>
      <prod name="webexpert" vendor="iplanet">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1587" seq="2003-1587" published="2010-02-05" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/313867">20030304 Log corruption on multiple webservers, log analyzers,...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56645">loganpro-useragent-xss(56645)</ref>
    </refs>
    <vuln_soft>
      <prod name="loganpro" vendor="iplanet">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1588" seq="2003-1588" published="2010-02-08" modified="2017-08-16" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201460-1" adv="1">201460</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56617">suncluster-haoracle-information-disclosure(56617)</ref>
    </refs>
    <vuln_soft>
      <prod name="cluster" vendor="sun">
        <vers num="2.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1589" seq="2003-1589" published="2010-02-25" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201454-1" adv="1" patch="1">201454</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56616">iplanet-unspecified-dos(56616)</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp10"/>
        <vers num="4.1" edition="sp11"/>
        <vers num="4.1" edition="sp12"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
        <vers num="4.1" edition="sp5"/>
        <vers num="4.1" edition="sp6"/>
        <vers num="4.1" edition="sp7"/>
        <vers num="4.1" edition="sp8"/>
        <vers num="4.1" edition="sp9"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="6.0" edition="sp4"/>
        <vers num="6.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1590" seq="2003-1590" published="2010-02-25" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201451-1" adv="1" patch="1">201451</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/56615">sunone-unspecified-dos(56615)</ref>
    </refs>
    <vuln_soft>
      <prod name="one_web_server" vendor="sun">
        <vers num="6.0" edition="sp3"/>
        <vers num="6.0" edition="sp4"/>
        <vers num="6.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1591" seq="2003-1591" published="2010-04-05" modified="2010-06-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not properly handled during an NLM unload.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1592" seq="2003-1592" published="2010-04-05" modified="2010-04-06" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num=""/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1593" seq="2003-1593" published="2010-04-05" modified="2010-04-06" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num=""/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1594" seq="2003-1594" published="2010-04-05" modified="2010-04-06" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num=""/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1595" seq="2003-1595" published="2010-04-05" modified="2010-04-06" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num=""/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1596" seq="2003-1596" published="2010-04-05" modified="2010-06-08" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num="5.01i"/>
        <vers num="5.01o"/>
        <vers num="5.01w"/>
        <vers num="5.01y"/>
        <vers num="5.02b"/>
        <vers num="5.02i"/>
        <vers num="5.02r"/>
        <vers num="5.02y"/>
        <vers num="5.03b" prev="1"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1598" seq="2003-1598" published="2014-10-01" modified="2017-08-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2012/q1/77">[oss-sec] 20120106 Re: CVE-request: WordPress SQL injection and arbitrary code injection (2003)</ref>
      <ref source="MISC" url="http://www.kernelpanik.org/docs/kernelpanik/wordpressadv.txt">http://www.kernelpanik.org/docs/kernelpanik/wordpressadv.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7784">7784</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12204">wordpress-blogheader-sql-injection(12204)</ref>
    </refs>
    <vuln_soft>
      <prod name="wordpress" vendor="wordpress">
        <vers num="0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1599" seq="2003-1599" published="2014-10-27" modified="2017-08-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2012/01/06/3">[oss-security] 20120106 Re: CVE-request: WordPress SQL injection and arbitrary  code injection (2003)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7785">7785</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/12205">wordpress-linksall-file-include(12205)</ref>
    </refs>
    <vuln_soft>
      <prod name="wordpress" vendor="wordpress">
        <vers num="0.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1603" seq="2003-1603" published="2015-08-04" modified="2018-03-27" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) "2" for the LOCAL user of the FTP server for the Codonics printer, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://apps.gehealthcare.com/servlet/ClientServlet/2337093-100.pdf?REQ=RAA&amp;DIRECTION=2337093-100&amp;FILENAME=2337093-100.pdf&amp;FILEREV=1&amp;DOCREV_ORG=1">http://apps.gehealthcare.com/servlet/ClientServlet/2337093-100.pdf?REQ=RAA&amp;DIRECTION=2337093-100&amp;FILENAME=2337093-100.pdf&amp;FILEREV=1&amp;DOCREV_ORG=1</ref>
      <ref source="MISC" url="http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/">http://www.forbes.com/sites/thomasbrewster/2015/07/10/vulnerable-breasts/</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-037-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-037-02</ref>
      <ref source="MISC" url="https://twitter.com/digitalbond/status/619250429751222277">https://twitter.com/digitalbond/status/619250429751222277</ref>
    </refs>
    <vuln_soft>
      <prod name="discovery_vh" vendor="gehealthcare">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1604" seq="2003-1604" published="2016-05-02" modified="2016-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.</descript>
      <descript source="nvd">&lt;a href="http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference&lt;/a></descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html">openSUSE-SU-2016:1008</ref>
      <ref source="MLIST" url="http://marc.info/?l=netfilter-devel&amp;m=106668497403047&amp;w=2">[netfilter-devel] 20031020 [PATCH] Fix possible oops in ipt_REDIRECT</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2016/01/27/9">[oss-security] 20160127 Re: CVE Request: Linux: NULL pointer dereference netfilter/nf_nat_redirect.c in nf_nat_redirect_ipv4 function</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1303072">https://bugzilla.redhat.com/show_bug.cgi?id=1303072</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.5.75" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2003-1605" seq="2003-1605" published="2018-08-23" modified="2018-10-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8432" adv="1">8432</ref>
      <ref source="MISC" url="https://curl.haxx.se/docs/CVE-2003-1605.html" adv="1">https://curl.haxx.se/docs/CVE-2003-1605.html</ref>
    </refs>
    <vuln_soft>
      <prod name="curl" vendor="haxx">
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.5"/>
        <vers num="7.5.1"/>
        <vers num="7.5.2"/>
        <vers num="7.6"/>
        <vers num="7.6.1"/>
        <vers num="7.7"/>
        <vers num="7.7.1"/>
        <vers num="7.7.2"/>
        <vers num="7.7.3"/>
        <vers num="7.8"/>
        <vers num="7.8.1"/>
        <vers num="7.9"/>
        <vers num="7.9.1"/>
        <vers num="7.9.2"/>
        <vers num="7.9.3"/>
        <vers num="7.9.4"/>
        <vers num="7.9.5"/>
        <vers num="7.9.6"/>
        <vers num="7.9.7"/>
        <vers num="7.9.8"/>
        <vers num="7.10"/>
        <vers num="7.10.1"/>
        <vers num="7.10.2"/>
        <vers num="7.10.3"/>
        <vers num="7.10.4"/>
        <vers num="7.10.5"/>
        <vers num="7.10.6"/>
      </prod>
    </vuln_soft>
  </entry>
</nvd>