<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="1.2" pub_date="2019-10-15" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 https://scap.nist.gov/schema/nvd/nvd-cve-feed_1.2.1.xsd">
  <entry type="CVE" name="CVE-2017-0001" seq="2017-0001" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0005, CVE-2017-0025, and CVE-2017-0047.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96057" adv="1">96057</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0001" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0001</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0002" seq="2017-0002" published="2017-01-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95284">95284</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037573">1037573</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-001">MS17-001</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0003" seq="2017-0003" published="2017-01-10" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://fortiguard.com/advisory/FG-VD-16-079">http://fortiguard.com/advisory/FG-VD-16-079</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/95287">95287</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037568">1037568</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037569">1037569</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-002">MS17-002</ref>
    </refs>
    <vuln_soft>
      <prod name="sharepoint_enterprise_server" vendor="microsoft">
        <vers num="2016"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0004" seq="2017-0004" published="2017-01-10" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95318">95318</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037571">1037571</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-004">MS17-004</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0005" seq="2017-0005" published="2017-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96033" adv="1">96033</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://blogs.technet.microsoft.com/mmpc/2017/03/27/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005/">https://blogs.technet.microsoft.com/mmpc/2017/03/27/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005/</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0005" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0005</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0006" seq="2017-0006" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96740" adv="1">96740</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0006" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0006</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod name="excel_viewer" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0007" seq="2017-0007" published="2017-03-16" modified="2017-07-11" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96018">96018</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001">1038001</ref>
      <ref source="MISC" url="https://enigma0x3.net/2017/04/03/defeating-device-guard-a-look-into-cve-2017-0007/">https://enigma0x3.net/2017/04/03/defeating-device-guard-a-look-into-cve-2017-0007/</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0007" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0007</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0008" seq="2017-0008" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009 and CVE-2017-0059.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96073" adv="1">96073</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0008" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0008</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0009" seq="2017-0009" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0011, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.security-assessment.com/files/documents/advisory/comparestring_infoleak.pdf">http://www.security-assessment.com/files/documents/advisory/comparestring_infoleak.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96077" adv="1">96077</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0009" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0009</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0010" seq="2017-0010" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96059" adv="1">96059</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0010" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0010</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0011" seq="2017-0011" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96064" adv="1">96064</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0011" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0011</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0012" seq="2017-0012" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0033 and CVE-2017-0069.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96085">96085</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0012" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0012</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0014" seq="2017-0014" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96013" adv="1">96013</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0014" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0014</ref>
      <ref source="MISC" url="https://secuniaresearch.flexerasoftware.com/secunia_research/2017-9/">https://secuniaresearch.flexerasoftware.com/secunia_research/2017-9/</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0015" seq="2017-0015" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96079" adv="1">96079</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0015" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0015</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0016" seq="2017-0016" published="2017-03-16" modified="2017-07-24" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95969" adv="1">95969</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037767">1037767</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001">1038001</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0016" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0016</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0017" seq="2017-0017" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0065, and CVE-2017-0068.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96078" adv="1">96078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0017" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0017</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0018" seq="2017-0018" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0037 and CVE-2017-0149.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96086" adv="1">96086</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0018" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0018</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0019" seq="2017-0019" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Word 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96042" adv="1">96042</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0019" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0019</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0020" seq="2017-0020" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Excel 2016, Excel 2010 SP2, Excel 2013 RT SP1, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96050" adv="1">96050</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0020" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0020</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1:~~rt~~~"/>
        <vers num="2016"/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0021" seq="2017-0021" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.7" CVSS_base_score="7.7" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96020" adv="1">96020</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0021" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0021</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0022" seq="2017-0022" published="2017-03-16" modified="2017-09-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96069" adv="1">96069</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038014">1038014</ref>
      <ref source="MISC" url="https://0patch.blogspot.com/2017/09/exploit-kit-rendezvous-and-cve-2017-0022.html">https://0patch.blogspot.com/2017/09/exploit-kit-rendezvous-and-cve-2017-0022.html</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0022" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0022</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0023" seq="2017-0023" published="2017-03-16" modified="2018-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Windows 10, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96075" adv="1">96075</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037989" adv="1">1037989</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0023" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0023</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0024" seq="2017-0024" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 10 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96029" adv="1">96029</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0024" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0024</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0025" seq="2017-0025" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005, and CVE-2017-0047.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96626" adv="1">96626</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0025" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0025</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0026" seq="2017-0026" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96032" adv="1">96032</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0026" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0026</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0027" seq="2017-0027" published="2017-03-16" modified="2017-07-11" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96043" adv="1">96043</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0027" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0027</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2:~~~~x64~"/>
        <vers num="2013" edition="sp1:~~rt~~~"/>
        <vers num="2016"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0028" seq="2017-0028" published="2017-07-17" modified="2017-08-04" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Microsoft/ChakraCore/commit/402f3d967c0a905ec5b9ca9c240783d3f2c15724" adv="1" patch="1">https://github.com/Microsoft/ChakraCore/commit/402f3d967c0a905ec5b9ca9c240783d3f2c15724</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0029" seq="2017-0029" published="2017-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96045" adv="1">96045</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0029" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0029</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1:~~rt~~~"/>
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0030" seq="2017-0030" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96051" adv="1">96051</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0030" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0030</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0031" seq="2017-0031" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0052, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96052" adv="1">96052</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0031" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0031</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0032" seq="2017-0032" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96080" adv="1">96080</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0032" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0032</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0033" seq="2017-0033" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96087" adv="1">96087</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0033" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0033</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0034" seq="2017-0034" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96786">96786</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0034" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0034</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0035" seq="2017-0035" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96082" adv="1">96082</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0035" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0035</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0037" seq="2017-0037" published="2017-02-26" modified="2017-11-18" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96088">96088</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037905">1037905</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037906">1037906</ref>
      <ref source="MISC" url="https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html">https://0patch.blogspot.si/2017/03/0patching-another-0-day-internet.html</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1011" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1011</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0037</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41454/">41454</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42354/">42354</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43125/">43125</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0038" seq="2017-0038" published="2017-02-20" modified="2017-08-31" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96023">96023</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037845">1037845</ref>
      <ref source="MISC" url="https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html" adv="1" patch="1">https://0patch.blogspot.com/2017/02/0patching-0-day-windows-gdi32dll-memory.html</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=992" adv="1" patch="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=992</ref>
      <ref source="MISC" url="https://github.com/k0keoyo/CVE-2017-0038-EXP-C-JS">https://github.com/k0keoyo/CVE-2017-0038-EXP-C-JS</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0038">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0038</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41363/">41363</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0039" seq="2017-0039" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle dynamic link library (DLL) loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96024" adv="1">96024</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001">1038001</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0039" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0039</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0040" seq="2017-0040" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0130.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.security-assessment.com/files/documents/advisory/reversesegment.pdf">http://www.security-assessment.com/files/documents/advisory/reversesegment.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96094">96094</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0040" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0040</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0042" seq="2017-0042" published="2017-03-16" modified="2017-07-11" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "Windows Media Player Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://pastebin.com/raw/Eztknq4s">http://pastebin.com/raw/Eztknq4s</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96098" adv="1">96098</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038016">1038016</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0042" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0042</ref>
      <ref source="MISC" url="https://twitter.com/Qab/status/842506404950917120">https://twitter.com/Qab/status/842506404950917120</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0043" seq="2017-0043" published="2017-03-16" modified="2017-07-11" severity="Low" CVSS_version="2.0" CVSS_score="2.9" CVSS_base_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active Directory Federation Services Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96628" adv="1">96628</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038018">1038018</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0043" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0043</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0045" seq="2017-0045" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://hyp3rlinx.altervista.org/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSURE.txt" adv="1">http://hyp3rlinx.altervista.org/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSURE.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96103" adv="1">96103</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038015">1038015</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0045" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0045</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41619/">41619</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0047" seq="2017-0047" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005 and CVE-2017-0025.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96034" adv="1">96034</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0047" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0047</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0049" seq="2017-0049" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0018, and CVE-2017-0037.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96095">96095</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0049" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0049</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0050" seq="2017-0050" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96025" adv="1">96025</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038013">1038013</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0050" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0050</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_8" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0051" seq="2017-0051" published="2017-03-16" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.9" CVSS_base_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 1607 and Windows Server 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Hyper-V Network Switch Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, CVE-2017-0098, and CVE-2017-0099.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96026" adv="1">96026</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0051" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0051</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0052" seq="2017-0052" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, and CVE-2017-0053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96741" adv="1">96741</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0052" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0052</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod name="excel_viewer" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0053" seq="2017-0053" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, Word 2010 SP2, Word 2013 SP1, Word 2013 R2 SP1, Word 2016, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, and CVE-2017-0052.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96745" adv="1">96745</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0053" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0053</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1:~~rt~~~"/>
        <vers num="2016"/>
      </prod>
      <prod name="word_viewer" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0055" seq="2017-0055" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96622" adv="1">96622</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038012">1038012</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0055" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0055</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0056" seq="2017-0056" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96630" adv="1">96630</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0056" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0056</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0057" seq="2017-0057" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to visit an untrusted webpage or (2) tricking a server into sending a DNS query to a malicious DNS server, aka "Windows DNS Query Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96695" adv="1">96695</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001">1038001</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0057" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0057</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0058" seq="2017-0058" published="2017-04-12" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97462" adv="1">97462</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0058" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0058</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41879/">41879</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0059" seq="2017-0059" published="2017-03-16" modified="2017-11-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96645">96645</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0059" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0059</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41661/">41661</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42354/">42354</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43125/">43125</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0060" seq="2017-0060" published="2017-03-16" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0060 and CVE-2017-0062.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96713" adv="1">96713</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0060" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0060</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41656/">41656</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0061" seq="2017-0061" published="2017-03-16" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0063.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96638" adv="1">96638</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0061" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0061</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41657/">41657</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0062" seq="2017-0062" published="2017-03-16" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0060 and CVE-2017-0073.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96715" adv="1">96715</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0062" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0062</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41658/">41658</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0063" seq="2017-0063" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0061.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96643" adv="1">96643</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0063" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0063</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41659/">41659</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0064" seq="2017-0064" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98121" adv="1">98121</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038447">1038447</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0064" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0064</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0065" seq="2017-0065" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96648" adv="1">96648</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0065" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0065</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0066" seq="2017-0066" published="2017-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96655" adv="1">96655</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0066" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0066</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0067" seq="2017-0067" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96662" adv="1">96662</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0067" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0067</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0068" seq="2017-0068" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0065.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96649">96649</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0068" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0068</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0069" seq="2017-0069" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0033.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96650">96650</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0069" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0069</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0070" seq="2017-0070" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96690" adv="1">96690</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0070" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0070</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41623/">41623</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0071" seq="2017-0071" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96681" adv="1">96681</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0071" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0071</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0072" seq="2017-0072" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96599">96599</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0072" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0072</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41654/">41654</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0073" seq="2017-0073" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows GDI+ Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0060 and CVE-2017-0062.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96637" adv="1">96637</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0073" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0073</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0074" seq="2017-0074" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.3" CVSS_base_score="2.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96641" adv="1">96641</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0074" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0074</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0075" seq="2017-0075" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0109.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96698" adv="1">96698</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0075" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0075</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0076" seq="2017-0076" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.9" CVSS_base_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0097, and CVE-2017-0099.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96636" adv="1">96636</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0076" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0076</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0077" seq="2017-0077" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow a local authenticated attacker to execute a specially crafted application to obtain information, or in Windows 7 and later, cause denial of service, aka "Win32k Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98114" adv="1">98114</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038454">1038454</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0077" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0077</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0078" seq="2017-0078" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96631" adv="1">96631</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0078" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0078</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0079" seq="2017-0079" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96632" adv="1">96632</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0079" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0079</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0080" seq="2017-0080" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0081, and CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96633" adv="1">96633</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0080" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0080</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0081" seq="2017-0081" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0082.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96634" adv="1">96634</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0081" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0081</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0082" seq="2017-0082" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, and CVE-2017-0081.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96635" adv="1">96635</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038017">1038017</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0082" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0082</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0083" seq="2017-0083" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96608">96608</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0083" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0083</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0084" seq="2017-0084" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96610" adv="1">96610</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0084" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0084</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41648/">41648</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-" edition="gold"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0085" seq="2017-0085" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96652">96652</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0085" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0085</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41646/">41646</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0086" seq="2017-0086" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96603">96603</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0086" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0086</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41649/">41649</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0087" seq="2017-0087" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96604">96604</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0087" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0087</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41650/">41650</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0088" seq="2017-0088" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96605">96605</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0088" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0088</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41651/">41651</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0089" seq="2017-0089" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, and CVE-2017-0090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96606">96606</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0089" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0089</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41652/">41652</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0090" seq="2017-0090" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, and CVE-2017-0089.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96607">96607</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0090" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0090</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41653/">41653</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0091" seq="2017-0091" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96657">96657</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0091" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0091</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0092" seq="2017-0092" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96676">96676</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0092" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0092</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0093" seq="2017-0093" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0201.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97419" adv="1">97419</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038234">1038234</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0093" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0093</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0094" seq="2017-0094" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96682" adv="1">96682</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0094" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0094</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0095" seq="2017-0095" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.9" CVSS_base_score="7.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0021.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96699" adv="1">96699</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0095" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0095</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0096" seq="2017-0096" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.3" CVSS_base_score="2.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96701" adv="1">96701</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0096" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0096</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0097" seq="2017-0097" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.3" CVSS_base_score="2.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0099.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96639" adv="1">96639</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0097" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0097</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0098" seq="2017-0098" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.9" CVSS_base_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96642" adv="1">96642</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0098" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0098</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0099" seq="2017-0099" published="2017-03-16" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.3" CVSS_base_score="2.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0097.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96640" adv="1">96640</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0099" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0099</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0100" seq="2017-0100" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows HelpPane Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.inspired-sec.com/archive/2017/03/17/COM-Moniker-Privesc.html">http://blog.inspired-sec.com/archive/2017/03/17/COM-Moniker-Privesc.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96700" adv="1">96700</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001">1038001</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1021">https://bugs.chromium.org/p/project-zero/issues/detail?id=1021</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0100" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0100</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41607/">41607</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0101" seq="2017-0101" published="2017-03-16" modified="2018-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96625" adv="1">96625</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038013">1038013</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0101" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0101</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44479/">44479</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0102" seq="2017-0102" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 let attackers with access to targets systems gain privileges when Windows fails to properly validate buffer lengths, aka "Windows Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96627" adv="1">96627</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038013">1038013</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0102" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0102</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0103" seq="2017-0103" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Registry Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96623" adv="1">96623</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038013">1038013</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0103" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0103</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41645/">41645</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0104" seq="2017-0104" published="2017-03-16" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers to issue malicious requests via an integer overflow, aka "iSNS Server Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96697" adv="1">96697</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038001" adv="1">1038001</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0104" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0104</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0105" seq="2017-0105" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96746" adv="1">96746</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038010">1038010</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0105" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0105</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="-" edition="sp3"/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod name="word_automation_services" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="word_for_mac" vendor="microsoft">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0106" seq="2017-0106" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97413" adv="1">97413</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038227">1038227</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0106" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0106</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0107" seq="2017-0107" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96748" adv="1">96748</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038019">1038019</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0107" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0107</ref>
    </refs>
    <vuln_soft>
      <prod name="sharepoint_foundation" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0108" seq="2017-0108" published="2017-03-16" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96722" adv="1">96722</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038002">1038002</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0108" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0108</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41647/">41647</ref>
    </refs>
    <vuln_soft>
      <prod name="live_meeting" vendor="microsoft">
        <vers num="2007"/>
      </prod>
      <prod name="lync" vendor="microsoft">
        <vers num="2010"/>
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="office" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="silverlight" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
      <prod name="skype_for_business" vendor="microsoft">
        <vers num="2016"/>
      </prod>
      <prod name="word_viewer" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0109" seq="2017-0109" published="2017-03-16" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0075.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96644" adv="1">96644</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037999">1037999</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0109" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0109</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0110" seq="2017-0110" published="2017-03-16" modified="2018-08-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96621" adv="1">96621</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038011" adv="1">1038011</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0110" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0110</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2013" edition="cumulative_update_14"/>
        <vers num="2013" edition="cumulative_update_3"/>
        <vers num="2013" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0111" seq="2017-0111" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96658">96658</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0111" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0111</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0112" seq="2017-0112" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96659">96659</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0112" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0112</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0113" seq="2017-0113" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96660">96660</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0113" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0113</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0114" seq="2017-0114" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96661">96661</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0114" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0114</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0115" seq="2017-0115" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96663">96663</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0115" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0115</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0116" seq="2017-0116" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96665">96665</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0116" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0116</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0117" seq="2017-0117" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96679">96679</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0117" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0117</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0118" seq="2017-0118" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96680" adv="1">96680</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0118" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0118</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0119" seq="2017-0119" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96666">96666</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0119" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0119</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0120" seq="2017-0120" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Uniscribe Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96667">96667</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0120" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0120</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0121" seq="2017-0121" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96678" adv="1">96678</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0121" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0121</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0122" seq="2017-0122" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96668">96668</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0122" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0122</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0123" seq="2017-0123" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96669">96669</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0123" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0123</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0124" seq="2017-0124" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96670">96670</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0124" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0124</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0125" seq="2017-0125" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96672">96672</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0125" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0125</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0126" seq="2017-0126" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0127, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96673">96673</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0126" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0126</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0127" seq="2017-0127" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0128.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96674">96674</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0127" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0127</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0128" seq="2017-0128" published="2017-03-16" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0127.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96675">96675</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037992">1037992</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0128" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0128</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41655/">41655</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0129" seq="2017-0129" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96752" adv="1">96752</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038020">1038020</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0129" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0129</ref>
    </refs>
    <vuln_soft>
      <prod name="lync_for_mac" vendor="microsoft">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0130" seq="2017-0130" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerability is different from that described in CVE-2017-0040.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96647" adv="1">96647</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0130" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0130</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0131" seq="2017-0131" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96671" adv="1">96671</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0131" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0131</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0132" seq="2017-0132" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96686" adv="1">96686</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0132" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0132</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0133" seq="2017-0133" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96683" adv="1">96683</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0133" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0133</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0134" seq="2017-0134" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96687" adv="1">96687</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0134" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0134</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0135" seq="2017-0135" published="2017-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96656">96656</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="MISC" url="https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754">https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135</ref>
      <ref source="MISC" url="https://www.freebuf.com/articles/web/164871.html">https://www.freebuf.com/articles/web/164871.html</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0136" seq="2017-0136" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96688" adv="1">96688</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0136" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0136</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0137" seq="2017-0137" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96689" adv="1">96689</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0137" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0137</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0138" seq="2017-0138" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96684" adv="1">96684</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0138" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0138</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0140" seq="2017-0140" published="2017-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96653">96653</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0141" seq="2017-0141" published="2017-03-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0150, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96685" adv="1">96685</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0141" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0141</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0143" seq="2017-0143" published="2017-03-16" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96703">96703</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0143" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0143</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/">41987</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43970/">43970</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0144" seq="2017-0144" published="2017-03-16" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96704">96704</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0144</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/">41987</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42030/">42030</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42031/">42031</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0145" seq="2017-0145" published="2017-03-16" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96705">96705</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0145" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0145</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/">41987</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0146" seq="2017-0146" published="2017-03-16" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96707">96707</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0146" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0146</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/">41987</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43970/">43970</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0147" seq="2017-0147" published="2017-03-16" modified="2018-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96709" adv="1">96709</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991" adv="1">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0147" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0147</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/" adv="1">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/" adv="1">41987</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43970/">43970</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0148" seq="2017-0148" published="2017-03-16" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html">http://packetstormsecurity.com/files/154690/DOUBLEPULSAR-Payload-Execution-Neutralization.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96706">96706</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037991">1037991</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-701903.pdf</ref>
      <ref source="CONFIRM" url="https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-966341.pdf</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0148</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41891/">41891</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41987/">41987</ref>
    </refs>
    <vuln_soft>
      <prod name="server_message_block" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0149" seq="2017-0149" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96724">96724</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0149" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0149</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0150" seq="2017-0150" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, and CVE-2017-0151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96725" adv="1">96725</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0150" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0150</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0151" seq="2017-0151" published="2017-03-16" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, and CVE-2017-0150.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96727" adv="1">96727</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038006">1038006</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0151" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0151</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0152" seq="2017-0152" published="2017-07-17" modified="2017-07-21" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Microsoft/ChakraCore/commit/9da019424601325a6e95e6be0fa03d7d21d0b517" adv="1" patch="1">https://github.com/Microsoft/ChakraCore/commit/9da019424601325a6e95e6be0fa03d7d21d0b517</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0154" seq="2017-0154" published="2017-03-16" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96766" adv="1">96766</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038008">1038008</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0154" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0154</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11" edition="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0155" seq="2017-0155" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97471" adv="1">97471</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038237">1038237</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0155" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0155</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0156" seq="2017-0156" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle objects in memory, aka "Windows Graphics Component Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97507" adv="1">97507</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038237">1038237</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0156" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0156</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0158" seq="2017-0158" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97455" adv="1">97455</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038238">1038238</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0158" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0158</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0159" seq="2017-0159" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97449" adv="1">97449</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038243">1038243</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0159" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0159</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0160" seq="2017-0160" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97447" adv="1">97447</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038236">1038236</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0160</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41903/">41903</ref>
    </refs>
    <vuln_soft>
      <prod name=".net_framework" vendor="microsoft">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0161" seq="2017-0161" published="2017-09-12" modified="2017-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code Execution Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100728" adv="1">100728</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039318" adv="1">1039318</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0161" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0161</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0162" seq="2017-0162" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0163, CVE-2017-0180, and CVE-2017-0181.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97461" adv="1">97461</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038233">1038233</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0162" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0162</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0163" seq="2017-0163" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97465" adv="1">97465</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038233">1038233</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0163" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0163</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0164" seq="2017-0164" published="2017-04-12" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97448" adv="1">97448</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038235">1038235</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0164" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0164</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0165" seq="2017-0165" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Windows Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97467" adv="1">97467</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0165" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0165</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41901/">41901</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0166" seq="2017-0166" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97446" adv="1">97446</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038245">1038245</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0166" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0166</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0167" seq="2017-0167" published="2017-04-12" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97473" adv="1">97473</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0167" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0167</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41880/">41880</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0168" seq="2017-0168" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability exists when the Windows Hyper-V Network Switch running on a Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0169.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97418" adv="1">97418</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038232">1038232</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0168" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0168</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0169" seq="2017-0169" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.2" CVSS_base_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0168.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97459" adv="1">97459</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038232">1038232</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0169" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0169</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0170" seq="2017-0170" published="2017-07-11" modified="2017-09-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99398" adv="1">99398</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038855" adv="1">1038855</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-0170" adv="1" patch="1">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-0170</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0171" seq="2017-0171" published="2017-05-12" modified="2017-05-25" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98097" adv="1">98097</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0171" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0171</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0173" seq="2017-0173" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0215, CVE-2017-0216, CVE-2017-0218, and CVE-2017-0219.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98873" adv="1">98873</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0173" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0173</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0174" seq="2017-0174" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.1" CVSS_base_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100038" adv="1">100038</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039109" adv="1">1039109</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0174" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0174</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0175" seq="2017-0175" published="2017-05-12" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98110" adv="1">98110</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038452" adv="1">1038452</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0175" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0175</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42009/" adv="1">42009</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0176" seq="2017-0176" published="2017-06-22" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98550" adv="1">98550</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98752" adv="1">98752</ref>
      <ref source="MISC" url="https://blog.fortinet.com/2017/05/11/deep-analysis-of-esteemaudit" adv="1">https://blog.fortinet.com/2017/05/11/deep-analysis-of-esteemaudit</ref>
      <ref source="MISC" url="https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/" adv="1" patch="1">https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/</ref>
      <ref source="CONFIRM" url="https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003" adv="1" patch="1">https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_server_2003" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0178" seq="2017-0178" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.2" CVSS_base_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server 2012 R2, and Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97416" adv="1">97416</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0178" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0178</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0179" seq="2017-0179" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97426" adv="1">97426</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0179" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0179</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0180" seq="2017-0180" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97444" adv="1">97444</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038233">1038233</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0180" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0180</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0181" seq="2017-0181" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.4" CVSS_base_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97445" adv="1">97445</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038233">1038233</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0181" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0181</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0182" seq="2017-0182" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97427" adv="1">97427</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0182" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0182</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0183" seq="2017-0183" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97428" adv="1">97428</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0183" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0183</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0184" seq="2017-0184" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.2" CVSS_base_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0185, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97435" adv="1">97435</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0184" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0184</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0185" seq="2017-0185" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0186.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97437" adv="1">97437</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038230">1038230</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0185" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0185</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0186" seq="2017-0186" published="2017-04-12" modified="2017-04-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0185.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97438" adv="1">97438</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0186" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0186</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0188" seq="2017-0188" published="2017-04-12" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A Win32k information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0189.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97475" adv="1">97475</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0188" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0188</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0189" seq="2017-0189" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0188.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97420" adv="1">97420</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0189" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0189</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0190" seq="2017-0190" published="2017-05-12" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98298" adv="1">98298</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038451">1038451</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0190" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0190</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0191" seq="2017-0191" published="2017-04-12" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding, aka "Windows Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97466" adv="1">97466</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038239">1038239</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0191" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0191</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0192" seq="2017-0192" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive information via a specially crafted document or an untrusted website, aka "ATMFD.dll Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97452" adv="1">97452</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038231">1038231</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0192" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0192</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0193" seq="2017-0193" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating system when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98878" adv="1">98878</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038670">1038670</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0193" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0193</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0194" seq="2017-0194" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97436" adv="1">97436</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038244">1038244</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0194" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0194</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0195" seq="2017-0195" published="2017-04-12" modified="2017-04-20" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97417" adv="1">97417</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0195" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0195</ref>
    </refs>
    <vuln_soft>
      <prod name="excel_web_app" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_online_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_web_apps_server" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0196" seq="2017-0196" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Microsoft/ChakraCore/commit/065b7978c40ded35c356ced6cd922a40156c9c46" adv="1" patch="1">https://github.com/Microsoft/ChakraCore/commit/065b7978c40ded35c356ced6cd922a40156c9c46</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0197" seq="2017-0197" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97411" adv="1">97411</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038241">1038241</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0197" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0197</ref>
      <ref source="MISC" url="https://twitter.com/buffaloverflow/status/852937040480149505" adv="1">https://twitter.com/buffaloverflow/status/852937040480149505</ref>
    </refs>
    <vuln_soft>
      <prod name="onenote" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0199" seq="2017-0199" published="2017-04-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html" adv="1">http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97498" adv="1">97498</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038224">1038224</ref>
      <ref source="MISC" url="https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/" adv="1">https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41894/">41894</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41934/">41934</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42995/">42995</ref>
      <ref source="MISC" url="https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html" adv="1">https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html</ref>
      <ref source="MISC" url="https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/" adv="1">https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_vista" vendor="microsoft">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0200" seq="2017-0200" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user, aka "Microsoft Edge Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97456" adv="1">97456</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038234">1038234</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0200" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0200</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0201" seq="2017-0201" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0093.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97454" adv="1">97454</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038238">1038238</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0201" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0201</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0202" seq="2017-0202" published="2017-04-12" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, a.k.a. "Internet Explorer Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97441" adv="1">97441</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038238">1038238</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0202" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0202</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41941/">41941</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0203" seq="2017-0203" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker could trick a user into loading a web page with malicious content, aka "Microsoft Edge Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97443" adv="1">97443</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038234">1038234</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0203" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0203</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0204" seq="2017-0204" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97458" adv="1">97458</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038227">1038227</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0204" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0204</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0205" seq="2017-0205" published="2017-04-12" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user, aka "Microsoft Edge Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97442" adv="1">97442</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038234">1038234</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0205" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0205</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0207" seq="2017-0207" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97463" adv="1">97463</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038242">1038242</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0207" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0207</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2011" edition=":~~~mac_os_x~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0208" seq="2017-0208" published="2017-04-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97460" adv="1">97460</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038234">1038234</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0210" seq="2017-0210" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97512" adv="1">97512</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038238">1038238</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0210</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0211" seq="2017-0211" published="2017-04-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97514" adv="1">97514</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038240">1038240</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0211" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0211</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41902/">41902</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0212" seq="2017-0212" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.4" CVSS_base_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98099" adv="1">98099</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0212" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0212</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0213" seq="2017-0213" published="2017-05-12" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98102" adv="1">98102</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038457">1038457</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42020/">42020</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0214" seq="2017-0214" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0213.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98103" adv="1">98103</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0214" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0214</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42021/">42021</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0215" seq="2017-0215" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0173, CVE-2017-0216, CVE-2017-0218, and CVE-2017-0219.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98879" adv="1">98879</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038669">1038669</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0215" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0215</ref>
      <ref source="MISC" url="https://posts.specterops.io/umci-bypass-using-psworkflowutility-cve-2017-0215-71c76c1588f9">https://posts.specterops.io/umci-bypass-using-psworkflowutility-cve-2017-0215-71c76c1588f9</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0216" seq="2017-0216" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0173, CVE-2017-0215, CVE-2017-0218, and CVE-2017-0219.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98896" adv="1">98896</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0216" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0216</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0218" seq="2017-0218" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0173, CVE-2017-0215, CVE-2017-0216, and CVE-2017-0219.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98897" adv="1">98897</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038669">1038669</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0218" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0218</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0219" seq="2017-0219" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0173, CVE-2017-0215, CVE-2017-0216, and CVE-2017-0218.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98898" adv="1">98898</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0219" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0219</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0220" seq="2017-0220" published="2017-05-12" modified="2017-08-12" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98111" adv="1">98111</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038445">1038445</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0220" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0220</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42009/">42009</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0221" seq="2017-0221" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0227 and CVE-2017-0240.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98147" adv="1">98147</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0221" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0221</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0222" seq="2017-0222" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98127" adv="1">98127</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038423">1038423</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0222" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0222</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0223" seq="2017-0223" published="2017-05-15" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038425">1038425</ref>
      <ref source="CONFIRM" url="https://github.com/Microsoft/ChakraCore/pull/2959" adv="1" patch="1">https://github.com/Microsoft/ChakraCore/pull/2959</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0224" seq="2017-0224" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in the way JavaScript engines render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98214" adv="1">98214</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0224" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0224</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0226" seq="2017-0226" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0222.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98139" adv="1">98139</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0226" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0226</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0227" seq="2017-0227" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0221 and CVE-2017-0240.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98281" adv="1">98281</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038424">1038424</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0227" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0227</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0228" seq="2017-0228" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98164" adv="1">98164</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038425">1038425</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038426">1038426</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0228" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0228</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0229" seq="2017-0229" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98217" adv="1">98217</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0229" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0229</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0230" seq="2017-0230" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98222" adv="1">98222</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0230" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0230</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0231" seq="2017-0231" published="2017-05-12" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98173" adv="1">98173</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038455">1038455</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038456">1038456</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0231" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0231</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0233" seq="2017-0233" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98179" adv="1">98179</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0233" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0233</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0234" seq="2017-0234" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98229" adv="1">98229</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038431">1038431</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0234" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0234</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0235" seq="2017-0235" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0236, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98230" adv="1">98230</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0235" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0235</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0236" seq="2017-0236" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0238.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98234" adv="1">98234</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038431">1038431</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0236" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0236</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0238" seq="2017-0238" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0236.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98237" adv="1">98237</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0238" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0238</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0240" seq="2017-0240" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0221 and CVE-2017-0227.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98203" adv="1">98203</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038424">1038424</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0240" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0240</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0241" seq="2017-0241" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.4" CVSS_base_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:C/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the browser when browsing in the context of the Internet Zone, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0233.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98208" adv="1">98208</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0241" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0241</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0242" seq="2017-0242" published="2017-05-12" modified="2017-05-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98275" adv="1">98275</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0242" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0242</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0243" seq="2017-0243" published="2017-07-11" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8570.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99446" adv="1">99446</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038851" adv="1">1038851</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-0243" adv="1" patch="1">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-0243</ref>
    </refs>
    <vuln_soft>
      <prod name="business_productivity_servers" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="web_applications" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0244" seq="2017-0244" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98109" adv="1">98109</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038453">1038453</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0244" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0244</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0245" seq="2017-0245" published="2017-05-12" modified="2017-08-12" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka "Win32k Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98115" adv="1">98115</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0245" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0245</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42008/">42008</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0246" seq="2017-0246" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application or in Windows 7 for x64-based Systems and later, cause denial of service, aka "Win32k Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98108" adv="1">98108</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038449">1038449</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0246" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0246</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0247" seq="2017-0247" published="2017-05-12" modified="2017-08-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/aspnet/Announcements/issues/239" adv="1">https://github.com/aspnet/Announcements/issues/239</ref>
      <ref source="CONFIRM" url="https://technet.microsoft.com/en-us/library/security/4021279.aspx" adv="1" patch="1">https://technet.microsoft.com/en-us/library/security/4021279.aspx</ref>
      <ref source="MISC" url="https://www.sidertia.com/Home/Community/Blog/2017/05/18/ASPNET-Core-Unicode-Non-Char-Encoding-DoS" adv="1">https://www.sidertia.com/Home/Community/Blog/2017/05/18/ASPNET-Core-Unicode-Non-Char-Encoding-DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="microsoft.aspnetcore.mvc" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.abstractions" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.apiexplorer" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.core" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.cors" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.dataannotations" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.json" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.xml" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.localization" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor.host" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.taghelpers" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.viewfeatures" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.webapicompatshim" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http" vendor="microsoft">
        <vers num="4.1.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.1" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http.winhttphandler" vendor="microsoft">
        <vers num="4.0.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.security" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.websockets.client" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.text.encodings.web" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0248" seq="2017-0248" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98117" adv="1">98117</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038458">1038458</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0248" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0248</ref>
    </refs>
    <vuln_soft>
      <prod name=".net_framework" vendor="microsoft">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0249" seq="2017-0249" published="2017-05-12" modified="2017-08-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/aspnet/Announcements/issues/239" adv="1">https://github.com/aspnet/Announcements/issues/239</ref>
    </refs>
    <vuln_soft>
      <prod name="microsoft.aspnetcore.mvc" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.abstractions" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.apiexplorer" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.core" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.cors" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.dataannotations" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.json" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.xml" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.localization" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor.host" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.taghelpers" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.viewfeatures" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.webapicompatshim" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http" vendor="microsoft">
        <vers num="4.1.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.1" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http.winhttphandler" vendor="microsoft">
        <vers num="4.0.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.security" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.websockets.client" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.text.encodings.web" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0250" seq="2017-0250" published="2017-08-08" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to buffer overflow, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98100" adv="1">98100</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039090" adv="1">1039090</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0250" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0250</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0252" seq="2017-0252" published="2017-05-15" modified="2017-05-24" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0223.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Microsoft/ChakraCore/pull/2959" adv="1" patch="1">https://github.com/Microsoft/ChakraCore/pull/2959</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0254" seq="2017-0254" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services on Microsoft SharePoint Server 2013 SP1, Office Word Viewer, SharePoint Enterprise Server 2016, and Word 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0264 and CVE-2017-0265.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98101" adv="1">98101</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038443">1038443</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0254" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0254</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2011" edition=":mac"/>
        <vers num="2016" edition=":mac"/>
      </prod>
      <prod name="office_compatibility_pack" vendor="microsoft">
        <vers num="" edition="sp3"/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2007"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="word_rt" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="word_viewer" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0255" seq="2017-0255" published="2017-05-12" modified="2017-05-23" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98107" adv="1">98107</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0255" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0255</ref>
    </refs>
    <vuln_soft>
      <prod name="sharepoint_foundation" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0256" seq="2017-0256" published="2017-05-12" modified="2017-08-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/aspnet/Announcements/issues/239" adv="1">https://github.com/aspnet/Announcements/issues/239</ref>
    </refs>
    <vuln_soft>
      <prod name="microsoft.aspnetcore.mvc" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.abstractions" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.apiexplorer" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.core" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.cors" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.dataannotations" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.json" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.formatters.xml" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.localization" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.razor.host" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.taghelpers" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.viewfeatures" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="microsoft.aspnetcore.mvc.webapicompatshim" vendor="microsoft">
        <vers num="1.0.0" edition=":~~~asp.net~~"/>
        <vers num="1.0.1" edition=":~~~asp.net~~"/>
        <vers num="1.0.2" edition=":~~~asp.net~~"/>
        <vers num="1.0.3" edition=":~~~asp.net~~"/>
        <vers num="1.1.0" edition=":~~~asp.net~~"/>
        <vers num="1.1.1" edition=":~~~asp.net~~"/>
        <vers num="1.1.2" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http" vendor="microsoft">
        <vers num="4.1.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.1" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.http.winhttphandler" vendor="microsoft">
        <vers num="4.0.1" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.security" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.net.websockets.client" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
      <prod name="system.text.encodings.web" vendor="microsoft">
        <vers num="4.0.0" edition=":~~~asp.net~~"/>
        <vers num="4.3.0" edition=":~~~asp.net~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0258" seq="2017-0258" published="2017-05-12" modified="2017-08-12" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0259.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98112" adv="1">98112</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038446">1038446</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0258" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0258</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42006/">42006</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0259" seq="2017-0259" published="2017-05-12" modified="2017-08-12" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0258.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98113" adv="1">98113</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0259" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0259</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42007/">42007</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0260" seq="2017-0260" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, and CVE-2017-8506.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98810" adv="1">98810</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038668">1038668</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0260" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0260</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0261" seq="2017-0261" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98104" adv="1">98104</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038444">1038444</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0261" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0261</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0262" seq="2017-0262" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98279" adv="1">98279</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0262" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0262</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0263" seq="2017-0263" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98258" adv="1">98258</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038449">1038449</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44478/">44478</ref>
      <ref source="MISC" url="https://xiaodaozhi.com/exploit/117.html">https://xiaodaozhi.com/exploit/117.html</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0264" seq="2017-0264" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98282" adv="1">98282</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0264" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0264</ref>
    </refs>
    <vuln_soft>
      <prod name="powerpoint_for_mac" vendor="microsoft">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0265" seq="2017-0265" published="2017-05-12" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0264.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98285" adv="1">98285</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038448">1038448</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0265" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0265</ref>
    </refs>
    <vuln_soft>
      <prod name="powerpoint_for_mac" vendor="microsoft">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0266" seq="2017-0266" published="2017-05-12" modified="2017-05-23" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98276" adv="1">98276</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0266" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0266</ref>
    </refs>
    <vuln_soft>
      <prod name="edge" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0267" seq="2017-0267" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98259" adv="1">98259</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038432">1038432</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0267" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0267</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0268" seq="2017-0268" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98261" adv="1">98261</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0268" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0268</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0269" seq="2017-0269" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98263" adv="1">98263</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038433">1038433</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0269</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0270" seq="2017-0270" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98264" adv="1">98264</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0270" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0270</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0271" seq="2017-0271" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98265" adv="1">98265</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038432">1038432</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0271" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0271</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0272" seq="2017-0272" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0277, CVE-2017-0278, and CVE-2017-0279.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98260" adv="1">98260</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0272" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0272</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0273" seq="2017-0273" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98274" adv="1">98274</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038433">1038433</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0273" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0273</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0274" seq="2017-0274" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0275, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98266" adv="1">98266</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0274" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0274</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0275" seq="2017-0275" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0276.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98267" adv="1">98267</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038432">1038432</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0275" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0275</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0276" seq="2017-0276" published="2017-05-12" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0275.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98268" adv="1">98268</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0276" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0276</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0277" seq="2017-0277" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98270" adv="1">98270</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038430">1038430</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0277" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0277</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0278" seq="2017-0278" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0279.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98271" adv="1">98271</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038430">1038430</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0278" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0278</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0279" seq="2017-0279" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0278.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98272" adv="1">98272</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038430">1038430</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0279" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0279</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0280" seq="2017-0280" published="2017-05-12" modified="2018-03-27" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98273" adv="1">98273</ref>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02">https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0280" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0280</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0281" seq="2017-0281" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0262.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98297" adv="1">98297</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0281" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0281</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="office_online_server" vendor="microsoft">
        <vers num="2016"/>
      </prod>
      <prod name="office_web_apps" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="project_server" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="sharepoint_foundation" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="sharepoint_server" vendor="microsoft">
        <vers num="2010" edition="sp2"/>
        <vers num="2013" edition="sp1"/>
        <vers num="2016"/>
      </prod>
      <prod name="skype_for_business" vendor="microsoft">
        <vers num="2016"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2016"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0282" seq="2017-0282" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0284, CVE-2017-0285, and CVE-2017-8534.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98885" adv="1">98885</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0282" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0282</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42237/">42237</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0283" seq="2017-0283" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013 SP1, Skype for Business 2016, Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows, and Microsoft Silverlight 5 when installed on Microsoft Windows allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Uniscribe Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8528.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98920" adv="1">98920</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038675">1038675</ref>
      <ref source="MISC" url="https://0patch.blogspot.com/2017/07/0patching-quick-brown-fox-of-cve-2017.html">https://0patch.blogspot.com/2017/07/0patching-quick-brown-fox-of-cve-2017.html</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1198">https://bugs.chromium.org/p/project-zero/issues/detail?id=1198</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0283" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0283</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42234/">42234</ref>
    </refs>
    <vuln_soft>
      <prod name="lync" vendor="microsoft">
        <vers num="2013" edition="sp1"/>
      </prod>
      <prod name="office" vendor="microsoft">
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp2"/>
      </prod>
      <prod name="office_word_viewer" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="silverlight" vendor="microsoft">
        <vers num="5.0" edition=":~~~windows~~"/>
      </prod>
      <prod name="skype_for_business" vendor="microsoft">
        <vers num="2016"/>
      </prod>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0284" seq="2017-0284" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0282, CVE-2017-0285, and CVE-2017-8534.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98918" adv="1">98918</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0284" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0284</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42235/">42235</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0285" seq="2017-0285" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, and Microsoft Office Word Viewer allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0282, CVE-2017-0284, and CVE-2017-8534.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98914" adv="1">98914</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0285" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0285</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42236/">42236</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0286" seq="2017-0286" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0287, CVE-2017-0288, CVE-2017-0289, CVE-2017-8531, CVE-2017-8532, and CVE-2017-8533.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98891" adv="1">98891</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0286" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0286</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42238/">42238</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0287" seq="2017-0287" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0288, CVE-2017-0289, CVE-2017-8531, CVE-2017-8532, and CVE-2017-8533.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98922" adv="1">98922</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038662">1038662</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0287" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0287</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42239/">42239</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0288" seq="2017-0288" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0289, CVE-2017-8531, CVE-2017-8532, and CVE-2017-8533.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98923" adv="1">98923</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0288" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0288</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42241/">42241</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0289" seq="2017-0289" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Windows Graphics Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0288, CVE-2017-8531, CVE-2017-8532, and CVE-2017-8533.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98929" adv="1">98929</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038662">1038662</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0289" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0289</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42240/">42240</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0290" seq="2017-0290" published="2017-05-09" modified="2019-05-08" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98330" adv="1">98330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038419">1038419</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038420">1038420</ref>
      <ref source="MISC" url="https://0patch.blogspot.si/2017/05/0patching-worst-windows-remote-code.html">https://0patch.blogspot.si/2017/05/0patching-worst-windows-remote-code.html</ref>
      <ref source="MISC" url="https://arstechnica.com/information-technology/2017/05/windows-defender-nscript-remote-vulnerability/" adv="1">https://arstechnica.com/information-technology/2017/05/windows-defender-nscript-remote-vulnerability/</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1252" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1252</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0290" adv="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0290</ref>
      <ref source="CONFIRM" url="https://technet.microsoft.com/library/security/4022344" adv="1" patch="1">https://technet.microsoft.com/library/security/4022344</ref>
      <ref source="MISC" url="https://twitter.com/natashenka/status/861748397409058816" adv="1">https://twitter.com/natashenka/status/861748397409058816</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41975/">41975</ref>
    </refs>
    <vuln_soft>
      <prod name="forefront_security" vendor="microsoft">
        <vers num="-"/>
      </prod>
      <prod name="malware_protection_engine" vendor="microsoft">
        <vers num="1.1.13701.0" prev="1"/>
      </prod>
      <prod name="windows_defender" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0291" seq="2017-0291" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0292.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98835" adv="1">98835</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0291" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0291</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0292" seq="2017-0292" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0291.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98836" adv="1">98836</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038678">1038678</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0292" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0292</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="2013" edition="sp1:~~rt~~~"/>
        <vers num="2016"/>
      </prod>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0293" seq="2017-0293" published="2017-08-08" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows PDF Library in Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100039" adv="1">100039</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039092" adv="1">1039092</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0293" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0293</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0294" seq="2017-0294" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute remote code when Windows fails to properly handle cabinet files, aka "Windows Remote Code Execution Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98837" adv="1">98837</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0294" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0294</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_rt_8.1" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0295" seq="2017-0295" published="2017-06-14" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98904" adv="1">98904</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038674">1038674</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0295" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0295</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0296" seq="2017-0296" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to elevate privilege when tdx.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows TDX Elevation of Privilege Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98839" adv="1">98839</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0296" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0296</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0297" seq="2017-0297" published="2017-06-14" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0299, CVE-2017-0300.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98840" adv="1">98840</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038671">1038671</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0297" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0297</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0298" seq="2017-0298" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM Session Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98841" adv="1">98841</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0298" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0298</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-" edition="gold"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0299" seq="2017-0299" published="2017-06-14" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0300, and CVE-2017-0297.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98884" adv="1">98884</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038671">1038671</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0299" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0299</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42219/">42219</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="-"/>
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0300" seq="2017-0300" published="2017-06-14" modified="2017-08-11" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0299, and CVE-2017-0297.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98901" adv="1">98901</ref>
      <ref source="CONFIRM" url="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0300" adv="1" patch="1">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0300</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42244/">42244</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_10" vendor="microsoft">
        <vers num="1511"/>
        <vers num="1607"/>
        <vers num="1703"/>
      </prod>
      <prod name="windows_7" vendor="microsoft">
        <vers num="-" edition="sp1"/>
      </prod>
      <prod name="windows_8.1" vendor="microsoft">
        <vers num="rt"/>
      </prod>
      <prod name="windows_server_2008" vendor="microsoft">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod name="windows_server_2012" vendor="microsoft">
        <vers num="-"/>
        <vers num="r2"/>
      </prod>
      <prod name="windows_server_2016" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0301" seq="2017-0301" published="2017-12-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.5" CVSS_vector="(AV:A/AC:H/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM resources, however the application resources and backend servers are unaffected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040040" adv="1">1040040</ref>
      <ref source="CONFIRM" url="https://support.f5.com/csp/article/K54358225" adv="1">https://support.f5.com/csp/article/K54358225</ref>
    </refs>
    <vuln_soft>
      <prod name="big-ip_access_policy_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0302" seq="2017-0302" published="2017-05-09" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038408">1038408</ref>
      <ref source="CONFIRM" url="https://support.f5.com/csp/article/K87141725" adv="1">https://support.f5.com/csp/article/K87141725</ref>
    </refs>
    <vuln_soft>
      <prod name="big-ip_access_policy_manager" vendor="f5">
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0303" seq="2017-0303" published="2017-10-27" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2 and 11.5.1 to 11.6.1, under limited circumstances connections handled by a Virtual Server with an associated SOCKS profile may not be properly cleaned up, potentially leading to resource starvation. Connections may be left in the connection table which then can only be removed by restarting TMM. Over time this may lead to the BIG-IP being unable to process further connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101612" adv="1">101612</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039674" adv="1">1039674</ref>
      <ref source="CONFIRM" url="https://support.f5.com/csp/article/K30201296" adv="1">https://support.f5.com/csp/article/K30201296</ref>
    </refs>
    <vuln_soft>
      <prod name="big-ip_access_policy_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_advanced_firewall_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_application_acceleration_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_application_security_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_link_controller" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_local_traffic_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_policy_enforcement_manager" vendor="f5">
        <vers num="11.5.0"/>
        <vers num="11.5.1"/>
        <vers num="11.5.2"/>
        <vers num="11.5.3"/>
        <vers num="11.5.4"/>
        <vers num="11.5.5"/>
        <vers num="11.6.0"/>
        <vers num="11.6.1"/>
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
      <prod name="big-ip_websafe" vendor="f5">
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0304" seq="2017-0304" published="2017-12-21" modified="2018-01-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules. Traffic processing and the live firewall rules in use are not affected.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102332" adv="1">102332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040041" adv="1">1040041</ref>
      <ref source="CONFIRM" url="https://support.f5.com/csp/article/K39428424" adv="1">https://support.f5.com/csp/article/K39428424</ref>
    </refs>
    <vuln_soft>
      <prod name="big-ip_advanced_firewall_manager" vendor="f5">
        <vers num="12.0.0"/>
        <vers num="12.1.0"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="13.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0305" seq="2017-0305" published="2017-04-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://support.f5.com/csp/article/K53244431" adv="1">https://support.f5.com/csp/article/K53244431</ref>
    </refs>
    <vuln_soft>
      <prod name="ssl_intercept_iapp" vendor="f5">
        <vers num="1.5.0"/>
        <vers num="1.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0306" seq="2017-0306" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-34132950. References: N-CVE-2017-0306.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96723">96723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0307" seq="2017-0307" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33177895. References: N-CVE-2017-0307.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96809">96809</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0308" seq="2017-0308" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where untrusted input is used for buffer size calculation leading to denial of service or escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0309" seq="2017-0309" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause improper memory allocation leading to a denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0310" seq="2017-0310" published="2017-02-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0311" seq="2017-0311" published="2017-02-15" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service or possible escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0312" seq="2017-0312" published="2017-02-15" modified="2017-08-31" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x100008b where user provided input is used as the limit for a loop may lead to denial of service or potential escalation of privileges</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41364/">41364</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0313" seq="2017-0313" published="2017-02-15" modified="2017-08-31" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41365/">41365</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0314" seq="2017-0314" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0315" seq="2017-0315" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an attempt to access an invalid object pointer may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0316" seq="2017-0316" published="2017-10-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4560" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4560</ref>
    </refs>
    <vuln_soft>
      <prod name="geforce_experience" vendor="nvidia">
        <vers num="gfe_3.0"/>
        <vers num="gfe_3.0.6"/>
        <vers num="gfe_3.0.7"/>
        <vers num="gfe_3.1.0"/>
        <vers num="gfe_3.1.0.00"/>
        <vers num="gfe_3.1.2"/>
        <vers num="gfe_3.2.0"/>
        <vers num="gfe_3.2.2"/>
        <vers num="gfe_3.3.0"/>
        <vers num="gfe_3.4.0"/>
        <vers num="gfe_3.5.0"/>
        <vers num="gfe_3.6.0"/>
        <vers num="gfe_3.7.0"/>
        <vers num="gfe_3.8.0"/>
        <vers num="gfe_3.9.0"/>
        <vers num="gfe_3.10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0317" seq="2017-0317" published="2017-02-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted files, potentially leading to escalation of privileges via code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0318" seq="2017-0318" published="2017-02-15" modified="2017-02-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Linux GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper validation of an input parameter may cause a denial of service on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0319" seq="2017-0319" published="2017-02-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0320" seq="2017-0320" published="2017-02-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0321" seq="2017-0321" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0322" seq="2017-0322" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a value passed from a user to the driver is not correctly validated and used as the index to an array, leading to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0323" seq="2017-0323" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0324" seq="2017-0324" published="2017-02-15" modified="2017-02-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4398" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4398</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0325" seq="2017-0325" published="2017-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10 and Kernel 3.18. Android ID: A-33040280. References: N-CVE-2017-0325.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97350" adv="1">97350</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0326" seq="2017-0326" published="2017-07-07" modified="2017-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read function in the Tegra Display Controller driver could result in possible information disclosure. This issue is rated as Moderate. Product: Android. Version: N/A. Android ID: A-33718700. References: N-CVE-2017-0326.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99477" adv="1">99477</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0327" seq="2017-0327" published="2017-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33893669. References: N-CVE-2017-0327.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97333" adv="1">97333</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0328" seq="2017-0328" published="2017-04-05" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33898322. References: N-CVE-2017-0328.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97347" adv="1">97347</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0329" seq="2017-0329" published="2017-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local malicious application to execute arbitrary code within the context of the boot and power management processor. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.18. Android ID:A-34115304. References: N-CVE-2017-0329.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97353" adv="1">97353</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0330" seq="2017-0330" published="2017-04-05" modified="2019-04-02" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33899858. References: N-CVE-2017-0330.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97347" adv="1">97347</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://nvidia.custhelp.com/app/answers/detail/a_id/4787">https://nvidia.custhelp.com/app/answers/detail/a_id/4787</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0331" seq="2017-0331" published="2017-05-02" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel 3.10. Android ID: A-34113000. References: N-CVE-2017-0331.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98150" adv="1">98150</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0332" seq="2017-0332" published="2017-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33812508. References: N-CVE-2017-0332.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97333" adv="1">97333</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0333" seq="2017-0333" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33899363. References: N-CVE-2017-0333.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96723">96723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0334" seq="2017-0334" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33245849. References: N-CVE-2017-0334.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0335" seq="2017-0335" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33043375. References: N-CVE-2017-0335.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96723">96723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0336" seq="2017-0336" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33042679. References: N-CVE-2017-0336.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0337" seq="2017-0337" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-31992762. References: N-CVE-2017-0337.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96723">96723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0338" seq="2017-0338" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33057977. References: N-CVE-2017-0338.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96723">96723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0339" seq="2017-0339" published="2017-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-27930566. References: N-CVE-2017-0339.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97333" adv="1">97333</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0340" seq="2017-0340" published="2017-07-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer with a user-controlled size could lead to a memory corruption and possible remote code execution. This issue is rated as High. Product: Android. Version: N/A. Android ID: A-33968204. References: N-CVE-2017-0340.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99477" adv="1">99477</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0341" seq="2017-0341" published="2017-05-09" modified="2017-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0342" seq="2017-0342" published="2017-05-09" modified="2017-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0343" seq="2017-0343" published="2017-05-09" modified="2017-05-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0344" seq="2017-0344" published="2017-05-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0345" seq="2017-0345" published="2017-05-09" modified="2017-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0346" seq="2017-0346" published="2017-05-09" modified="2017-05-24" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98503">98503</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0347" seq="2017-0347" published="2017-05-09" modified="2017-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0348" seq="2017-0348" published="2017-05-09" modified="2017-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0349" seq="2017-0349" published="2017-05-09" modified="2017-05-24" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is not correctly validated before it is dereferenced for a write operation, may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98513">98513</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0350" seq="2017-0350" published="2017-05-09" modified="2017-06-04" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98490">98490</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0351" seq="2017-0351" published="2017-05-09" modified="2017-06-04" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98497">98497</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0352" seq="2017-0352" published="2017-05-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA GPU Display Driver contain a vulnerability in the GPU firmware where incorrect access control may allow CPU access sensitive GPU control registers, leading to an escalation of privileges</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98517">98517</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0353" seq="2017-0353" published="2017-05-09" modified="2017-05-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0354" seq="2017-0354" published="2017-05-09" modified="2017-05-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.7" CVSS_base_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where a call to certain function requiring lower IRQL can be made under raised IRQL which may lead to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0355" seq="2017-0355" published="2017-05-09" modified="2017-05-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access paged memory while holding a spinlock, leading to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4462" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4462</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98516">98516</ref>
    </refs>
    <vuln_soft>
      <prod name="gpu_driver" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0356" seq="2017-0356" published="2018-04-13" modified="2018-05-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95420" adv="1">95420</ref>
      <ref source="CONFIRM" url="https://ikiwiki.info/security/#cve-2017-0356" adv="1">https://ikiwiki.info/security/#cve-2017-0356</ref>
      <ref source="MLIST" url="https://marc.info/?l=oss-security&amp;m=148418234314276&amp;w=2" adv="1">[oss-security] 20170112 ikiwiki: CVE-2017-0356: Authentication bypass via repeated parameters</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3760" adv="1">DSA-3760</ref>
    </refs>
    <vuln_soft>
      <prod name="ikiwiki" vendor="ikiwiki">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.47"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.30"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="1.33.3"/>
        <vers num="1.34"/>
        <vers num="1.34.1"/>
        <vers num="1.34.2"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.50"/>
        <vers num="1.51"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
        <vers num="2.20"/>
        <vers num="2.30"/>
        <vers num="2.31"/>
        <vers num="2.31.1"/>
        <vers num="2.31.2"/>
        <vers num="2.31.3"/>
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
        <vers num="2.44"/>
        <vers num="2.45"/>
        <vers num="2.46"/>
        <vers num="2.47"/>
        <vers num="2.48"/>
        <vers num="2.49"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.53"/>
        <vers num="2.54"/>
        <vers num="2.55"/>
        <vers num="2.56"/>
        <vers num="2.60"/>
        <vers num="2.61"/>
        <vers num="2.62"/>
        <vers num="2.62.1"/>
        <vers num="2.63"/>
        <vers num="2.64"/>
        <vers num="2.65"/>
        <vers num="2.66"/>
        <vers num="2.67"/>
        <vers num="2.68"/>
        <vers num="2.69"/>
        <vers num="2.70"/>
        <vers num="2.71"/>
        <vers num="2.72"/>
        <vers num="3.0"/>
        <vers num="3.01"/>
        <vers num="3.02"/>
        <vers num="3.03"/>
        <vers num="3.04"/>
        <vers num="3.05"/>
        <vers num="3.06"/>
        <vers num="3.07"/>
        <vers num="3.08"/>
        <vers num="3.09"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.141"/>
        <vers num="3.1415"/>
        <vers num="3.14159"/>
        <vers num="3.141592"/>
        <vers num="3.1415926"/>
        <vers num="3.14159265"/>
        <vers num="3.20091009"/>
        <vers num="3.20091017"/>
        <vers num="3.20091022"/>
        <vers num="3.20091023"/>
        <vers num="3.20091031"/>
        <vers num="3.20091113"/>
        <vers num="3.20091202"/>
        <vers num="3.20091218"/>
        <vers num="3.20100102.3"/>
        <vers num="3.20100122"/>
        <vers num="3.20100212"/>
        <vers num="3.20100302"/>
        <vers num="3.20100312"/>
        <vers num="3.20100403"/>
        <vers num="3.20100427"/>
        <vers num="3.20100501"/>
        <vers num="3.20100504"/>
        <vers num="3.20100515"/>
        <vers num="3.20100518"/>
        <vers num="3.20100518.2"/>
        <vers num="3.20100610"/>
        <vers num="3.20100623"/>
        <vers num="3.20100722"/>
        <vers num="3.20100804"/>
        <vers num="3.20100815"/>
        <vers num="3.20100831"/>
        <vers num="3.20100926"/>
        <vers num="3.20101019"/>
        <vers num="3.20101023"/>
        <vers num="3.20101112"/>
        <vers num="3.20101129"/>
        <vers num="3.20101201"/>
        <vers num="3.20101231"/>
        <vers num="3.20110105"/>
        <vers num="3.20110123"/>
        <vers num="3.20110124"/>
        <vers num="3.20110225"/>
        <vers num="3.20110321"/>
        <vers num="3.20160121"/>
        <vers num="3.20161219"/>
        <vers num="3.20161229"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0357" seq="2017-0357" published="2018-04-13" modified="2018-05-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95432" adv="1">95432</ref>
      <ref source="CONFIRM" url="https://gitlab.com/iucode-tool/iucode-tool/issues/3" adv="1" patch="1">https://gitlab.com/iucode-tool/iucode-tool/issues/3</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0357" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0357</ref>
    </refs>
    <vuln_soft>
      <prod name="iucode-tool" vendor="iucode-tool_project">
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0358" seq="2017-0358" published="2018-04-13" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/02/04/1" adv="1">[oss-security] 20170203 Re: CVE-2017-0358 ntfs-3g: modprobe influence vulnerability via environment variables</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/95987" adv="1">95987</ref>
      <ref source="MLIST" url="https://marc.info/?l=oss-security&amp;m=148594671929354&amp;w=2" adv="1">[oss-security] 20170201 CVE-2017-0358 ntfs-3g: modprobe influence vulnerability via environment variables</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201702-10" adv="1">GLSA-201702-10</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3780">DSA-3780</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41240/" adv="1">41240</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41356/" adv="1">41356</ref>
    </refs>
    <vuln_soft>
      <prod name="ntfs-3g" vendor="tuxera">
        <vers num="2016.2.22" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0359" seq="2017-0359" published="2018-04-13" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.debian.org/854723" adv="1" patch="1">https://bugs.debian.org/854723</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0359" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0359</ref>
    </refs>
    <vuln_soft>
      <prod name="diffoscope" vendor="diffoscope">
        <vers num="77"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0360" seq="2017-0360" published="2017-04-04" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.tryton.org/trytond?cmd=changeset;node=472510fdc6f8">http://hg.tryton.org/trytond?cmd=changeset;node=472510fdc6f8</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3826">DSA-3826</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97489" adv="1">97489</ref>
      <ref source="CONFIRM" url="https://lists.debian.org/debian-security-announce/2017/msg00084.html" adv="1">https://lists.debian.org/debian-security-announce/2017/msg00084.html</ref>
    </refs>
    <vuln_soft>
      <prod name="tryton" vendor="tryton">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.8.14"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0361" seq="2017-0361" published="2018-04-13" modified="2018-05-14" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039812" adv="1">1039812</ref>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T125177" adv="1">https://phabricator.wikimedia.org/T125177</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0361" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0361</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0362" seq="2017-0362" published="2018-04-13" modified="2018-05-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T150044" adv="1">https://phabricator.wikimedia.org/T150044</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0362" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0362</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0363" seq="2017-0363" published="2018-04-13" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T109140" adv="1">https://phabricator.wikimedia.org/T109140</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0363" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0363</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0364" seq="2017-0364" published="2018-04-13" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T122209" adv="1">https://phabricator.wikimedia.org/T122209</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0364" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0364</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0365" seq="2017-0365" published="2018-04-13" modified="2018-05-14" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T144845" adv="1">https://phabricator.wikimedia.org/T144845</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0365" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0365</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0366" seq="2017-0366" published="2018-04-13" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T151735" adv="1">https://phabricator.wikimedia.org/T151735</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0366" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0366</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0367" seq="2017-0367" published="2018-04-13" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T161453" adv="1">https://phabricator.wikimedia.org/T161453</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0367" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0367</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0368" seq="2017-0368" published="2018-04-13" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T156184" adv="1">https://phabricator.wikimedia.org/T156184</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0368" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0368</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0369" seq="2017-0369" published="2018-04-13" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T108138" adv="1">https://phabricator.wikimedia.org/T108138</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0369" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0369</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0370" seq="2017-0370" published="2018-04-13" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T48143" adv="1">https://phabricator.wikimedia.org/T48143</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0370" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0370</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.0" edition="rc0"/>
        <vers num="1.23.0" edition="rc1"/>
        <vers num="1.23.0" edition="rc2"/>
        <vers num="1.23.0" edition="rc3"/>
        <vers num="1.23.1"/>
        <vers num="1.23.2"/>
        <vers num="1.23.3"/>
        <vers num="1.23.4"/>
        <vers num="1.23.5"/>
        <vers num="1.23.6"/>
        <vers num="1.23.7"/>
        <vers num="1.23.8"/>
        <vers num="1.23.9"/>
        <vers num="1.23.10"/>
        <vers num="1.23.11"/>
        <vers num="1.23.12"/>
        <vers num="1.23.13"/>
        <vers num="1.23.14"/>
        <vers num="1.23.15"/>
        <vers num="1.23.16"/>
        <vers num="1.27.0" edition="rc0"/>
        <vers num="1.27.0" edition="rc1"/>
        <vers num="1.27.1"/>
        <vers num="1.28.0" edition="rc0"/>
        <vers num="1.28.0" edition="rc1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0372" seq="2017-0372" published="2018-04-13" modified="2018-05-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.debian.org/861585" adv="1">https://bugs.debian.org/861585</ref>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html" adv="1" patch="1">[mediawiki-announce] 20170406 Security Release: 1.28.1 / 1.27.2 / 1.23.16</ref>
      <ref source="MLIST" url="https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.html" adv="1" patch="1">[mediawiki-announce] 20170430 Security release 1.27.3 and 1.28.2</ref>
      <ref source="CONFIRM" url="https://phabricator.wikimedia.org/T158689" adv="1">https://phabricator.wikimedia.org/T158689</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0372" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0372</ref>
    </refs>
    <vuln_soft>
      <prod name="mediawiki" vendor="mediawiki">
        <vers num="1.23.15" prev="1"/>
        <vers num="1.27.0"/>
        <vers num="1.27.1"/>
        <vers num="1.27.2"/>
        <vers num="1.28.0"/>
        <vers num="1.28.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0373" seq="2017-0373" published="2017-05-23" modified="2017-06-08" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cpansearch.perl.org/src/DDUMONT/Config-Model-2.102/Changes">http://cpansearch.perl.org/src/DDUMONT/Config-Model-2.102/Changes</ref>
      <ref source="CONFIRM" url="https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&amp;id=e7e5dd1a650939a0e021d1d5b311dbb3c4884773" patch="1">https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&amp;id=e7e5dd1a650939a0e021d1d5b311dbb3c4884773</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0373" adv="1">https://security-tracker.debian.org/tracker/CVE-2017-0373</ref>
    </refs>
    <vuln_soft>
      <prod name="config-model" vendor="config-model_project">
        <vers num="2.101" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0374" seq="2017-0374" published="2017-05-23" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://cpansearch.perl.org/src/DDUMONT/Config-Model-2.102/Changes">http://cpansearch.perl.org/src/DDUMONT/Config-Model-2.102/Changes</ref>
      <ref source="CONFIRM" url="https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&amp;id=0de8471e5a8958ad37446dfcd0362a269e3ec573" patch="1">https://anonscm.debian.org/cgit/pkg-perl/packages/libconfig-model-perl.git/commit/?h=stretch&amp;id=0de8471e5a8958ad37446dfcd0362a269e3ec573</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0374">https://security-tracker.debian.org/tracker/CVE-2017-0374</ref>
    </refs>
    <vuln_soft>
      <prod name="config-model" vendor="config-model_project">
        <vers num="2.101" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0375" seq="2017-0375" published="2017-06-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99017" adv="1">99017</ref>
      <ref source="CONFIRM" url="https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7" adv="1" patch="1">https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7</ref>
      <ref source="CONFIRM" url="https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.html" adv="1">https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.html</ref>
      <ref source="CONFIRM" url="https://trac.torproject.org/projects/tor/ticket/22493">https://trac.torproject.org/projects/tor/ticket/22493</ref>
    </refs>
    <vuln_soft>
      <prod name="tor" vendor="torproject">
        <vers num="0.0.2" edition="pre13"/>
        <vers num="0.0.2" edition="pre14"/>
        <vers num="0.0.2" edition="pre15"/>
        <vers num="0.0.2" edition="pre16"/>
        <vers num="0.0.2" edition="pre17"/>
        <vers num="0.0.2" edition="pre18"/>
        <vers num="0.0.2" edition="pre19"/>
        <vers num="0.0.2" edition="pre20"/>
        <vers num="0.0.2" edition="pre21"/>
        <vers num="0.0.2" edition="pre22"/>
        <vers num="0.0.2" edition="pre23"/>
        <vers num="0.0.2" edition="pre24"/>
        <vers num="0.0.2" edition="pre25"/>
        <vers num="0.0.2" edition="pre26"/>
        <vers num="0.0.2" edition="pre27"/>
        <vers num="0.0.2" edition="pre8"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.6.1"/>
        <vers num="0.0.6.2"/>
        <vers num="0.0.7"/>
        <vers num="0.0.7.1"/>
        <vers num="0.0.7.2"/>
        <vers num="0.0.7.3"/>
        <vers num="0.0.8" edition="pre1"/>
        <vers num="0.0.8" edition="pre2"/>
        <vers num="0.0.8" edition="pre3"/>
        <vers num="0.0.8" edition="rc1"/>
        <vers num="0.0.8" edition="rc2"/>
        <vers num="0.0.8.1"/>
        <vers num="0.0.9" edition="pre1"/>
        <vers num="0.0.9" edition="pre2"/>
        <vers num="0.0.9" edition="pre3"/>
        <vers num="0.0.9" edition="pre4"/>
        <vers num="0.0.9" edition="pre5"/>
        <vers num="0.0.9" edition="pre6"/>
        <vers num="0.0.9" edition="rc1"/>
        <vers num="0.0.9" edition="rc2"/>
        <vers num="0.0.9" edition="rc3"/>
        <vers num="0.0.9" edition="rc4"/>
        <vers num="0.0.9" edition="rc5"/>
        <vers num="0.0.9" edition="rc6"/>
        <vers num="0.0.9" edition="rc7"/>
        <vers num="0.0.9.1"/>
        <vers num="0.0.9.2"/>
        <vers num="0.0.9.3"/>
        <vers num="0.0.9.4"/>
        <vers num="0.0.9.5"/>
        <vers num="0.0.9.6"/>
        <vers num="0.0.9.7"/>
        <vers num="0.0.9.8"/>
        <vers num="0.0.9.9"/>
        <vers num="0.0.9.10"/>
        <vers num="0.1.0.1"/>
        <vers num="0.1.0.2"/>
        <vers num="0.1.0.4"/>
        <vers num="0.1.0.5"/>
        <vers num="0.1.0.6"/>
        <vers num="0.1.0.7"/>
        <vers num="0.1.0.9"/>
        <vers num="0.1.0.10"/>
        <vers num="0.1.0.11"/>
        <vers num="0.1.0.12"/>
        <vers num="0.1.0.13"/>
        <vers num="0.1.0.14"/>
        <vers num="0.1.0.15"/>
        <vers num="0.1.0.16"/>
        <vers num="0.1.0.17"/>
        <vers num="0.1.1.1" edition="alpha"/>
        <vers num="0.1.1.2" edition="alpha"/>
        <vers num="0.1.1.4" edition="alpha"/>
        <vers num="0.1.1.5" edition="alpha"/>
        <vers num="0.1.1.6" edition="alpha"/>
        <vers num="0.1.1.7" edition="alpha"/>
        <vers num="0.1.1.8" edition="alpha"/>
        <vers num="0.1.1.9" edition="alpha"/>
        <vers num="0.1.1.10" edition="alpha"/>
        <vers num="0.1.1.11" edition="alpha"/>
        <vers num="0.1.1.12" edition="alpha"/>
        <vers num="0.1.1.13" edition="alpha"/>
        <vers num="0.1.1.14" edition="alpha"/>
        <vers num="0.1.1.15"/>
        <vers num="0.1.1.16"/>
        <vers num="0.1.1.17"/>
        <vers num="0.1.1.18"/>
        <vers num="0.1.1.19"/>
        <vers num="0.1.1.20"/>
        <vers num="0.1.1.21"/>
        <vers num="0.1.1.22"/>
        <vers num="0.1.1.23"/>
        <vers num="0.1.1.24"/>
        <vers num="0.1.1.25"/>
        <vers num="0.1.1.26"/>
        <vers num="0.1.2.1" edition="alpha"/>
        <vers num="0.1.2.2" edition="alpha"/>
        <vers num="0.1.2.3" edition="alpha"/>
        <vers num="0.1.2.4" edition="alpha"/>
        <vers num="0.1.2.5" edition="alpha"/>
        <vers num="0.1.2.6" edition="alpha"/>
        <vers num="0.1.2.7" edition="alpha"/>
        <vers num="0.1.2.8" edition="beta"/>
        <vers num="0.1.2.9"/>
        <vers num="0.1.2.10"/>
        <vers num="0.1.2.11"/>
        <vers num="0.1.2.12"/>
        <vers num="0.1.2.13"/>
        <vers num="0.1.2.14"/>
        <vers num="0.1.2.15"/>
        <vers num="0.1.2.16"/>
        <vers num="0.1.2.17"/>
        <vers num="0.1.2.18"/>
        <vers num="0.1.2.19"/>
        <vers num="0.2.0.1" edition="alpha"/>
        <vers num="0.2.0.2" edition="alpha"/>
        <vers num="0.2.0.3" edition="alpha"/>
        <vers num="0.2.0.4" edition="alpha"/>
        <vers num="0.2.0.5" edition="alpha"/>
        <vers num="0.2.0.6" edition="alpha"/>
        <vers num="0.2.0.7" edition="alpha"/>
        <vers num="0.2.0.8" edition="alpha"/>
        <vers num="0.2.0.9" edition="alpha"/>
        <vers num="0.2.0.10" edition="alpha"/>
        <vers num="0.2.0.11" edition="alpha"/>
        <vers num="0.2.0.12" edition="alpha"/>
        <vers num="0.2.0.13" edition="alpha"/>
        <vers num="0.2.0.14" edition="alpha"/>
        <vers num="0.2.0.15" edition="alpha"/>
        <vers num="0.2.0.16" edition="alpha"/>
        <vers num="0.2.0.17" edition="alpha"/>
        <vers num="0.2.0.18" edition="alpha"/>
        <vers num="0.2.0.19" edition="alpha"/>
        <vers num="0.2.0.20"/>
        <vers num="0.2.0.21"/>
        <vers num="0.2.0.22"/>
        <vers num="0.2.0.23"/>
        <vers num="0.2.0.24"/>
        <vers num="0.2.0.25"/>
        <vers num="0.2.0.26"/>
        <vers num="0.2.0.27"/>
        <vers num="0.2.0.28"/>
        <vers num="0.2.0.29"/>
        <vers num="0.2.0.30"/>
        <vers num="0.2.0.31"/>
        <vers num="0.2.0.32"/>
        <vers num="0.2.0.33"/>
        <vers num="0.2.0.34"/>
        <vers num="0.2.0.35"/>
        <vers num="0.2.1.1" edition="alpha"/>
        <vers num="0.2.1.2" edition="alpha"/>
        <vers num="0.2.1.3" edition="alpha"/>
        <vers num="0.2.1.4" edition="alpha"/>
        <vers num="0.2.1.5" edition="alpha"/>
        <vers num="0.2.1.6" edition="alpha"/>
        <vers num="0.2.1.7" edition="alpha"/>
        <vers num="0.2.1.8" edition="alpha"/>
        <vers num="0.2.1.9" edition="alpha"/>
        <vers num="0.2.1.10" edition="alpha"/>
        <vers num="0.2.1.11" edition="alpha"/>
        <vers num="0.2.1.12" edition="alpha"/>
        <vers num="0.2.1.13" edition="alpha"/>
        <vers num="0.2.1.14"/>
        <vers num="0.2.1.15"/>
        <vers num="0.2.1.16"/>
        <vers num="0.2.1.17"/>
        <vers num="0.2.1.18"/>
        <vers num="0.2.1.19"/>
        <vers num="0.2.1.20"/>
        <vers num="0.2.1.21"/>
        <vers num="0.2.1.22"/>
        <vers num="0.2.1.23"/>
        <vers num="0.2.1.24"/>
        <vers num="0.2.1.25"/>
        <vers num="0.2.1.26"/>
        <vers num="0.2.1.27"/>
        <vers num="0.2.1.28"/>
        <vers num="0.2.1.29"/>
        <vers num="0.2.1.30"/>
        <vers num="0.2.1.31"/>
        <vers num="0.2.1.32"/>
        <vers num="0.2.2.1" edition="alpha"/>
        <vers num="0.2.2.2" edition="alpha"/>
        <vers num="0.2.2.3" edition="alpha"/>
        <vers num="0.2.2.4" edition="alpha"/>
        <vers num="0.2.2.5" edition="alpha"/>
        <vers num="0.2.2.6" edition="alpha"/>
        <vers num="0.2.2.7" edition="alpha"/>
        <vers num="0.2.2.8" edition="alpha"/>
        <vers num="0.2.2.9" edition="alpha"/>
        <vers num="0.2.2.10" edition="alpha"/>
        <vers num="0.2.2.11" edition="alpha"/>
        <vers num="0.2.2.12" edition="alpha"/>
        <vers num="0.2.2.13" edition="alpha"/>
        <vers num="0.2.2.14" edition="alpha"/>
        <vers num="0.2.2.15" edition="alpha"/>
        <vers num="0.2.2.16" edition="alpha"/>
        <vers num="0.2.2.17" edition="alpha"/>
        <vers num="0.2.2.18" edition="alpha"/>
        <vers num="0.2.2.19" edition="alpha"/>
        <vers num="0.2.2.20" edition="alpha"/>
        <vers num="0.2.2.21" edition="alpha"/>
        <vers num="0.2.2.22" edition="alpha"/>
        <vers num="0.2.2.23" edition="alpha"/>
        <vers num="0.2.2.24" edition="alpha"/>
        <vers num="0.2.2.25" edition="alpha"/>
        <vers num="0.2.2.26" edition="beta"/>
        <vers num="0.2.2.27" edition="beta"/>
        <vers num="0.2.2.28" edition="beta"/>
        <vers num="0.2.2.29" edition="beta"/>
        <vers num="0.2.2.30"/>
        <vers num="0.2.2.31"/>
        <vers num="0.2.2.32"/>
        <vers num="0.2.2.33"/>
        <vers num="0.2.2.34"/>
        <vers num="0.2.2.35"/>
        <vers num="0.2.2.36"/>
        <vers num="0.2.2.37"/>
        <vers num="0.2.2.38"/>
        <vers num="0.2.2.39"/>
        <vers num="0.2.3"/>
        <vers num="0.2.3.1" edition="alpha"/>
        <vers num="0.2.3.2" edition="alpha"/>
        <vers num="0.2.3.3" edition="alpha"/>
        <vers num="0.2.3.4" edition="alpha"/>
        <vers num="0.2.3.5" edition="alpha"/>
        <vers num="0.2.3.6" edition="alpha"/>
        <vers num="0.2.3.7" edition="alpha"/>
        <vers num="0.2.3.8" edition="alpha"/>
        <vers num="0.2.3.9" edition="alpha"/>
        <vers num="0.2.3.10" edition="alpha"/>
        <vers num="0.2.3.11" edition="alpha"/>
        <vers num="0.2.3.12" edition="alpha"/>
        <vers num="0.2.3.13" edition="alpha"/>
        <vers num="0.2.3.14" edition="alpha"/>
        <vers num="0.2.3.15" edition="alpha"/>
        <vers num="0.2.3.16" edition="alpha"/>
        <vers num="0.2.3.17" edition="beta"/>
        <vers num="0.2.3.18" edition="rc"/>
        <vers num="0.2.3.19" edition="rc"/>
        <vers num="0.2.3.20" edition="rc"/>
        <vers num="0.2.3.21" edition="rc"/>
        <vers num="0.2.3.22" edition="rc"/>
        <vers num="0.2.3.23" edition="rc"/>
        <vers num="0.2.3.24" edition="rc"/>
        <vers num="0.2.3.25"/>
        <vers num="0.2.4.1" edition="alpha"/>
        <vers num="0.2.4.2" edition="alpha"/>
        <vers num="0.2.4.3" edition="alpha"/>
        <vers num="0.2.4.4" edition="alpha"/>
        <vers num="0.2.4.5" edition="alpha"/>
        <vers num="0.2.4.6" edition="alpha"/>
        <vers num="0.2.4.7" edition="alpha"/>
        <vers num="0.2.4.8" edition="alpha"/>
        <vers num="0.2.4.9" edition="alpha"/>
        <vers num="0.2.4.10" edition="alpha"/>
        <vers num="0.2.4.11" edition="alpha"/>
        <vers num="0.2.4.12" edition="alpha"/>
        <vers num="0.2.4.13" edition="alpha"/>
        <vers num="0.2.4.14" edition="alpha"/>
        <vers num="0.2.4.15" edition="rc"/>
        <vers num="0.2.4.16" edition="rc"/>
        <vers num="0.2.4.17" edition="rc"/>
        <vers num="0.2.4.18" edition="rc"/>
        <vers num="0.2.4.19"/>
        <vers num="0.2.4.20"/>
        <vers num="0.2.4.21" edition="alpha"/>
        <vers num="0.2.4.22" edition="alpha"/>
        <vers num="0.2.4.23" edition="alpha"/>
        <vers num="0.2.4.24"/>
        <vers num="0.2.4.25"/>
        <vers num="0.2.4.26"/>
        <vers num="0.2.4.27"/>
        <vers num="0.2.4.28"/>
        <vers num="0.2.4.29"/>
        <vers num="0.2.5.1" edition="alpha"/>
        <vers num="0.2.5.2" edition="alpha"/>
        <vers num="0.2.5.3" edition="alpha"/>
        <vers num="0.2.5.4" edition="alpha"/>
        <vers num="0.2.5.5" edition="alpha"/>
        <vers num="0.2.5.6" edition="alpha"/>
        <vers num="0.2.5.7"/>
        <vers num="0.2.5.8"/>
        <vers num="0.2.5.9"/>
        <vers num="0.2.5.10"/>
        <vers num="0.2.5.11"/>
        <vers num="0.2.5.12"/>
        <vers num="0.2.5.13"/>
        <vers num="0.2.5.14"/>
        <vers num="0.2.6.1" edition="alpha"/>
        <vers num="0.2.6.2" edition="alpha"/>
        <vers num="0.2.6.3" edition="alpha"/>
        <vers num="0.2.6.4"/>
        <vers num="0.2.6.5"/>
        <vers num="0.2.6.6"/>
        <vers num="0.2.6.7"/>
        <vers num="0.2.6.8"/>
        <vers num="0.2.6.9"/>
        <vers num="0.2.6.10"/>
        <vers num="0.2.6.11"/>
        <vers num="0.2.6.12"/>
        <vers num="0.2.7.1" edition="alpha"/>
        <vers num="0.2.7.2" edition="alpha"/>
        <vers num="0.2.7.3"/>
        <vers num="0.2.7.4"/>
        <vers num="0.2.7.5"/>
        <vers num="0.2.7.6"/>
        <vers num="0.2.7.7"/>
        <vers num="0.2.7.8"/>
        <vers num="0.2.8.1" edition="alpha"/>
        <vers num="0.2.8.2" edition="alpha"/>
        <vers num="0.2.8.3" edition="alpha"/>
        <vers num="0.2.8.4"/>
        <vers num="0.2.8.5"/>
        <vers num="0.2.8.6"/>
        <vers num="0.2.8.7"/>
        <vers num="0.2.8.8"/>
        <vers num="0.2.8.9"/>
        <vers num="0.2.8.10"/>
        <vers num="0.2.8.11"/>
        <vers num="0.2.8.12"/>
        <vers num="0.2.8.13"/>
        <vers num="0.2.8.14"/>
        <vers num="0.2.9.0" edition="alpha"/>
        <vers num="0.2.9.1" edition="alpha"/>
        <vers num="0.2.9.2" edition="alpha"/>
        <vers num="0.2.9.3" edition="alpha"/>
        <vers num="0.2.9.4" edition="alpha"/>
        <vers num="0.2.9.5" edition="alpha"/>
        <vers num="0.2.9.6"/>
        <vers num="0.2.9.8"/>
        <vers num="0.2.9.9"/>
        <vers num="0.2.9.10"/>
        <vers num="0.2.9.11"/>
        <vers num="0.2.9.13"/>
        <vers num="0.2.9.14"/>
        <vers num="0.2.9.15"/>
        <vers num="0.2.9.16"/>
        <vers num="0.2.9.17"/>
        <vers num="0.3.0.0"/>
        <vers num="0.3.0.1" edition="-"/>
        <vers num="0.3.0.1" edition="alpha"/>
        <vers num="0.3.0.2" edition="alpha"/>
        <vers num="0.3.0.3" edition="alpha"/>
        <vers num="0.3.0.4" edition="rc"/>
        <vers num="0.3.0.5" edition="rc"/>
        <vers num="0.3.0.6"/>
        <vers num="0.3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0376" seq="2017-0376" published="2017-06-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3877" adv="1">DSA-3877</ref>
      <ref source="CONFIRM" url="https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcd" adv="1" patch="1">https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcd</ref>
      <ref source="CONFIRM" url="https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.html" adv="1">https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.html</ref>
      <ref source="CONFIRM" url="https://trac.torproject.org/projects/tor/ticket/22494" adv="1">https://trac.torproject.org/projects/tor/ticket/22494</ref>
    </refs>
    <vuln_soft>
      <prod name="tor" vendor="torproject">
        <vers num="0.0.2" edition="pre13"/>
        <vers num="0.0.2" edition="pre14"/>
        <vers num="0.0.2" edition="pre15"/>
        <vers num="0.0.2" edition="pre16"/>
        <vers num="0.0.2" edition="pre17"/>
        <vers num="0.0.2" edition="pre18"/>
        <vers num="0.0.2" edition="pre19"/>
        <vers num="0.0.2" edition="pre20"/>
        <vers num="0.0.2" edition="pre21"/>
        <vers num="0.0.2" edition="pre22"/>
        <vers num="0.0.2" edition="pre23"/>
        <vers num="0.0.2" edition="pre24"/>
        <vers num="0.0.2" edition="pre25"/>
        <vers num="0.0.2" edition="pre26"/>
        <vers num="0.0.2" edition="pre27"/>
        <vers num="0.0.2" edition="pre8"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.6.1"/>
        <vers num="0.0.6.2"/>
        <vers num="0.0.7"/>
        <vers num="0.0.7.1"/>
        <vers num="0.0.7.2"/>
        <vers num="0.0.7.3"/>
        <vers num="0.0.8" edition="pre1"/>
        <vers num="0.0.8" edition="pre2"/>
        <vers num="0.0.8" edition="pre3"/>
        <vers num="0.0.8" edition="rc1"/>
        <vers num="0.0.8" edition="rc2"/>
        <vers num="0.0.8.1"/>
        <vers num="0.0.9" edition="pre1"/>
        <vers num="0.0.9" edition="pre2"/>
        <vers num="0.0.9" edition="pre3"/>
        <vers num="0.0.9" edition="pre4"/>
        <vers num="0.0.9" edition="pre5"/>
        <vers num="0.0.9" edition="pre6"/>
        <vers num="0.0.9" edition="rc1"/>
        <vers num="0.0.9" edition="rc2"/>
        <vers num="0.0.9" edition="rc3"/>
        <vers num="0.0.9" edition="rc4"/>
        <vers num="0.0.9" edition="rc5"/>
        <vers num="0.0.9" edition="rc6"/>
        <vers num="0.0.9" edition="rc7"/>
        <vers num="0.0.9.1"/>
        <vers num="0.0.9.2"/>
        <vers num="0.0.9.3"/>
        <vers num="0.0.9.4"/>
        <vers num="0.0.9.5"/>
        <vers num="0.0.9.6"/>
        <vers num="0.0.9.7"/>
        <vers num="0.0.9.8"/>
        <vers num="0.0.9.9"/>
        <vers num="0.0.9.10"/>
        <vers num="0.1.0.1"/>
        <vers num="0.1.0.2"/>
        <vers num="0.1.0.4"/>
        <vers num="0.1.0.5"/>
        <vers num="0.1.0.6"/>
        <vers num="0.1.0.7"/>
        <vers num="0.1.0.9"/>
        <vers num="0.1.0.10"/>
        <vers num="0.1.0.11"/>
        <vers num="0.1.0.12"/>
        <vers num="0.1.0.13"/>
        <vers num="0.1.0.14"/>
        <vers num="0.1.0.15"/>
        <vers num="0.1.0.16"/>
        <vers num="0.1.0.17"/>
        <vers num="0.1.1.1" edition="alpha"/>
        <vers num="0.1.1.2" edition="alpha"/>
        <vers num="0.1.1.4" edition="alpha"/>
        <vers num="0.1.1.5" edition="alpha"/>
        <vers num="0.1.1.6" edition="alpha"/>
        <vers num="0.1.1.7" edition="alpha"/>
        <vers num="0.1.1.8" edition="alpha"/>
        <vers num="0.1.1.9" edition="alpha"/>
        <vers num="0.1.1.10" edition="alpha"/>
        <vers num="0.1.1.11" edition="alpha"/>
        <vers num="0.1.1.12" edition="alpha"/>
        <vers num="0.1.1.13" edition="alpha"/>
        <vers num="0.1.1.14" edition="alpha"/>
        <vers num="0.1.1.15"/>
        <vers num="0.1.1.16"/>
        <vers num="0.1.1.17"/>
        <vers num="0.1.1.18"/>
        <vers num="0.1.1.19"/>
        <vers num="0.1.1.20"/>
        <vers num="0.1.1.21"/>
        <vers num="0.1.1.22"/>
        <vers num="0.1.1.23"/>
        <vers num="0.1.1.24"/>
        <vers num="0.1.1.25"/>
        <vers num="0.1.1.26"/>
        <vers num="0.1.2.1" edition="alpha"/>
        <vers num="0.1.2.2" edition="alpha"/>
        <vers num="0.1.2.3" edition="alpha"/>
        <vers num="0.1.2.4" edition="alpha"/>
        <vers num="0.1.2.5" edition="alpha"/>
        <vers num="0.1.2.6" edition="alpha"/>
        <vers num="0.1.2.7" edition="alpha"/>
        <vers num="0.1.2.8" edition="beta"/>
        <vers num="0.1.2.9"/>
        <vers num="0.1.2.10"/>
        <vers num="0.1.2.11"/>
        <vers num="0.1.2.12"/>
        <vers num="0.1.2.13"/>
        <vers num="0.1.2.14"/>
        <vers num="0.1.2.15"/>
        <vers num="0.1.2.16"/>
        <vers num="0.1.2.17"/>
        <vers num="0.1.2.18"/>
        <vers num="0.1.2.19"/>
        <vers num="0.2.0.1" edition="alpha"/>
        <vers num="0.2.0.2" edition="alpha"/>
        <vers num="0.2.0.3" edition="alpha"/>
        <vers num="0.2.0.4" edition="alpha"/>
        <vers num="0.2.0.5" edition="alpha"/>
        <vers num="0.2.0.6" edition="alpha"/>
        <vers num="0.2.0.7" edition="alpha"/>
        <vers num="0.2.0.8" edition="alpha"/>
        <vers num="0.2.0.9" edition="alpha"/>
        <vers num="0.2.0.10" edition="alpha"/>
        <vers num="0.2.0.11" edition="alpha"/>
        <vers num="0.2.0.12" edition="alpha"/>
        <vers num="0.2.0.13" edition="alpha"/>
        <vers num="0.2.0.14" edition="alpha"/>
        <vers num="0.2.0.15" edition="alpha"/>
        <vers num="0.2.0.16" edition="alpha"/>
        <vers num="0.2.0.17" edition="alpha"/>
        <vers num="0.2.0.18" edition="alpha"/>
        <vers num="0.2.0.19" edition="alpha"/>
        <vers num="0.2.0.20"/>
        <vers num="0.2.0.21"/>
        <vers num="0.2.0.22"/>
        <vers num="0.2.0.23"/>
        <vers num="0.2.0.24"/>
        <vers num="0.2.0.25"/>
        <vers num="0.2.0.26"/>
        <vers num="0.2.0.27"/>
        <vers num="0.2.0.28"/>
        <vers num="0.2.0.29"/>
        <vers num="0.2.0.30"/>
        <vers num="0.2.0.31"/>
        <vers num="0.2.0.32"/>
        <vers num="0.2.0.33"/>
        <vers num="0.2.0.34"/>
        <vers num="0.2.0.35"/>
        <vers num="0.2.1.1" edition="alpha"/>
        <vers num="0.2.1.2" edition="alpha"/>
        <vers num="0.2.1.3" edition="alpha"/>
        <vers num="0.2.1.4" edition="alpha"/>
        <vers num="0.2.1.5" edition="alpha"/>
        <vers num="0.2.1.6" edition="alpha"/>
        <vers num="0.2.1.7" edition="alpha"/>
        <vers num="0.2.1.8" edition="alpha"/>
        <vers num="0.2.1.9" edition="alpha"/>
        <vers num="0.2.1.10" edition="alpha"/>
        <vers num="0.2.1.11" edition="alpha"/>
        <vers num="0.2.1.12" edition="alpha"/>
        <vers num="0.2.1.13" edition="alpha"/>
        <vers num="0.2.1.14"/>
        <vers num="0.2.1.15"/>
        <vers num="0.2.1.16"/>
        <vers num="0.2.1.17"/>
        <vers num="0.2.1.18"/>
        <vers num="0.2.1.19"/>
        <vers num="0.2.1.20"/>
        <vers num="0.2.1.21"/>
        <vers num="0.2.1.22"/>
        <vers num="0.2.1.23"/>
        <vers num="0.2.1.24"/>
        <vers num="0.2.1.25"/>
        <vers num="0.2.1.26"/>
        <vers num="0.2.1.27"/>
        <vers num="0.2.1.28"/>
        <vers num="0.2.1.29"/>
        <vers num="0.2.1.30"/>
        <vers num="0.2.1.31"/>
        <vers num="0.2.1.32"/>
        <vers num="0.2.2.1" edition="alpha"/>
        <vers num="0.2.2.2" edition="alpha"/>
        <vers num="0.2.2.3" edition="alpha"/>
        <vers num="0.2.2.4" edition="alpha"/>
        <vers num="0.2.2.5" edition="alpha"/>
        <vers num="0.2.2.6" edition="alpha"/>
        <vers num="0.2.2.7" edition="alpha"/>
        <vers num="0.2.2.8" edition="alpha"/>
        <vers num="0.2.2.9" edition="alpha"/>
        <vers num="0.2.2.10" edition="alpha"/>
        <vers num="0.2.2.11" edition="alpha"/>
        <vers num="0.2.2.12" edition="alpha"/>
        <vers num="0.2.2.13" edition="alpha"/>
        <vers num="0.2.2.14" edition="alpha"/>
        <vers num="0.2.2.15" edition="alpha"/>
        <vers num="0.2.2.16" edition="alpha"/>
        <vers num="0.2.2.17" edition="alpha"/>
        <vers num="0.2.2.18" edition="alpha"/>
        <vers num="0.2.2.19" edition="alpha"/>
        <vers num="0.2.2.20" edition="alpha"/>
        <vers num="0.2.2.21" edition="alpha"/>
        <vers num="0.2.2.22" edition="alpha"/>
        <vers num="0.2.2.23" edition="alpha"/>
        <vers num="0.2.2.24" edition="alpha"/>
        <vers num="0.2.2.25" edition="alpha"/>
        <vers num="0.2.2.26" edition="beta"/>
        <vers num="0.2.2.27" edition="beta"/>
        <vers num="0.2.2.28" edition="beta"/>
        <vers num="0.2.2.29" edition="beta"/>
        <vers num="0.2.2.30"/>
        <vers num="0.2.2.31"/>
        <vers num="0.2.2.32"/>
        <vers num="0.2.2.33"/>
        <vers num="0.2.2.34"/>
        <vers num="0.2.2.35"/>
        <vers num="0.2.2.36"/>
        <vers num="0.2.2.37"/>
        <vers num="0.2.2.38"/>
        <vers num="0.2.2.39"/>
        <vers num="0.2.3"/>
        <vers num="0.2.3.1" edition="alpha"/>
        <vers num="0.2.3.2" edition="alpha"/>
        <vers num="0.2.3.3" edition="alpha"/>
        <vers num="0.2.3.4" edition="alpha"/>
        <vers num="0.2.3.5" edition="alpha"/>
        <vers num="0.2.3.6" edition="alpha"/>
        <vers num="0.2.3.7" edition="alpha"/>
        <vers num="0.2.3.8" edition="alpha"/>
        <vers num="0.2.3.9" edition="alpha"/>
        <vers num="0.2.3.10" edition="alpha"/>
        <vers num="0.2.3.11" edition="alpha"/>
        <vers num="0.2.3.12" edition="alpha"/>
        <vers num="0.2.3.13" edition="alpha"/>
        <vers num="0.2.3.14" edition="alpha"/>
        <vers num="0.2.3.15" edition="alpha"/>
        <vers num="0.2.3.16" edition="alpha"/>
        <vers num="0.2.3.17" edition="beta"/>
        <vers num="0.2.3.18" edition="rc"/>
        <vers num="0.2.3.19" edition="rc"/>
        <vers num="0.2.3.20" edition="rc"/>
        <vers num="0.2.3.21" edition="rc"/>
        <vers num="0.2.3.22" edition="rc"/>
        <vers num="0.2.3.23" edition="rc"/>
        <vers num="0.2.3.24" edition="rc"/>
        <vers num="0.2.3.25"/>
        <vers num="0.2.4.1" edition="alpha"/>
        <vers num="0.2.4.2" edition="alpha"/>
        <vers num="0.2.4.3" edition="alpha"/>
        <vers num="0.2.4.4" edition="alpha"/>
        <vers num="0.2.4.5" edition="alpha"/>
        <vers num="0.2.4.6" edition="alpha"/>
        <vers num="0.2.4.7" edition="alpha"/>
        <vers num="0.2.4.8" edition="alpha"/>
        <vers num="0.2.4.9" edition="alpha"/>
        <vers num="0.2.4.10" edition="alpha"/>
        <vers num="0.2.4.11" edition="alpha"/>
        <vers num="0.2.4.12" edition="alpha"/>
        <vers num="0.2.4.13" edition="alpha"/>
        <vers num="0.2.4.14" edition="alpha"/>
        <vers num="0.2.4.15" edition="rc"/>
        <vers num="0.2.4.16" edition="rc"/>
        <vers num="0.2.4.17" edition="rc"/>
        <vers num="0.2.4.18" edition="rc"/>
        <vers num="0.2.4.19"/>
        <vers num="0.2.4.20"/>
        <vers num="0.2.4.21" edition="alpha"/>
        <vers num="0.2.4.22" edition="alpha"/>
        <vers num="0.2.4.23" edition="alpha"/>
        <vers num="0.2.4.24"/>
        <vers num="0.2.4.25"/>
        <vers num="0.2.4.26"/>
        <vers num="0.2.4.27"/>
        <vers num="0.2.4.28"/>
        <vers num="0.2.4.29"/>
        <vers num="0.2.5.1" edition="alpha"/>
        <vers num="0.2.5.2" edition="alpha"/>
        <vers num="0.2.5.3" edition="alpha"/>
        <vers num="0.2.5.4" edition="alpha"/>
        <vers num="0.2.5.5" edition="alpha"/>
        <vers num="0.2.5.6" edition="alpha"/>
        <vers num="0.2.5.7"/>
        <vers num="0.2.5.8"/>
        <vers num="0.2.5.9"/>
        <vers num="0.2.5.10"/>
        <vers num="0.2.5.11"/>
        <vers num="0.2.5.12"/>
        <vers num="0.2.5.13"/>
        <vers num="0.2.5.14"/>
        <vers num="0.2.6.1" edition="alpha"/>
        <vers num="0.2.6.2" edition="alpha"/>
        <vers num="0.2.6.3" edition="alpha"/>
        <vers num="0.2.6.4"/>
        <vers num="0.2.6.5"/>
        <vers num="0.2.6.6"/>
        <vers num="0.2.6.7"/>
        <vers num="0.2.6.8"/>
        <vers num="0.2.6.9"/>
        <vers num="0.2.6.10"/>
        <vers num="0.2.6.11"/>
        <vers num="0.2.6.12"/>
        <vers num="0.2.7.1" edition="alpha"/>
        <vers num="0.2.7.2" edition="alpha"/>
        <vers num="0.2.7.3"/>
        <vers num="0.2.7.4"/>
        <vers num="0.2.7.5"/>
        <vers num="0.2.7.6"/>
        <vers num="0.2.7.7"/>
        <vers num="0.2.7.8"/>
        <vers num="0.2.8.1" edition="alpha"/>
        <vers num="0.2.8.2" edition="alpha"/>
        <vers num="0.2.8.3" edition="alpha"/>
        <vers num="0.2.8.4"/>
        <vers num="0.2.8.5"/>
        <vers num="0.2.8.6"/>
        <vers num="0.2.8.7"/>
        <vers num="0.2.8.8"/>
        <vers num="0.2.8.9"/>
        <vers num="0.2.8.10"/>
        <vers num="0.2.8.11"/>
        <vers num="0.2.8.12"/>
        <vers num="0.2.8.13"/>
        <vers num="0.2.8.14"/>
        <vers num="0.2.9.0" edition="alpha"/>
        <vers num="0.2.9.1" edition="alpha"/>
        <vers num="0.2.9.2" edition="alpha"/>
        <vers num="0.2.9.3" edition="alpha"/>
        <vers num="0.2.9.4" edition="alpha"/>
        <vers num="0.2.9.5" edition="alpha"/>
        <vers num="0.2.9.6"/>
        <vers num="0.2.9.8"/>
        <vers num="0.2.9.9"/>
        <vers num="0.2.9.10"/>
        <vers num="0.2.9.11"/>
        <vers num="0.2.9.13"/>
        <vers num="0.2.9.14"/>
        <vers num="0.2.9.15"/>
        <vers num="0.2.9.16"/>
        <vers num="0.2.9.17"/>
        <vers num="0.3.0.0"/>
        <vers num="0.3.0.1" edition="-"/>
        <vers num="0.3.0.1" edition="alpha"/>
        <vers num="0.3.0.2" edition="alpha"/>
        <vers num="0.3.0.3" edition="alpha"/>
        <vers num="0.3.0.4" edition="rc"/>
        <vers num="0.3.0.5" edition="rc"/>
        <vers num="0.3.0.6"/>
        <vers num="0.3.0.7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0377" seq="2017-0377" published="2017-07-02" modified="2017-07-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://blog.torproject.org/blog/tor-0309-released-security-update-clients" adv="1">https://blog.torproject.org/blog/tor-0309-released-security-update-clients</ref>
      <ref source="CONFIRM" url="https://blog.torproject.org/blog/tor-0314-alpha-released-security-update-clients" adv="1">https://blog.torproject.org/blog/tor-0314-alpha-released-security-update-clients</ref>
      <ref source="CONFIRM" url="https://github.com/torproject/tor/commit/665baf5ed5c6186d973c46cdea165c0548027350" adv="1" patch="1">https://github.com/torproject/tor/commit/665baf5ed5c6186d973c46cdea165c0548027350</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/CVE-2017-0377" adv="1">https://security-tracker.debian.org/CVE-2017-0377</ref>
      <ref source="CONFIRM" url="https://trac.torproject.org/projects/tor/ticket/22753" adv="1">https://trac.torproject.org/projects/tor/ticket/22753</ref>
    </refs>
    <vuln_soft>
      <prod name="tor" vendor="torproject">
        <vers num="0.3.0.1" edition="alpha"/>
        <vers num="0.3.0.2" edition="alpha"/>
        <vers num="0.3.0.3" edition="alpha"/>
        <vers num="0.3.0.4"/>
        <vers num="0.3.0.5"/>
        <vers num="0.3.0.6"/>
        <vers num="0.3.0.7"/>
        <vers num="0.3.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0378" seq="2017-0378" published="2017-07-20" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.openwall.com/lists/oss-security/2017/07/20/3" adv="1">http://www.openwall.com/lists/oss-security/2017/07/20/3</ref>
      <ref source="CONFIRM" url="http://www.phamm.org/docs/CHANGELOG" adv="1">http://www.phamm.org/docs/CHANGELOG</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99927" adv="1">99927</ref>
      <ref source="CONFIRM" url="https://bugs.debian.org/868988" adv="1">https://bugs.debian.org/868988</ref>
      <ref source="CONFIRM" url="https://github.com/lota/phamm/issues/21" adv="1">https://github.com/lota/phamm/issues/21</ref>
    </refs>
    <vuln_soft>
      <prod name="phamm" vendor="phamm">
        <vers num="0.6.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0379" seq="2017-0379" published="2017-08-29" modified="2019-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html">http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100503" adv="1">100503</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1041294">1041294</ref>
      <ref source="MISC" url="https://bugs.debian.org/873383" adv="1">https://bugs.debian.org/873383</ref>
      <ref source="MISC" url="https://eprint.iacr.org/2017/806" adv="1">https://eprint.iacr.org/2017/806</ref>
      <ref source="MISC" url="https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b" adv="1" patch="1">https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=da780c8183cccc8f533c8ace8211ac2cb2bdee7b</ref>
      <ref source="MISC" url="https://lists.debian.org/debian-security-announce/2017/msg00221.html" adv="1" patch="1">https://lists.debian.org/debian-security-announce/2017/msg00221.html</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180726-0002/">https://security.netapp.com/advisory/ntap-20180726-0002/</ref>
      <ref source="MISC" url="https://security-tracker.debian.org/tracker/CVE-2017-0379" adv="1" patch="1">https://security-tracker.debian.org/tracker/CVE-2017-0379</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3959" adv="1" patch="1">DSA-3959</ref>
      <ref source="CONFIRM" url="https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html">https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html</ref>
    </refs>
    <vuln_soft>
      <prod name="libgcrypt" vendor="gnupg">
        <vers num="1.8.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0380" seq="2017-0380" published="2017-09-18" modified="2017-11-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3993">DSA-3993</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039519">1039519</ref>
      <ref source="CONFIRM" url="https://github.com/torproject/tor/commit/09ea89764a4d3a907808ed7d4fe42abfe64bd486" adv="1" patch="1">https://github.com/torproject/tor/commit/09ea89764a4d3a907808ed7d4fe42abfe64bd486</ref>
      <ref source="CONFIRM" url="https://trac.torproject.org/projects/tor/ticket/23490" adv="1" patch="1">https://trac.torproject.org/projects/tor/ticket/23490</ref>
    </refs>
    <vuln_soft>
      <prod name="tor" vendor="torproject">
        <vers num="0.2.8.14" prev="1"/>
        <vers num="0.2.9.0" edition="alpha"/>
        <vers num="0.2.9.1" edition="alpha"/>
        <vers num="0.2.9.2" edition="alpha"/>
        <vers num="0.2.9.3" edition="alpha"/>
        <vers num="0.2.9.4" edition="alpha"/>
        <vers num="0.2.9.5" edition="alpha"/>
        <vers num="0.2.9.6"/>
        <vers num="0.2.9.8"/>
        <vers num="0.2.9.9"/>
        <vers num="0.2.9.10"/>
        <vers num="0.2.9.11"/>
        <vers num="0.3.0.0"/>
        <vers num="0.3.0.1" edition="alpha"/>
        <vers num="0.3.0.2" edition="alpha"/>
        <vers num="0.3.0.3" edition="alpha"/>
        <vers num="0.3.0.4" edition="rc"/>
        <vers num="0.3.0.5" edition="rc"/>
        <vers num="0.3.0.6"/>
        <vers num="0.3.0.7"/>
        <vers num="0.3.0.8"/>
        <vers num="0.3.0.9"/>
        <vers num="0.3.0.10"/>
        <vers num="0.3.1.1" edition="alpha"/>
        <vers num="0.3.1.2" edition="alpha"/>
        <vers num="0.3.1.3" edition="alpha"/>
        <vers num="0.3.1.4" edition="alpha"/>
        <vers num="0.3.1.5" edition="alpha"/>
        <vers num="0.3.1.6" edition="alpha"/>
        <vers num="0.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0381" seq="2017-0381" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31607432.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95248">95248</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039427">1039427</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libopus/+/0d052d64480a30e83fcdda80f4774624e044beb7" patch="1">https://android.googlesource.com/platform/external/libopus/+/0d052d64480a30e83fcdda80f4774624e044beb7</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201702-21">GLSA-201702-21</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113">https://support.apple.com/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208115">https://support.apple.com/HT208115</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208144">https://support.apple.com/HT208144</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0382" seq="2017-0382" published="2017-01-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32338390.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95247" adv="1">95247</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0383" seq="2017-0383" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1. Android ID: A-31677614.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95243" adv="1">95243</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0384" seq="2017-0384" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32095626.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95239" adv="1">95239</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/321ea5257e37c8edb26e66fe4ee78cca4cd915fe" patch="1">https://android.googlesource.com/platform/frameworks/av/+/321ea5257e37c8edb26e66fe4ee78cca4cd915fe</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0385" seq="2017-0385" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32585400.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95239" adv="1">95239</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0386" seq="2017-0386" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95256" adv="1">95256</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0387" seq="2017-0387" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32660278.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95258" adv="1">95258</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0388" seq="2017-0388" published="2017-01-12" modified="2017-01-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95252">95252</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0389" seq="2017-0389" published="2017-01-12" modified="2017-01-17" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31850211.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95251">95251</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0390" seq="2017-0390" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31647370.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95230" adv="1">95230</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/tremolo/+/5dc99237d49e73c27d3eca54f6ccd97d13f94de0" patch="1">https://android.googlesource.com/platform/external/tremolo/+/5dc99237d49e73c27d3eca54f6ccd97d13f94de0</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0391" seq="2017-0391" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32322258.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95230" adv="1">95230</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/a33f6725d7e9f92330f995ce2dcf4faa33f6433f" patch="1">https://android.googlesource.com/platform/external/libhevc/+/a33f6725d7e9f92330f995ce2dcf4faa33f6433f</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0392" seq="2017-0392" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95230" adv="1">95230</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/453b351ac5bd2b6619925dc966da60adf6b3126c" patch="1">https://android.googlesource.com/platform/frameworks/av/+/453b351ac5bd2b6619925dc966da60adf6b3126c</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0393" seq="2017-0393" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95230" adv="1">95230</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libvpx/+/6886e8e0a9db2dbad723dc37a548233e004b33bc" patch="1">https://android.googlesource.com/platform/external/libvpx/+/6886e8e0a9db2dbad723dc37a548233e004b33bc</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0394" seq="2017-0394" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Telephony could enable a remote attacker to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31752213.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95255" adv="1">95255</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0395" seq="2017-0395" published="2017-01-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Contacts could enable a local malicious application to silently create contact information. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32219099.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95261" adv="1">95261</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0396" seq="2017-0396" published="2017-01-12" modified="2017-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31781965.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95232" adv="1">95232</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/557bd7bfe6c4895faee09e46fc9b5304a956c8b7" patch="1">https://android.googlesource.com/platform/frameworks/av/+/557bd7bfe6c4895faee09e46fc9b5304a956c8b7</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0397" seq="2017-0397" published="2017-01-12" modified="2017-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32377688.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95232" adv="1">95232</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/7a3246b870ddd11861eda2ab458b11d723c7f62c" patch="1">https://android.googlesource.com/platform/frameworks/av/+/7a3246b870ddd11861eda2ab458b11d723c7f62c</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0398" seq="2017-0398" published="2017-01-13" modified="2017-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-32635664.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95226">95226</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0399" seq="2017-0399" published="2017-01-12" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32588756.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95226" adv="1">95226</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac" patch="1">https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0400" seq="2017-0400" published="2017-01-12" modified="2019-05-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32584034.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95226" adv="1">95226</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac" patch="1">https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0401" seq="2017-0401" published="2017-01-12" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32588016.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95226" adv="1">95226</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/321ea5257e37c8edb26e66fe4ee78cca4cd915fe" patch="1">https://android.googlesource.com/platform/frameworks/av/+/321ea5257e37c8edb26e66fe4ee78cca4cd915fe</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0402" seq="2017-0402" published="2017-01-12" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32436341.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95226" adv="1">95226</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac" patch="1">https://android.googlesource.com/platform/frameworks/av/+/c66c43ad571ed2590dcd55a762c73c90d9744bac</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/hardware/qcom/audio/+/d72ea85c78a1a68bf99fd5804ad9784b4102fe57" patch="1">https://android.googlesource.com/platform/hardware/qcom/audio/+/d72ea85c78a1a68bf99fd5804ad9784b4102fe57</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0403" seq="2017-0403" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95274">95274</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0404" seq="2017-0404" published="2017-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95281">95281</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-01-01.html" adv="1">https://source.android.com/security/bulletin/2017-01-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0405" seq="2017-0405" published="2017-02-08" modified="2017-07-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Surfaceflinger process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-31960359.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96048" adv="1">96048</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0406" seq="2017-0406" published="2017-02-08" modified="2017-07-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32915871.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96046" adv="1">96046</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0407" seq="2017-0407" published="2017-02-08" modified="2017-07-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32873375.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96046" adv="1">96046</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0408" seq="2017-0408" published="2017-02-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-32769670.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96092" adv="1">96092</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0409" seq="2017-0409" published="2017-02-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31999646.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96091" adv="1">96091</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0410" seq="2017-0410" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31929765.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96056">96056</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0411" seq="2017-0411" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33042690.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96056" adv="1">96056</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41354/">41354</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0412" seq="2017-0412" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33039926.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96056" adv="1">96056</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41355/">41355</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0413" seq="2017-0413" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32161610.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96063" adv="1">96063</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0414" seq="2017-0414" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32807795.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96063" adv="1">96063</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0415" seq="2017-0415" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32706020.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96089" adv="1">96089</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0416" seq="2017-0416" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32886609.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96055" adv="1">96055</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0417" seq="2017-0417" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32705438.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96055" adv="1">96055</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0418" seq="2017-0418" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32703959.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96055" adv="1">96055</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0419" seq="2017-0419" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32220769.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96055" adv="1">96055</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0420" seq="2017-0420" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32615212.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96093" adv="1">96093</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0421" seq="2017-0421" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32555637.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96096" adv="1">96096</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0422" seq="2017-0422" published="2017-02-08" modified="2017-07-24" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322088.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96097" adv="1">96097</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0423" seq="2017-0423" published="2017-02-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.9" CVSS_base_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96102" adv="1">96102</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0424" seq="2017-0424" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense in depth or exploit mitigation technology in a privileged process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322450.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96104" adv="1">96104</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0425" seq="2017-0425" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96106" adv="1">96106</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0426" seq="2017-0426" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32799236.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96099" adv="1">96099</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0427" seq="2017-0427" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495866.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96071" adv="1">96071</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0428" seq="2017-0428" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32401526. References: N-CVE-2017-0428.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96070" adv="1">96070</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0429" seq="2017-0429" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32636619. References: N-CVE-2017-0429.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96070" adv="1">96070</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0430" seq="2017-0430" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32838767. References: B-RB#107459.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96065" adv="1">96065</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0431" seq="2017-0431" published="2018-04-05" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32573899.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96068" adv="1">96068</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798" adv="1">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0432" seq="2017-0432" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-28332719.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96067" adv="1">96067</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0433" seq="2017-0433" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913571.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96061" adv="1">96061</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="MISC" url="https://alephsecurity.com/vulns/aleph-2016001">https://alephsecurity.com/vulns/aleph-2016001</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0434" seq="2017-0434" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33001936.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96061" adv="1">96061</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0435" seq="2017-0435" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31906657. References: QC-CR#1078000.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96053">96053</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0436" seq="2017-0436" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32624661. References: QC-CR#1078000.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96053" adv="1">96053</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0437" seq="2017-0437" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402310. References: QC-CR#1092497.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0438" seq="2017-0438" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402604. References: QC-CR#1092497.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0439" seq="2017-0439" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32450647. References: QC-CR#1092059.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/out-bounds-write-wifi-driver-function-hddextscanpasspointfillnetworklist-cve-2017-0439">https://www.codeaurora.org/out-bounds-write-wifi-driver-function-hddextscanpasspointfillnetworklist-cve-2017-0439</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0440" seq="2017-0440" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33252788. References: QC-CR#1095770.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0441" seq="2017-0441" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32872662. References: QC-CR#1095009.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/possible-integer-overflow-buffer-overflow-qcanl80211vendorsubcmdextscansetsignificantchange-cve-2017">https://www.codeaurora.org/possible-integer-overflow-buffer-overflow-qcanl80211vendorsubcmdextscansetsignificantchange-cve-2017</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0442" seq="2017-0442" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32871330. References: QC-CR#1092497.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0443" seq="2017-0443" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877494. References: QC-CR#1092497.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96047" adv="1">96047</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/out-bounds-write-wlan-driver-function-wlanhddcfg80211setextroamparams-cve-2017-0443">https://www.codeaurora.org/out-bounds-write-wlan-driver-function-wlanhddcfg80211setextroamparams-cve-2017-0443</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0444" seq="2017-0444" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-32705232.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96107" adv="1">96107</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0445" seq="2017-0445" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32769717.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96054" adv="1">96054</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0446" seq="2017-0446" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32917445.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96054" adv="1">96054</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0447" seq="2017-0447" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32919560.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96054" adv="1">96054</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0448" seq="2017-0448" published="2017-02-08" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-32721029. References: N-CVE-2017-0448.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96105" adv="1">96105</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0449" seq="2017-0449" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10. Android ID: A-31707909. References: B-RB#32094.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96110" adv="1">96110</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0450" seq="2017-0450" published="2017-02-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96109" adv="1">96109</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0451" seq="2017-0451" published="2017-02-08" modified="2017-07-24" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31796345. References: QC-CR#1073129.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96108" adv="1">96108</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037798">1037798</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-02-01.html" adv="1">https://source.android.com/security/bulletin/2017-02-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0452" seq="2017-0452" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-32873615. References: QC-CR#1093693.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96836">96836</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0453" seq="2017-0453" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33979145. References: QC-CR#1105085.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96735">96735</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=05af1f34723939f477cb7d25adb320d016d68513" patch="1">https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=05af1f34723939f477cb7d25adb320d016d68513</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0454" seq="2017-0454" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm audio driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33353700. References: QC-CR#1104067.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97399">97399</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0455" seq="2017-0455" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code within the context of the bootloader. This issue is rated as High because it is a general bypass for a bootloader level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-32370952. References: QC-CR#1082755.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96812">96812</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=2c00928b4884fdb0b1661bcc530d7e68c9561a2f" patch="1">https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=2c00928b4884fdb0b1661bcc530d7e68c9561a2f</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0456" seq="2017-0456" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm IPA driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33106520. References: QC-CR#1099598.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96947">96947</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0457" seq="2017-0457" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31695439. References: QC-CR#1086123, QC-CR#1100695.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96803">96803</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0458" seq="2017-0458" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32588962. References: QC-CR#1089433.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96951">96951</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=eba46cb98431ba1d7a6bd859f26f6ad03f1bf4d4" patch="1">https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=eba46cb98431ba1d7a6bd859f26f6ad03f1bf4d4</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0459" seq="2017-0459" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32644895. References: QC-CR#1091939.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96743">96743</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?h=rel/msm-3.18&amp;id=ffacf6e2dc41b6063c3564791ed7a2f903e7e3b7" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?h=rel/msm-3.18&amp;id=ffacf6e2dc41b6063c3564791ed7a2f903e7e3b7</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0460" seq="2017-0460" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm networking driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31252965. References: QC-CR#1098801.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96948">96948</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/out-memory-and-out-bounds-vulnerability-while-handling-netlink-messages-cve-2017-0460">https://www.codeaurora.org/out-memory-and-out-bounds-vulnerability-while-handling-netlink-messages-cve-2017-0460</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0461" seq="2017-0461" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32073794. References: QC-CR#1100132.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96743">96743</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=ce5d6f84420a2e6ca6aad6b866992970dd313a65" patch="1">https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=ce5d6f84420a2e6ca6aad6b866992970dd313a65</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0462" seq="2017-0462" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Seemp driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33353601. References: QC-CR#1102288.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0463" seq="2017-0463" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm networking driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33277611. References: QC-CR#1101792.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96948">96948</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=955bd7e7ac097bdffbadafab90e5378038fefeb2" patch="1">https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=955bd7e7ac097bdffbadafab90e5378038fefeb2</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0464" seq="2017-0464" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32940193. References: QC-CR#1102593.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96735">96735</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=051597a4fe19fd1292fb7ea2e627d12d1fd2934f" patch="1">https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=051597a4fe19fd1292fb7ea2e627d12d1fd2934f</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0465" seq="2017-0465" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34112914. References: QC-CR#1110747.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98184" adv="1">98184</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0466" seq="2017-0466" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33139050.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0467" seq="2017-0467" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33250932.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0468" seq="2017-0468" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33351708.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0469" seq="2017-0469" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33450635.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0470" seq="2017-0470" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818500.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0471" seq="2017-0471" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33816782.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0472" seq="2017-0472" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33862021.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0473" seq="2017-0473" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33982658.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0474" seq="2017-0474" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32589224.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96717">96717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0475" seq="2017-0475" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31914369.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96716">96716</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0476" seq="2017-0476" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in AOSP Messaging could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of an unprivileged process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33388925.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96756">96756</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0477" seq="2017-0477" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-33621647.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96760">96760</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0478" seq="2017-0478" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33718716.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96762">96762</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="MISC" url="https://github.com/JiounDai/CVE-2017-0478">https://github.com/JiounDai/CVE-2017-0478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0479" seq="2017-0479" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32707507.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96958">96958</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0480" seq="2017-0480" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32705429.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96958">96958</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0481" seq="2017-0481" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33434992.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96765">96765</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96953">96953</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0482" seq="2017-0482" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33090864.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0483" seq="2017-0483" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33137046.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0484" seq="2017-0484" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33298089.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0485" seq="2017-0485" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33387820.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0486" seq="2017-0486" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33621215.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0487" seq="2017-0487" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33751193.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0488" seq="2017-0488" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097213.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96733">96733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0489" seq="2017-0489" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96792">96792</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0490" seq="2017-0490" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delete user data. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33178389.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96790">96790</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0491" seq="2017-0491" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32553261.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96791">96791</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0492" seq="2017-0492" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 7.1.1. Android ID: A-30150688.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96794">96794</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0493" seq="2017-0493" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32793550.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98140" adv="1">98140</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0494" seq="2017-0494" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32764144.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96789">96789</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0495" seq="2017-0495" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33552073.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96796">96796</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0496" seq="2017-0496" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-31554152.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96788">96788</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0497" seq="2017-0497" published="2017-03-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.4" CVSS_base_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33300701.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96795">96795</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0498" seq="2017-0498" published="2017-03-07" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Setup Wizard could allow a local attacker to require Google account sign-in after a factory reset. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30352311.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96793">96793</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0499" seq="2017-0499" published="2017-03-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32095713.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96806">96806</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0500" seq="2017-0500" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28429685. References: M-ALPS02710006.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0501" seq="2017-0501" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28430015. References: M-ALPS02708983.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0502" seq="2017-0502" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28430164. References: M-ALPS02710027.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0503" seq="2017-0503" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28449045. References: M-ALPS02710075.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0504" seq="2017-0504" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30074628. References: M-ALPS02829371.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0505" seq="2017-0505" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-31822282. References: M-ALPS02992041.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0506" seq="2017-0506" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-32276718. References: M-ALPS03006904.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96726">96726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0507" seq="2017-0507" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31992382.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96952">96952</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0508" seq="2017-0508" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33940449.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96952">96952</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0509" seq="2017-0509" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-32124445. References: B-RB#110688.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/94943">94943</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96797">96797</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0510" seq="2017-0510" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96800">96800</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="MISC" url="https://alephsecurity.com/2017/03/08/nexus9-fiq-debugger/">https://alephsecurity.com/2017/03/08/nexus9-fiq-debugger/</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0516" seq="2017-0516" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm input hardware driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32341680. References: QC-CR#1096301.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96802">96802</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0517" seq="2017-0517" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek hardware sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-32372051. References: M-ALPS02973195.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96799">96799</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0518" seq="2017-0518" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32370896. References: QC-CR#1086530.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96950">96950</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0519" seq="2017-0519" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32372915. References: QC-CR#1086530.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96950">96950</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0520" seq="2017-0520" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31750232. References: QC-CR#1082636.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96804">96804</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=eb2aad752c43f57e88ab9b0c3c5ee7b976ee31dd" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=eb2aad752c43f57e88ab9b0c3c5ee7b976ee31dd</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0521" seq="2017-0521" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32919951. References: QC-CR#1097709.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96951">96951</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=dbe4f26f200db10deaf38676b96d8738afcc10c8" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=dbe4f26f200db10deaf38676b96d8738afcc10c8</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0522" seq="2017-0522" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High due to the possibility of local arbitrary code execution in a privileged process. Product: Android. Versions: N/A. Android ID: A-32916158. References: M-ALPS03032516.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96798">96798</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0523" seq="2017-0523" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-32835279. References: QC-CR#1096945.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96735">96735</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=5bb646471da76d3d5cd02cf3da7a03ce6e3cb582" adv="1" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=5bb646471da76d3d5cd02cf3da7a03ce6e3cb582</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0524" seq="2017-0524" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33002026.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96808">96808</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0525" seq="2017-0525" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm IPA driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33139056. References: QC-CR#1097714.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96947">96947</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/use-after-free-vulnerability-during-ipa-routing-commit-logic-cve-2017-0525">https://www.codeaurora.org/use-after-free-vulnerability-during-ipa-routing-commit-logic-cve-2017-0525</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0526" seq="2017-0526" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC Sensor Hub Driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33897738.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96949">96949</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0527" seq="2017-0527" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC Sensor Hub Driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33899318.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96949">96949</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0528" seq="2017-0528" published="2017-03-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel security subsystem could enable a local malicious application to to execute code in the context of a privileged process. This issue is rated as High because it is a general bypass for a kernel level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-33351919.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96807">96807</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0529" seq="2017-0529" published="2017-03-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-28449427. References: M-ALPS02710042.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96810">96810</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0531" seq="2017-0531" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877245. References: QC-CR#1087469.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96743">96743</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=530f3a0fd837ed105eddaf99810bc13d97dc4302" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=530f3a0fd837ed105eddaf99810bc13d97dc4302</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0532" seq="2017-0532" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the MediaTek video codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-32370398. References: M-ALPS03069985.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96834">96834</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0533" seq="2017-0533" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32509422. References: QC-CR#1088206.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96734">96734</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3af5e89426f1c8d4e703d415eff5435b925649f" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3af5e89426f1c8d4e703d415eff5435b925649f</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0534" seq="2017-0534" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32508732. References: QC-CR#1088206.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96734">96734</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3af5e89426f1c8d4e703d415eff5435b925649f" patch="1">https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3af5e89426f1c8d4e703d415eff5435b925649f</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0535" seq="2017-0535" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96833">96833</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0536" seq="2017-0536" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33555878.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96835">96835</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0537" seq="2017-0537" published="2017-03-07" modified="2017-07-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the kernel USB gadget driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-31614969.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96831">96831</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037968">1037968</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-03-01">https://source.android.com/security/bulletin/2017-03-01</ref>
      <ref source="MISC" url="https://source.android.com/security/bulletin/2017-03-01.html" adv="1" patch="1">https://source.android.com/security/bulletin/2017-03-01.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0538" seq="2017-0538" published="2017-04-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33641588.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/494561291a503840f385fbcd11d9bc5f4dc502b8" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/494561291a503840f385fbcd11d9bc5f4dc502b8</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0539" seq="2017-0539" published="2017-04-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33864300.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/1ab5ce7e42feccd49e49752e6f58f9097ac5d254" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/1ab5ce7e42feccd49e49752e6f58f9097ac5d254</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0540" seq="2017-0540" published="2017-04-07" modified="2017-07-12" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33966031.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/01ca88bb6c5bdd44e071f8effebe12f1d7da9853" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/01ca88bb6c5bdd44e071f8effebe12f1d7da9853</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0541" seq="2017-0541" published="2017-04-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34031018.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/sonivox/+/56d153259cc3e16a6a0014199a2317dde333c978" adv="1" patch="1">https://android.googlesource.com/platform/external/sonivox/+/56d153259cc3e16a6a0014199a2317dde333c978</ref>
      <ref source="MISC" url="https://github.com/JiounDai/CVE-2017-0541">https://github.com/JiounDai/CVE-2017-0541</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0542" seq="2017-0542" published="2017-04-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33934721.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/33ef7de9ddc8ea7eb9cbc440d1cf89957a0c267b" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/33ef7de9ddc8ea7eb9cbc440d1cf89957a0c267b</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0543" seq="2017-0543" published="2017-04-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097866.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97330" adv="1">97330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/f634481e940421020e52f511c1fb34aac1db4b2f" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/f634481e940421020e52f511c1fb34aac1db4b2f</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0544" seq="2017-0544" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code. This issue is rated as High because it is a local arbitrary code execution in a privileged process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31992879.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97337" adv="1">97337</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0545" seq="2017-0545" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32591350.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97346" adv="1">97346</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0546" seq="2017-0546" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32628763.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97341" adv="1">97341</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0547" seq="2017-0547" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33861560.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97338" adv="1">97338</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/9667e3eff2d34c3797c3b529370de47b2c1f1bf6" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/9667e3eff2d34c3797c3b529370de47b2c1f1bf6</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0548" seq="2017-0548" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33251605.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97398" adv="1">97398</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0549" seq="2017-0549" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818508.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97336" adv="1">97336</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/37345554fea84afd446d6d8fbb87feea5a0dde3f" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/37345554fea84afd446d6d8fbb87feea5a0dde3f</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0550" seq="2017-0550" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33933140.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97336" adv="1">97336</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/7950bf47b6944546a0aff11a7184947de9591b51" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/7950bf47b6944546a0aff11a7184947de9591b51</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0551" seq="2017-0551" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097231.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97336" adv="1">97336</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/494561291a503840f385fbcd11d9bc5f4dc502b8" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/494561291a503840f385fbcd11d9bc5f4dc502b8</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/8b5fd8f24eba5dd19ab2f80ea11a9125aa882ae2" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/8b5fd8f24eba5dd19ab2f80ea11a9125aa882ae2</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0552" seq="2017-0552" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097915.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97336" adv="1">97336</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/9a00f562a612d56e7b2b989d168647db900ba6cf" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/9a00f562a612d56e7b2b989d168647db900ba6cf</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0553" seq="2017-0553" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb">http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb</ref>
      <ref source="MLIST" url="http://lists.infradead.org/pipermail/libnl/2017-May/002313.html">[libnl] 20170503 ANN: libnl 3.3.0 released</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97340" adv="1">97340</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-3311-2">USN-3311-2</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2299">RHSA-2017:2299</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6VCF5KS6HOJZLFIY2ZSXSVSDQX65A2PU/">FEDORA-2017-7a5363b41d</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KIHASXRQO2YTQPKVP4VGIB2XHPANG6YX/">FEDORA-2017-34f6e70fdd</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/usn/usn-3311-1/">USN-3311-1</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0554" seq="2017-0554" published="2017-04-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33815946.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97343" adv="1">97343</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0555" seq="2017-0555" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33551775.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97332" adv="1">97332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/0b23c81c3dd9ec38f7e6806a3955fed1925541a0" adv="1">https://android.googlesource.com/platform/external/libavc/+/0b23c81c3dd9ec38f7e6806a3955fed1925541a0</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0556" seq="2017-0556" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093952.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97332" adv="1">97332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libmpeg2/+/f301cff2c1ddd880d9a2c77b22602a137519867b" adv="1" patch="1">https://android.googlesource.com/platform/external/libmpeg2/+/f301cff2c1ddd880d9a2c77b22602a137519867b</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0557" seq="2017-0557" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97332" adv="1">97332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libmpeg2/+/227c1f829127405e21dab1664393050c652ef71e" adv="1" patch="1">https://android.googlesource.com/platform/external/libmpeg2/+/227c1f829127405e21dab1664393050c652ef71e</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0558" seq="2017-0558" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34056274.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97332" adv="1">97332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/50358a80b1724f6cf1bcdf003e1abf9cc141b122" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/50358a80b1724f6cf1bcdf003e1abf9cc141b122</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0559" seq="2017-0559" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33897722.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97352" adv="1">97352</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0560" seq="2017-0560" published="2017-04-07" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30681079.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97360" adv="1">97360</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0561" seq="2017-0561" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199105. References: B-RB#110814.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97367" adv="1">97367</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/11/msg00015.html">[debian-lts-announce] 20181113 [SECURITY] [DLA 1573-1] firmware-nonfree security update</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41805/">41805</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41806/">41806</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0562" seq="2017-0562" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30202425. References: M-ALPS02898189.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97345" adv="1">97345</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0563" seq="2017-0563" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32089409.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/May/19">http://seclists.org/fulldisclosure/2017/May/19</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97342">97342</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="MISC" url="https://alephsecurity.com/vulns/aleph-2017009">https://alephsecurity.com/vulns/aleph-2017009</ref>
      <ref source="MISC" url="https://github.com/alephsecurity/PoCs/tree/master/CVE-2017-0563">https://github.com/alephsecurity/PoCs/tree/master/CVE-2017-0563</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0564" seq="2017-0564" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34276203.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97344">97344</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0565" seq="2017-0565" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175904. References: M-ALPS02696516.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97349" adv="1">97349</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0566" seq="2017-0566" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28470975. References: M-ALPS02696367.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97351" adv="1">97351</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0567" seq="2017-0567" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32125310. References: B-RB#112575.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0568" seq="2017-0568" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34197514. References: B-RB#112600.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0569" seq="2017-0569" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#110666.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41808/">41808</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0570" seq="2017-0570" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199963. References: B-RB#110688.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0571" seq="2017-0571" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34203305. References: B-RB#111541.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0572" seq="2017-0572" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-34198931. References: B-RB#112597.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0573" seq="2017-0573" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34469904. References: B-RB#91539.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0574" seq="2017-0574" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34624457. References: B-RB#113189.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97331">97331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0575" seq="2017-0575" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32658595. References: QC-CR#1103099.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97403">97403</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0576" seq="2017-0576" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97395">97395</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="MISC" url="https://github.com/derrekr/android_security/commit/0dd1a733e60cf5239c0a185d4219ba2ef1118a8b">https://github.com/derrekr/android_security/commit/0dd1a733e60cf5239c0a185d4219ba2ef1118a8b</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0577" seq="2017-0577" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33842951.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97348">97348</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0578" seq="2017-0578" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the DTS sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-33964406.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97358" adv="1">97358</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0579" seq="2017-0579" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34125463. References: QC-CR#1115406.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97339">97339</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0580" seq="2017-0580" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Synaptics Touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34325986.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97335">97335</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0581" seq="2017-0581" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Synaptics Touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34614485.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97335">97335</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0582" seq="2017-0582" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC OEM fastboot command could enable a local malicious application to execute arbitrary code within the context of the sensor hub. This issue is rated as Moderate because it first requires exploitation of separate vulnerabilities. Product: Android. Versions: Kernel-3.10. Android ID: A-33178836.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97356" adv="1">97356</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0583" seq="2017-0583" published="2017-04-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm CP access driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of vulnerability specific details which limit the impact of the issue. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32068683. References: QC-CR#1103788.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97368">97368</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0584" seq="2017-0584" published="2017-04-07" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32074353. References: QC-CR#1104731.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97363" adv="1">97363</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0585" seq="2017-0585" published="2017-04-07" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32475556. References: B-RB#112953.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97366" adv="1">97366</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0586" seq="2017-0586" published="2017-04-07" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33649808. References: QC-CR#1097569.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97357" adv="1">97357</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038201">1038201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-04-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0587" seq="2017-0587" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35219737.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98119" adv="1">98119</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libmpeg2/+/a86eb798d077b9b25c8f8c77e3c02c2f287c1ce7" adv="1" patch="1">https://android.googlesource.com/platform/external/libmpeg2/+/a86eb798d077b9b25c8f8c77e3c02c2f287c1ce7</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0588" seq="2017-0588" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34618607.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98120" adv="1">98120</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/6f1d990ce0f116a205f467d9eb2082795e33872b" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/6f1d990ce0f116a205f467d9eb2082795e33872b</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0589" seq="2017-0589" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34897036.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98122" adv="1">98122</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/bcfc7124f6ef9f1ec128fb2e90de774a5b33d199" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/bcfc7124f6ef9f1ec128fb2e90de774a5b33d199</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0590" seq="2017-0590" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35039946.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98123" adv="1">98123</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/45c97f878bee15cd97262fe7f57ecea71990fed7" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/45c97f878bee15cd97262fe7f57ecea71990fed7</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0591" seq="2017-0591" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34097672.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98124" adv="1">98124</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libavc/+/5c3fd5d93a268abb20ff22f26009535b40db3c7d" adv="1" patch="1">https://android.googlesource.com/platform/external/libavc/+/5c3fd5d93a268abb20ff22f26009535b40db3c7d</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0592" seq="2017-0592" published="2017-05-12" modified="2017-05-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34970788.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98125" adv="1">98125</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/acc192347665943ca674acf117e4f74a88436922" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/acc192347665943ca674acf117e4f74a88436922</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0593" seq="2017-0593" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114230.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98126" adv="1">98126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0594" seq="2017-0594" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34617444.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98128" adv="1">98128</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/594bf934384920618d2b6ce0bcda1f60144cb3eb" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/594bf934384920618d2b6ce0bcda1f60144cb3eb</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0595" seq="2017-0595" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34705519.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98129" adv="1">98129</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0596" seq="2017-0596" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34749392.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98130" adv="1">98130</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0597" seq="2017-0597" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34749571.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98131" adv="1">98131</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0598" seq="2017-0598" published="2017-05-12" modified="2017-05-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34128677.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98133" adv="1">98133</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0599" seq="2017-0599" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34672748.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98134" adv="1">98134</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/a1424724a00d62ac5efa0e27953eed66850d662f" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/a1424724a00d62ac5efa0e27953eed66850d662f</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0600" seq="2017-0600" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35269635.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/961e5ac5788b52304e64b9a509781beaf5201fb0" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/961e5ac5788b52304e64b9a509781beaf5201fb0</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0601" seq="2017-0601" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98137" adv="1">98137</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0602" seq="2017-0602" published="2017-05-12" modified="2017-05-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98141" adv="1">98141</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0603" seq="2017-0603" published="2017-05-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.4" CVSS_base_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35763994.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98143" adv="1">98143</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/36b04932bb93cc3269279282686b439a17a89920" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/36b04932bb93cc3269279282686b439a17a89920</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0604" seq="2017-0604" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-35392981. References: QC-CR#826589.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98151">98151</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0605" seq="2017-0605" published="2017-05-12" modified="2017-10-03" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-0606" seq="2017-0606" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34088848. References: QC-CR#1116015.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98168" adv="1">98168</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0607" seq="2017-0607" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-35400551. References: QC-CR#1085928.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98171" adv="1">98171</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0608" seq="2017-0608" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35400458. References: QC-CR#1098363.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98172" adv="1">98172</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0609" seq="2017-0609" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35399801. References: QC-CR#1090482.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98174" adv="1">98174</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0610" seq="2017-0610" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35399404. References: QC-CR#1094852.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98255" adv="1">98255</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0611" seq="2017-0611" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35393841. References: QC-CR#1084210.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98177" adv="1">98177</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0612" seq="2017-0612" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-34389303. References: QC-CR#1061845.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98231" adv="1">98231</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0613" seq="2017-0613" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35400457. References: QC-CR#1086140.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98186" adv="1">98186</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0614" seq="2017-0614" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35399405. References: QC-CR#1080290.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98187" adv="1">98187</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0615" seq="2017-0615" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34259126. References: M-ALPS03150278.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98188" adv="1">98188</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0616" seq="2017-0616" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek system management interrupt driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34470286. References: M-ALPS03149160.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98189" adv="1">98189</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0617" seq="2017-0617" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34471002. References: M-ALPS03149173.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98190" adv="1">98190</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0618" seq="2017-0618" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-35100728. References: M-ALPS03161536.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98191">98191</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0619" seq="2017-0619" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm pin controller driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-35401152. References: QC-CR#826566.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98192">98192</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0620" seq="2017-0620" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35401052. References: QC-CR#1081711.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98193" adv="1">98193</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0621" seq="2017-0621" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-35399703. References: QC-CR#831322.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98196" adv="1">98196</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0622" seq="2017-0622" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-32749036. References: QC-CR#1098602.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98198" adv="1">98198</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0623" seq="2017-0623" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32512358.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98199" adv="1">98199</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0624" seq="2017-0624" published="2017-05-12" modified="2017-05-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34327795. References: QC-CR#2005832.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98200" adv="1">98200</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0625" seq="2017-0625" published="2017-05-12" modified="2017-05-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-35142799. References: M-ALPS03161531.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98201">98201</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0626" seq="2017-0626" published="2017-05-12" modified="2017-05-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35393124. References: QC-CR#1088050.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98202" adv="1">98202</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0627" seq="2017-0627" published="2017-05-12" modified="2018-06-15" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33300353.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98205" adv="1">98205</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3674-1/">USN-3674-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3674-2/">USN-3674-2</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0628" seq="2017-0628" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34230377. References: QC-CR#1086833.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98211" adv="1">98211</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0629" seq="2017-0629" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35214296. References: QC-CR#1086833.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98212" adv="1">98212</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0630" seq="2017-0630" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98213" adv="1">98213</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0631" seq="2017-0631" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35399756. References: QC-CR#1093232.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98216" adv="1">98216</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0632" seq="2017-0632" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-35392586. References: QC-CR#832915.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98221" adv="1">98221</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0633" seq="2017-0633" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious component to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-36000515. References: B-RB#117131.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98223" adv="1">98223</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0634" seq="2017-0634" published="2017-05-12" modified="2017-05-19" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32511682.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98224" adv="1">98224</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0635" seq="2017-0635" published="2017-05-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35467107.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/523f6b49c1a2289161f40cf9fe80b92e592e9441" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/523f6b49c1a2289161f40cf9fe80b92e592e9441</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-05-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-05-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0636" seq="2017-0636" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-35310230. References: M-ALPS03162263.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98866" adv="1">98866</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0637" seq="2017-0637" published="2017-06-14" modified="2017-07-07" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process.Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34064500.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/ebaa71da6362c497310377df509651974401d258" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/ebaa71da6362c497310377df509651974401d258</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0638" seq="2017-0638" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code execution in an unprivileged process. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36368305.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98872" adv="1">98872</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0639" seq="2017-0639" published="2017-06-14" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35310991.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98871" adv="1">98871</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0640" seq="2017-0640" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33129467.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0641" seq="2017-0641" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libvpx/+/698796fc930baecf5c3fdebef17e73d5d9a58bcb" adv="1">https://android.googlesource.com/platform/external/libvpx/+/698796fc930baecf5c3fdebef17e73d5d9a58bcb</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0642" seq="2017-0642" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34819017.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/913d9e8d93d6b81bb8eac3fc2c1426651f5b259d" adv="1">https://android.googlesource.com/platform/external/libhevc/+/913d9e8d93d6b81bb8eac3fc2c1426651f5b259d</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0643" seq="2017-0643" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-35645051.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0644" seq="2017-0644" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-35472997.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98868" adv="1">98868</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0645" seq="2017-0645" published="2017-06-14" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35385327.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98871" adv="1">98871</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0646" seq="2017-0646" published="2017-06-14" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33899337.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98871" adv="1">98871</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0647" seq="2017-0647" published="2017-06-14" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36392138.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98877" adv="1">98877</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0648" seq="2017-0648" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-36101220.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98875" adv="1">98875</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0649" seq="2017-0649" published="2017-06-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of vulnerability specific details which limit the impact of the issue. Product: Android. Versions: N/A. Android ID: A-34468195. References: M-ALPS03162283.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98866" adv="1">98866</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0650" seq="2017-0650" published="2017-06-14" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35472278.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.10"/>
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0651" seq="2017-0651" published="2017-06-14" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the kernel ION subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-35644815.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98875" adv="1">98875</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0663" seq="2017-0663" published="2017-06-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3952">DSA-3952</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98877" adv="1">98877</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038623">1038623</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-01">GLSA-201711-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-06-01" adv="1">https://source.android.com/security/bulletin/2017-06-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0664" seq="2017-0664" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0665" seq="2017-0665" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0666" seq="2017-0666" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0667" seq="2017-0667" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37478824.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0668" seq="2017-0668" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-22011579.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0669" seq="2017-0669" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114752.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0670" seq="2017-0670" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36104177.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99470" adv="1">99470</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0671" seq="2017-0671" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android libraries. Product: Android. Versions: 4.4.4. Android ID: A-34514762.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0672" seq="2017-0672" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android libraries. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-34778578.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0673" seq="2017-0673" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33974623.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0674" seq="2017-0674" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231163.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0675" seq="2017-0675" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0676" seq="2017-0676" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34896431.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0677" seq="2017-0677" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36035074.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0678" seq="2017-0678" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0679" seq="2017-0679" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36996978.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0680" seq="2017-0680" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37008096.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0681" seq="2017-0681" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37208566.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0682" seq="2017-0682" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36588422.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0683" seq="2017-0683" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36591008.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0684" seq="2017-0684" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0685" seq="2017-0685" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34203195.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0686" seq="2017-0686" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231231.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0687" seq="2017-0687" published="2017-08-18" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35583675.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0688" seq="2017-0688" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35584425.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0689" seq="2017-0689" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36215950.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0690" seq="2017-0690" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36592202.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0691" seq="2017-0691" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0692" seq="2017-0692" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0693" seq="2017-0693" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36993291.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0694" seq="2017-0694" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37093318.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0695" seq="2017-0695" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37094889.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0696" seq="2017-0696" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207120.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0697" seq="2017-0697" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37239013.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0698" seq="2017-0698" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35467458.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0699" seq="2017-0699" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490809.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99478" adv="1">99478</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0700" seq="2017-0700" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99472" adv="1">99472</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0701" seq="2017-0701" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36385715.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99472" adv="1">99472</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0702" seq="2017-0702" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36621442.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99472" adv="1">99472</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0703" seq="2017-0703" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99472" adv="1">99472</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0704" seq="2017-0704" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-33059280.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99472" adv="1">99472</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0705" seq="2017-0705" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99482" adv="1">99482</ref>
      <ref source="MISC" url="https://github.com/ScottyBauer/Android_Kernel_CVE_POCs/blob/master/CVE-2017-0705.c">https://github.com/ScottyBauer/Android_Kernel_CVE_POCs/blob/master/CVE-2017-0705.c</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0706" seq="2017-0706" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99482" adv="1">99482</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0707" seq="2017-0707" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the HTC led driver. Product: Android. Versions: Android kernel. Android ID: A-36088467.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99474" adv="1">99474</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0708" seq="2017-0708" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99474" adv="1">99474</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0709" seq="2017-0709" published="2017-07-06" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99474" adv="1">99474</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0710" seq="2017-0710" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Upstream Linux tcb. Product: Android. Versions: Android kernel. Android ID: A-34951864.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99468" adv="1">99468</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0711" seq="2017-0711" published="2017-07-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99466" adv="1">99466</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-07-01" adv="1">https://source.android.com/security/bulletin/2017-07-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0712" seq="2017-0712" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100220" adv="1">100220</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0713" seq="2017-0713" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100219" adv="1">100219</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0714" seq="2017-0714" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0715" seq="2017-0715" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36998372.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0716" seq="2017-0716" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37203196.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0718" seq="2017-0718" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0719" seq="2017-0719" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0720" seq="2017-0720" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0721" seq="2017-0721" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37561455.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0722" seq="2017-0722" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0723" seq="2017-0723" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37968755.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0724" seq="2017-0724" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36819262.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0725" seq="2017-0725" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0726" seq="2017-0726" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36389123.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0727" seq="2017-0727" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0728" seq="2017-0728" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0729" seq="2017-0729" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37710346.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0730" seq="2017-0730" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0731" seq="2017-0731" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0732" seq="2017-0732" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37504237.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0733" seq="2017-0733" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38391487.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0734" seq="2017-0734" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38014992.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0735" seq="2017-0735" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38239864.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0736" seq="2017-0736" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38487564.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0737" seq="2017-0737" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563942.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3692-2/">USN-3692-2</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0738" seq="2017-0738" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0739" seq="2017-0739" published="2017-08-09" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0740" seq="2017-0740" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100217" adv="1">100217</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0741" seq="2017-0741" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android ID: A-32458601. References: M-ALPS03007523.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100209" adv="1">100209</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0742" seq="2017-0742" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100209" adv="1">100209</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0744" seq="2017-0744" published="2018-04-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100210" adv="1">100210</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0745" seq="2017-0745" published="2017-08-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100204" adv="1">100204</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0746" seq="2017-0746" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100213" adv="1">100213</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0747" seq="2017-0747" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100213" adv="1">100213</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0748" seq="2017-0748" published="2018-04-05" modified="2018-04-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100210" adv="1">100210</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0749" seq="2017-0749" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100215" adv="1">100215</ref>
      <ref source="MISC" url="https://bugzilla.novell.com/show_bug.cgi?id=1053162">https://bugzilla.novell.com/show_bug.cgi?id=1053162</ref>
      <ref source="MISC" url="https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-0749.html">https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-0749.html</ref>
      <ref source="MISC" url="https://security-tracker.debian.org/tracker/CVE-2017-0749">https://security-tracker.debian.org/tracker/CVE-2017-0749</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0750" seq="2017-0750" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100215" adv="1">100215</ref>
      <ref source="MISC" url="https://bugzilla.novell.com/show_bug.cgi?id=1053160">https://bugzilla.novell.com/show_bug.cgi?id=1053160</ref>
      <ref source="MISC" url="https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-0750.html">https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-0750.html</ref>
      <ref source="MISC" url="https://security-tracker.debian.org/tracker/CVE-2017-0750">https://security-tracker.debian.org/tracker/CVE-2017-0750</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-1/">USN-3583-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-2/">USN-3583-2</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0751" seq="2017-0751" published="2018-04-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100210" adv="1">100210</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0752" seq="2017-0752" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100673" adv="1">100673</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0753" seq="2017-0753" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions: 7.1.1, 7.1.2, 8.0. Android ID: A-62218744.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100650" adv="1">100650</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0755" seq="2017-0755" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-32178311.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100650" adv="1">100650</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0756" seq="2017-0756" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0757" seq="2017-0757" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36006815.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0758" seq="2017-0758" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0759" seq="2017-0759" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0760" seq="2017-0760" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0761" seq="2017-0761" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0762" seq="2017-0762" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62214264.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0763" seq="2017-0763" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62534693.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0764" seq="2017-0764" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0765" seq="2017-0765" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872863.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0766" seq="2017-0766" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libjhead). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37776688.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0767" seq="2017-0767" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37536407.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0768" seq="2017-0768" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62019992.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0769" seq="2017-0769" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37662122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0770" seq="2017-0770" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38234812.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0771" seq="2017-0771" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37624243.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0772" seq="2017-0772" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38115076.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0773" seq="2017-0773" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37615911.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0774" seq="2017-0774" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0775" seq="2017-0775" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673179.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0776" seq="2017-0776" published="2017-09-08" modified="2017-09-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0777" seq="2017-0777" published="2017-09-08" modified="2017-09-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0778" seq="2017-0778" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:C)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0779" seq="2017-0779" published="2017-09-08" modified="2017-09-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100649" adv="1">100649</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0780" seq="2017-0780" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android runtime (android messenger). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37742976.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100674" adv="1">100674</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0781" seq="2017-0781" published="2017-09-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100810" adv="1">100810</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44415/">44415</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0782" seq="2017-0782" published="2017-09-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100822" adv="1">100822</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0783" seq="2017-0783" published="2017-09-14" modified="2018-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.1" CVSS_base_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100811" adv="1">100811</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0784" seq="2017-0784" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100671" adv="1">100671</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0785" seq="2017-0785" published="2017-09-14" modified="2018-07-27" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html">http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100812" adv="1">100812</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1041300">1041300</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0786" seq="2017-0786" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0787" seq="2017-0787" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0788" seq="2017-0788" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0789" seq="2017-0789" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0790" seq="2017-0790" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0791" seq="2017-0791" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0792" seq="2017-0792" published="2017-09-08" modified="2017-09-12" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100655" adv="1">100655</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0793" seq="2017-0793" published="2017-09-08" modified="2017-09-15" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100670" adv="1">100670</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0794" seq="2017-0794" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100667" adv="1">100667</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3798-1/">USN-3798-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3798-2/">USN-3798-2</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0795" seq="2017-0795" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0796" seq="2017-0796" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0797" seq="2017-0797" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0798" seq="2017-0798" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36100671. References: M-ALPS03365532.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0799" seq="2017-0799" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0800" seq="2017-0800" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0801" seq="2017-0801" published="2017-09-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0802" seq="2017-0802" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0803" seq="2017-0803" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0804" seq="2017-0804" published="2017-09-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android ID: A-36274676. References: M-ALPS03361487.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100652" adv="1">100652</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0805" seq="2017-0805" published="2017-08-23" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0806" seq="2017-0806" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101086" adv="1">101086</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/base/+/b87c968e5a41a1a09166199bf54eee12608f3900" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/base/+/b87c968e5a41a1a09166199bf54eee12608f3900</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0807" seq="2017-0807" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101190" adv="1">101190</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102131" adv="1">102131</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0808" seq="2017-0808" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62301183.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101190" adv="1">101190</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/libcore/+/809681f310663288e83587089abb7715c68f6924" adv="1" patch="1">https://android.googlesource.com/platform/libcore/+/809681f310663288e83587089abb7715c68f6924</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0809" seq="2017-0809" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673128.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/552a3b5df2a6876d10da20f72e4cc0d44ac2c790" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/552a3b5df2a6876d10da20f72e4cc0d44ac2c790</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0810" seq="2017-0810" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libmpeg2/+/7737780815fe523ad7b0e49456eb75d27a30818a" adv="1" patch="1">https://android.googlesource.com/platform/external/libmpeg2/+/7737780815fe523ad7b0e49456eb75d27a30818a</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0811" seq="2017-0811" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37930177.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/25c0ffbe6a181b4a373c3c9b421ea449d457e6ed" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/25c0ffbe6a181b4a373c3c9b421ea449d457e6ed</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0812" seq="2017-0812" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62873231.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/device/google/dragon/+/7df7ec13b1d222ac3a66797fbe432605ea8f973f" adv="1" patch="1">https://android.googlesource.com/device/google/dragon/+/7df7ec13b1d222ac3a66797fbe432605ea8f973f</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0813" seq="2017-0813" published="2017-10-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36531046.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/7fa3f552a6f34ed05c15e64ea30b8eed53f77a41" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/7fa3f552a6f34ed05c15e64ea30b8eed53f77a41</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0814" seq="2017-0814" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/tremolo/+/eeb4e45d5683f88488c083ecf142dc89bc3f0b47" adv="1" patch="1">https://android.googlesource.com/platform/external/tremolo/+/eeb4e45d5683f88488c083ecf142dc89bc3f0b47</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0815" seq="2017-0815" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/f490fc335772a9b14e78997486f4a572b0594c04" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/f490fc335772a9b14e78997486f4a572b0594c04</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0816" seq="2017-0816" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63662938.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101088" adv="1">101088</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/f490fc335772a9b14e78997486f4a572b0594c04" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/f490fc335772a9b14e78997486f4a572b0594c04</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0817" seq="2017-0817" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63522430.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/d834160d9759f1098df692b34e6eeb548f9e317b" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/d834160d9759f1098df692b34e6eeb548f9e317b</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0818" seq="2017-0818" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63581671.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/d07f5c14e811951ff9b411ceb84e7288e0d04aaf" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/d07f5c14e811951ff9b411ceb84e7288e0d04aaf</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0819" seq="2017-0819" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/external/libhevc/+/87fb7909c49e6a4510ba86ace1ffc83459c7e1b9" adv="1" patch="1">https://android.googlesource.com/platform/external/libhevc/+/87fb7909c49e6a4510ba86ace1ffc83459c7e1b9</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0820" seq="2017-0820" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187433.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101151" adv="1">101151</ref>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/av/+/8a3a2f6ea7defe1a81bb32b3c9f3537f84749b9d" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/av/+/8a3a2f6ea7defe1a81bb32b3c9f3537f84749b9d</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.4.4"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0822" seq="2017-0822" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a" adv="1" patch="1">https://android.googlesource.com/platform/frameworks/base/+/c574568aaede7f652432deb7707f20ae54bbdf9a</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0823" seq="2017-0823" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://android.googlesource.com/platform/hardware/ril/+/cd5f15f588a5d27e99ba12f057245bfe507f8c42" adv="1" patch="1">https://android.googlesource.com/platform/hardware/ril/+/cd5f15f588a5d27e99ba12f057245bfe507f8c42</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0824" seq="2017-0824" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0825" seq="2017-0825" published="2017-10-03" modified="2017-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37305633. References: B-V2017063002.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0826" seq="2017-0826" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-34949781.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0827" seq="2017-0827" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-62539960. References: M-ALPS03353876, M-ALPS03353861, M-ALPS03353869, M-ALPS03353867, M-ALPS03353872.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101120" adv="1">101120</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0828" seq="2017-0828" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0829" seq="2017-0829" published="2017-10-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0830" seq="2017-0830" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62623498.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101775" adv="1">101775</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0831" seq="2017-0831" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101775" adv="1">101775</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0832" seq="2017-0832" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62887820.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0833" seq="2017-0833" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62896384.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0834" seq="2017-0834" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63125953.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0835" seq="2017-0835" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0836" seq="2017-0836" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64893226.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0837" seq="2017-0837" published="2017-12-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android media framework (libaudiopolicymanager). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64340921.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0838" seq="2017-0838" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-63522818.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0839" seq="2017-0839" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64478003.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0840" seq="2017-0840" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62948670.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101717" adv="1">101717</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0841" seq="2017-0841" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37723026.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101718" adv="1">101718</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0842" seq="2017-0842" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37502513.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101718" adv="1">101718</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0843" seq="2017-0843" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek ccci. Product: Android. Versions: Android kernel. Android ID: A-62670819. References: M-ALPS03361488.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0845" seq="2017-0845" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35028827.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0846" seq="2017-0846" published="2018-01-12" modified="2018-02-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0847" seq="2017-0847" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0848" seq="2017-0848" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64477217.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0849" seq="2017-0849" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62688399.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0850" seq="2017-0850" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-64836941.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0851" seq="2017-0851" published="2017-11-16" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-35430570.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0852" seq="2017-0852" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0. Android ID: A-62815506.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0853" seq="2017-0853" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63121644.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0854" seq="2017-0854" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63873837.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0855" seq="2017-0855" published="2018-01-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64452857.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102414" adv="1">102414</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040106" adv="1">1040106</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0857" seq="2017-0857" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65122447.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0858" seq="2017-0858" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0859" seq="2017-0859" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36075131.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0860" seq="2017-0860" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-31097064.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.0.2"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0861" seq="2017-0861" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://lists.alioth.debian.org/pipermail/secure-testing-commits/2017-December/059967.html">[secure-testing-commits] 20171206 r58306 - data/CVE</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102329">102329</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2390">RHSA-2018:2390</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3083">RHSA-2018:3083</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3096">RHSA-2018:3096</ref>
      <ref source="CONFIRM" url="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=362bca57f5d78220f8b5907b875961af9436e229">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=362bca57f5d78220f8b5907b875961af9436e229</ref>
      <ref source="CONFIRM" url="https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0">https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html">[debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-0861">https://security-tracker.debian.org/tracker/CVE-2017-0861</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-1/">USN-3583-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-2/">USN-3583-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3617-1/">USN-3617-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3617-2/">USN-3617-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3617-3/">USN-3617-3</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3619-1/">USN-3619-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3619-2/">USN-3619-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3632-1/">USN-3632-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4187">DSA-4187</ref>
      <ref source="MISC" url="https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html">https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0862" seq="2017-0862" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-36006779.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0863" seq="2017-0863" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Upstream kernel video driver. Product: Android. Versions: Android kernel. Android ID: A-37950620.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0864" seq="2017-0864" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek ioctl (flashlight). Product: Android. Versions: Android kernel. Android ID: A-37277147. References: M-ALPS03394571.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0865" seq="2017-0865" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-65025090. References: M-ALPS02973195.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0866" seq="2017-0866" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-38415808. References: N-CVE-2017-0866.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01#announcements" adv="1">https://source.android.com/security/bulletin/pixel/2017-11-01#announcements</ref>
    </refs>
    <vuln_soft>
      <prod name="tegra_x1_firmware" vendor="nvidia">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0869" seq="2017-0869" published="2018-01-12" modified="2018-02-01" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling code execution as a privileged process. This issue is rated as high. Version: N/A. Android ID: A-37776156. References: N-CVE-2017-0869.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102374" adv="1">102374</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040106" adv="1">1040106</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0870" seq="2017-0870" published="2017-12-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (libminikin). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-62134807.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102131" adv="1">102131</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0871" seq="2017-0871" published="2017-12-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An elevation of privilege vulnerability in the Android framework (framework base). Product: Android. Versions: 8.0. Android ID A-65281159.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102131" adv="1">102131</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0872" seq="2017-0872" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65290323.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0873" seq="2017-0873" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63316255.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0874" seq="2017-0874" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63315932.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0876" seq="2017-0876" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0877" seq="2017-0877" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0878" seq="2017-0878" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0879" seq="2017-0879" published="2017-12-06" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:C)">
    <desc>
      <descript source="cve">An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0880" seq="2017-0880" published="2017-12-06" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102126" adv="1">102126</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="7.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0881" seq="2017-0881" published="2017-03-27" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97159" adv="1">97159</ref>
      <ref source="MISC" url="https://github.com/zulip/zulip/commit/7ecda1ac8e26d8fb3725e954b2dc4723dda2255f" adv="1" patch="1">https://github.com/zulip/zulip/commit/7ecda1ac8e26d8fb3725e954b2dc4723dda2255f</ref>
      <ref source="MISC" url="https://groups.google.com/d/msg/zulip-announce/VyawgRuoY34/NTBwnTArGwAJ" adv="1" patch="1">https://groups.google.com/d/msg/zulip-announce/VyawgRuoY34/NTBwnTArGwAJ</ref>
    </refs>
    <vuln_soft>
      <prod name="zulip_server" vendor="zulip">
        <vers num="1.1.5"/>
        <vers num="1.2.0" edition="-"/>
        <vers num="1.2.0" edition="p1"/>
        <vers num="1.2.1"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0882" seq="2017-0882" published="2017-03-27" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97157" adv="1">97157</ref>
      <ref source="MISC" url="https://about.gitlab.com/2017/03/20/gitlab-8-dot-17-dot-4-security-release/" adv="1">https://about.gitlab.com/2017/03/20/gitlab-8-dot-17-dot-4-security-release/</ref>
      <ref source="MISC" url="https://gitlab.com/gitlab-org/gitlab-ce/commit/43f5a2739dbf8f5c4c16a79f98e2630888f6b5d1" adv="1" patch="1">https://gitlab.com/gitlab-org/gitlab-ce/commit/43f5a2739dbf8f5c4c16a79f98e2630888f6b5d1</ref>
      <ref source="MISC" url="https://gitlab.com/gitlab-org/gitlab-ce/commit/a70346fc6530aa28a98e4aa4cf0f40e2c3bcef6b" adv="1" patch="1">https://gitlab.com/gitlab-org/gitlab-ce/commit/a70346fc6530aa28a98e4aa4cf0f40e2c3bcef6b</ref>
      <ref source="MISC" url="https://gitlab.com/gitlab-org/gitlab-ce/commit/cdf396f456472ef8decd9598daa8dc0097cd30c5" adv="1" patch="1">https://gitlab.com/gitlab-org/gitlab-ce/commit/cdf396f456472ef8decd9598daa8dc0097cd30c5</ref>
      <ref source="MISC" url="https://gitlab.com/gitlab-org/gitlab-ce/issues/29661" adv="1">https://gitlab.com/gitlab-org/gitlab-ce/issues/29661</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.2.0"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2"/>
        <vers num="8.2.3"/>
        <vers num="8.2.4"/>
        <vers num="8.2.5"/>
        <vers num="8.3.0"/>
        <vers num="8.3.8"/>
        <vers num="8.3.9"/>
        <vers num="8.4.0"/>
        <vers num="8.4.9"/>
        <vers num="8.4.10"/>
        <vers num="8.5.0"/>
        <vers num="8.5.11"/>
        <vers num="8.5.12"/>
        <vers num="8.6.0"/>
        <vers num="8.6.7"/>
        <vers num="8.6.8"/>
        <vers num="8.7.0"/>
        <vers num="8.7.1"/>
        <vers num="8.10.0"/>
        <vers num="8.10.12"/>
        <vers num="8.10.13"/>
        <vers num="8.11.0"/>
        <vers num="8.11.9"/>
        <vers num="8.11.10"/>
        <vers num="8.12.0"/>
        <vers num="8.12.7"/>
        <vers num="8.12.8"/>
        <vers num="8.13.0"/>
        <vers num="8.13.2"/>
        <vers num="8.13.3"/>
        <vers num="8.14.0"/>
        <vers num="8.14.1"/>
        <vers num="8.14.2"/>
        <vers num="8.14.3"/>
        <vers num="8.14.4"/>
        <vers num="8.14.5"/>
        <vers num="8.14.6"/>
        <vers num="8.15.0"/>
        <vers num="8.15.1"/>
        <vers num="8.15.2"/>
        <vers num="8.15.3"/>
        <vers num="8.15.4"/>
        <vers num="8.15.5"/>
        <vers num="8.15.6"/>
        <vers num="8.15.7"/>
        <vers num="8.16.0"/>
        <vers num="8.16.1"/>
        <vers num="8.16.2"/>
        <vers num="8.16.3"/>
        <vers num="8.16.4"/>
        <vers num="8.16.5"/>
        <vers num="8.16.6"/>
        <vers num="8.16.7"/>
        <vers num="8.17.0"/>
        <vers num="8.17.1"/>
        <vers num="8.17.2"/>
        <vers num="8.17.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0883" seq="2017-0883" published="2017-04-05" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/169680" adv="1">https://hackerone.com/reports/169680</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-001" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-001</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud_server" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0884" seq="2017-0884" published="2017-04-05" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/169680" adv="1">https://hackerone.com/reports/169680</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-002" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-002</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0885" seq="2017-0885" published="2017-04-05" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/174524" adv="1">https://hackerone.com/reports/174524</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-003" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-003</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0886" seq="2017-0886" published="2017-04-05" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/174524" adv="1">https://hackerone.com/reports/174524</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-004" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-004</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0887" seq="2017-0887" published="2017-04-05" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/173622" adv="1">https://hackerone.com/reports/173622</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-005" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-005</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0888" seq="2017-0888" published="2017-04-05" modified="2017-04-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97491">97491</ref>
      <ref source="MISC" url="https://hackerone.com/reports/179073" adv="1">https://hackerone.com/reports/179073</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-006" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-006</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="9.0.54" prev="1"/>
        <vers num="10.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0889" seq="2017-0889" published="2017-11-13" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/thoughtbot/paperclip/pull/2435" adv="1" patch="1">https://github.com/thoughtbot/paperclip/pull/2435</ref>
      <ref source="MISC" url="https://hackerone.com/reports/209430">https://hackerone.com/reports/209430</ref>
      <ref source="MISC" url="https://hackerone.com/reports/713" adv="1">https://hackerone.com/reports/713</ref>
    </refs>
    <vuln_soft>
      <prod name="paperclip" vendor="thoughtbot">
        <vers num="3.1.4" edition=":~~~ruby~~"/>
        <vers num="3.2.0" edition=":~~~ruby~~"/>
        <vers num="3.2.1" edition=":~~~ruby~~"/>
        <vers num="3.3.0" edition=":~~~ruby~~"/>
        <vers num="3.3.1" edition=":~~~ruby~~"/>
        <vers num="3.4.0" edition=":~~~ruby~~"/>
        <vers num="3.4.1" edition=":~~~ruby~~"/>
        <vers num="3.4.2" edition=":~~~ruby~~"/>
        <vers num="3.5.0" edition=":~~~ruby~~"/>
        <vers num="3.5.1" edition=":~~~ruby~~"/>
        <vers num="3.5.1.1" edition=":~~~ruby~~"/>
        <vers num="3.5.2" edition=":~~~ruby~~"/>
        <vers num="3.5.3" edition=":~~~ruby~~"/>
        <vers num="3.5.4" edition=":~~~ruby~~"/>
        <vers num="4.0.0" edition=":~~~ruby~~"/>
        <vers num="4.1.0" edition=":~~~ruby~~"/>
        <vers num="4.1.1" edition=":~~~ruby~~"/>
        <vers num="4.2.0" edition=":~~~ruby~~"/>
        <vers num="4.2.1" edition=":~~~ruby~~"/>
        <vers num="4.2.2" edition=":~~~ruby~~"/>
        <vers num="4.2.3" edition=":~~~ruby~~"/>
        <vers num="4.2.4" edition=":~~~ruby~~"/>
        <vers num="4.3.0" edition=":~~~ruby~~"/>
        <vers num="4.3.1" edition=":~~~ruby~~"/>
        <vers num="4.3.2" edition=":~~~ruby~~"/>
        <vers num="4.3.3" edition=":~~~ruby~~"/>
        <vers num="4.3.4" edition=":~~~ruby~~"/>
        <vers num="4.3.5" edition=":~~~ruby~~"/>
        <vers num="4.3.6" edition=":~~~ruby~~"/>
        <vers num="4.3.7" edition=":~~~ruby~~"/>
        <vers num="5.0.0" edition=":~~~ruby~~"/>
        <vers num="5.0.0" edition="beta1:~~~ruby~~"/>
        <vers num="5.0.0" edition="beta2:~~~ruby~~"/>
        <vers num="5.1.0" edition=":~~~ruby~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0890" seq="2017-0890" published="2017-05-08" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/213227">https://hackerone.com/reports/213227</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-007" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-007</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="11.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0891" seq="2017-0891" published="2017-05-08" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/216812" adv="1">https://hackerone.com/reports/216812</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-008" adv="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-008</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud_server" vendor="nextcloud">
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.1"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="3.0" edition="alpha1"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0.1"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.0" edition="rc"/>
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.5.0" edition="beta1"/>
        <vers num="4.5.0" edition="beta2"/>
        <vers num="4.5.0" edition="beta3"/>
        <vers num="4.5.0" edition="beta4"/>
        <vers num="4.5.0" edition="rc1"/>
        <vers num="4.5.0" edition="rc2"/>
        <vers num="4.5.0" edition="rc3"/>
        <vers num="4.5.1" edition="alpha"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.5.9"/>
        <vers num="4.5.10" edition="rc1"/>
        <vers num="4.5.11"/>
        <vers num="4.5.12"/>
        <vers num="4.5.13"/>
        <vers num="5.0.0" edition="alpha1"/>
        <vers num="5.0.0" edition="beta1"/>
        <vers num="5.0.0" edition="beta2"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition="rc1"/>
        <vers num="5.0.5" edition="rc1"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14" edition="alpha"/>
        <vers num="5.0.15" edition="rc1"/>
        <vers num="5.0.16" edition="rc1"/>
        <vers num="5.0.17" edition="beta1"/>
        <vers num="5.0.19"/>
        <vers num="6.0.0" edition="alpha"/>
        <vers num="6.0.0" edition="alpha2"/>
        <vers num="6.0.0" edition="beta2"/>
        <vers num="6.0.0" edition="beta3"/>
        <vers num="6.0.0" edition="beta4"/>
        <vers num="6.0.0" edition="beta5"/>
        <vers num="6.0.0" edition="rc1"/>
        <vers num="6.0.0" edition="rc2"/>
        <vers num="6.0.0" edition="rc3"/>
        <vers num="6.0.0" edition="rc4"/>
        <vers num="6.0.1" edition="rc1"/>
        <vers num="6.0.2" edition="rc1"/>
        <vers num="6.0.3" edition="rc1"/>
        <vers num="6.0.4" edition="beta1"/>
        <vers num="6.0.5" edition="rc1"/>
        <vers num="6.0.6" edition="rc1"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8" edition="rc1"/>
        <vers num="6.0.8" edition="rc2"/>
        <vers num="6.0.9" edition="beta"/>
        <vers num="6.0.9" edition="rc1"/>
        <vers num="6.0.10" edition="beta1"/>
        <vers num="7.0.0" edition="alpha2"/>
        <vers num="7.0.0" edition="beta1"/>
        <vers num="7.0.0" edition="rc1"/>
        <vers num="7.0.0" edition="rc2"/>
        <vers num="7.0.0" edition="rc3"/>
        <vers num="7.0.1" edition="rc1"/>
        <vers num="7.0.2" edition="rc1"/>
        <vers num="7.0.3" edition="alpha1"/>
        <vers num="7.0.3" edition="rc1"/>
        <vers num="7.0.3" edition="rc2"/>
        <vers num="7.0.3" edition="rc3"/>
        <vers num="7.0.4" edition="rc1"/>
        <vers num="7.0.4" edition="rc2"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6" edition="rc1"/>
        <vers num="7.0.6" edition="rc2"/>
        <vers num="7.0.7" edition="beta"/>
        <vers num="7.0.7" edition="rc1"/>
        <vers num="7.0.8" edition="beta1"/>
        <vers num="7.0.8" edition="rc1"/>
        <vers num="7.0.9" edition="rc1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11" edition="rc1"/>
        <vers num="7.0.11" edition="rc2"/>
        <vers num="7.0.12" edition="rc1"/>
        <vers num="7.0.13" edition="rc1"/>
        <vers num="7.0.13" edition="rc2"/>
        <vers num="7.0.14" edition="rc1"/>
        <vers num="7.0.14" edition="rc2"/>
        <vers num="7.0.15" edition="rc1"/>
        <vers num="7.0.15" edition="rc2"/>
        <vers num="8.0.0" edition="alpha1"/>
        <vers num="8.0.0" edition="alpha2"/>
        <vers num="8.0.0" edition="beta1"/>
        <vers num="8.0.0" edition="beta2"/>
        <vers num="8.0.0" edition="rc1"/>
        <vers num="8.0.0" edition="rc2"/>
        <vers num="8.0.1" edition="rc1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3" edition="rc1"/>
        <vers num="8.0.3" edition="rc2"/>
        <vers num="8.0.3" edition="rc3"/>
        <vers num="8.0.3" edition="rc4"/>
        <vers num="8.0.4" edition="rc1"/>
        <vers num="8.0.4" edition="rc2"/>
        <vers num="8.0.5" edition="beta"/>
        <vers num="8.0.5" edition="rc1"/>
        <vers num="8.0.6" edition="beta1"/>
        <vers num="8.0.6" edition="rc1"/>
        <vers num="8.0.7" edition="rc1"/>
        <vers num="8.0.8"/>
        <vers num="8.0.9" edition="rc1"/>
        <vers num="8.0.9" edition="rc2"/>
        <vers num="8.0.10" edition="rc1"/>
        <vers num="8.0.11" edition="rc1"/>
        <vers num="8.0.11" edition="rc2"/>
        <vers num="8.0.12" edition="rc1"/>
        <vers num="8.0.12" edition="rc2"/>
        <vers num="8.0.13" edition="rc1"/>
        <vers num="8.0.13" edition="rc2"/>
        <vers num="8.0.14" edition="rc2"/>
        <vers num="8.0.15" edition="rc1"/>
        <vers num="8.0.16" edition="rc1"/>
        <vers num="8.0.16" edition="rc2"/>
        <vers num="8.1" edition="rc2"/>
        <vers num="8.1.0" edition="alpha1"/>
        <vers num="8.1.0" edition="alpha2"/>
        <vers num="8.1.0" edition="beta1"/>
        <vers num="8.1.0" edition="beta2"/>
        <vers num="8.1.1" edition="beta"/>
        <vers num="8.1.1" edition="beta1"/>
        <vers num="8.1.1" edition="rc1"/>
        <vers num="8.1.2" edition="rc1"/>
        <vers num="8.1.3"/>
        <vers num="8.1.4" edition="rc1"/>
        <vers num="8.1.4" edition="rc2"/>
        <vers num="8.1.5" edition="rc1"/>
        <vers num="8.1.6" edition="rc1"/>
        <vers num="8.1.6" edition="rc2"/>
        <vers num="8.1.7" edition="rc1"/>
        <vers num="8.1.7" edition="rc2"/>
        <vers num="8.1.8" edition="rc1"/>
        <vers num="8.1.8" edition="rc2"/>
        <vers num="8.1.9" edition="rc1"/>
        <vers num="8.1.9" edition="rc2"/>
        <vers num="8.1.10" edition="rc1"/>
        <vers num="8.1.11" edition="rc1"/>
        <vers num="8.1.11" edition="rc2"/>
        <vers num="8.2" edition="beta1"/>
        <vers num="8.2" edition="rc1"/>
        <vers num="8.2" edition="rc2"/>
        <vers num="8.2" edition="rc3"/>
        <vers num="8.2.0"/>
        <vers num="8.2.1" edition="rc1"/>
        <vers num="8.2.1" edition="rc2"/>
        <vers num="8.2.1" edition="rc3"/>
        <vers num="8.2.1" edition="rc4"/>
        <vers num="8.2.2" edition="rc1"/>
        <vers num="8.2.3" edition="rc1"/>
        <vers num="8.2.3" edition="rc2"/>
        <vers num="8.2.4" edition="rc1"/>
        <vers num="8.2.4" edition="rc2"/>
        <vers num="8.2.5" edition="rc1"/>
        <vers num="8.2.5" edition="rc2"/>
        <vers num="8.2.6" edition="rc1"/>
        <vers num="8.2.7" edition="rc1"/>
        <vers num="8.2.8" edition="rc1"/>
        <vers num="8.2.8" edition="rc2"/>
        <vers num="8.2.9" edition="rc1"/>
        <vers num="8.2.9" edition="rc2"/>
        <vers num="9.0" edition="beta1"/>
        <vers num="9.0.0" edition="beta2"/>
        <vers num="9.0.0" edition="rc1"/>
        <vers num="9.0.0" edition="rc2"/>
        <vers num="9.0.0" edition="rc3"/>
        <vers num="9.0.1" edition="beta"/>
        <vers num="9.0.1" edition="beta2"/>
        <vers num="9.0.1" edition="rc1"/>
        <vers num="9.0.1" edition="rc2"/>
        <vers num="9.0.2" edition="rc1"/>
        <vers num="9.0.2" edition="rc2"/>
        <vers num="9.0.3" edition="rc1"/>
        <vers num="9.0.4" edition="rc1"/>
        <vers num="9.0.5" edition="rc1"/>
        <vers num="9.0.5" edition="rc2"/>
        <vers num="9.0.6" edition="rc1"/>
        <vers num="9.0.6" edition="rc2"/>
        <vers num="9.0.7" edition="rc1"/>
        <vers num="9.0.50"/>
        <vers num="9.0.51"/>
        <vers num="9.0.52" edition="rc1"/>
        <vers num="9.0.53"/>
        <vers num="9.0.54" edition="rc1"/>
        <vers num="9.0.55"/>
        <vers num="9.0.56" edition="rc1"/>
        <vers num="9.0.57" edition="rc1"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1" edition="rc1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3" edition="rc1"/>
        <vers num="10.0.4" edition="rc1"/>
        <vers num="11.0.0"/>
        <vers num="11.0.1" edition="rc1"/>
        <vers num="11.0.2" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0892" seq="2017-0892" published="2017-05-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/191979" adv="1">https://hackerone.com/reports/191979</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-009" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-009</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="11.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0893" seq="2017-0893" published="2017-05-08" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/222838" adv="1">https://hackerone.com/reports/222838</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-010" adv="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-010</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud_server" vendor="nextcloud">
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.1"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="3.0" edition="alpha1"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0.1"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.0" edition="rc"/>
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.5.0" edition="beta1"/>
        <vers num="4.5.0" edition="beta2"/>
        <vers num="4.5.0" edition="beta3"/>
        <vers num="4.5.0" edition="beta4"/>
        <vers num="4.5.0" edition="rc1"/>
        <vers num="4.5.0" edition="rc2"/>
        <vers num="4.5.0" edition="rc3"/>
        <vers num="4.5.1" edition="alpha"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.5.9"/>
        <vers num="4.5.10" edition="rc1"/>
        <vers num="4.5.11"/>
        <vers num="4.5.12"/>
        <vers num="4.5.13"/>
        <vers num="5.0.0" edition="alpha1"/>
        <vers num="5.0.0" edition="beta1"/>
        <vers num="5.0.0" edition="beta2"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition="rc1"/>
        <vers num="5.0.5" edition="rc1"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14" edition="alpha"/>
        <vers num="5.0.15" edition="rc1"/>
        <vers num="5.0.16" edition="rc1"/>
        <vers num="5.0.17" edition="beta1"/>
        <vers num="5.0.19"/>
        <vers num="6.0.0" edition="alpha"/>
        <vers num="6.0.0" edition="alpha2"/>
        <vers num="6.0.0" edition="beta2"/>
        <vers num="6.0.0" edition="beta3"/>
        <vers num="6.0.0" edition="beta4"/>
        <vers num="6.0.0" edition="beta5"/>
        <vers num="6.0.0" edition="rc1"/>
        <vers num="6.0.0" edition="rc2"/>
        <vers num="6.0.0" edition="rc3"/>
        <vers num="6.0.0" edition="rc4"/>
        <vers num="6.0.1" edition="rc1"/>
        <vers num="6.0.2" edition="rc1"/>
        <vers num="6.0.3" edition="rc1"/>
        <vers num="6.0.4" edition="beta1"/>
        <vers num="6.0.5" edition="rc1"/>
        <vers num="6.0.6" edition="rc1"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8" edition="rc1"/>
        <vers num="6.0.8" edition="rc2"/>
        <vers num="6.0.9" edition="beta"/>
        <vers num="6.0.9" edition="rc1"/>
        <vers num="6.0.10" edition="beta1"/>
        <vers num="7.0.0" edition="alpha2"/>
        <vers num="7.0.0" edition="beta1"/>
        <vers num="7.0.0" edition="rc1"/>
        <vers num="7.0.0" edition="rc2"/>
        <vers num="7.0.0" edition="rc3"/>
        <vers num="7.0.1" edition="rc1"/>
        <vers num="7.0.2" edition="rc1"/>
        <vers num="7.0.3" edition="alpha1"/>
        <vers num="7.0.3" edition="rc1"/>
        <vers num="7.0.3" edition="rc2"/>
        <vers num="7.0.3" edition="rc3"/>
        <vers num="7.0.4" edition="rc1"/>
        <vers num="7.0.4" edition="rc2"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6" edition="rc1"/>
        <vers num="7.0.6" edition="rc2"/>
        <vers num="7.0.7" edition="beta"/>
        <vers num="7.0.7" edition="rc1"/>
        <vers num="7.0.8" edition="beta1"/>
        <vers num="7.0.8" edition="rc1"/>
        <vers num="7.0.9" edition="rc1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11" edition="rc1"/>
        <vers num="7.0.11" edition="rc2"/>
        <vers num="7.0.12" edition="rc1"/>
        <vers num="7.0.13" edition="rc1"/>
        <vers num="7.0.13" edition="rc2"/>
        <vers num="7.0.14" edition="rc1"/>
        <vers num="7.0.14" edition="rc2"/>
        <vers num="7.0.15" edition="rc1"/>
        <vers num="7.0.15" edition="rc2"/>
        <vers num="8.0.0" edition="alpha1"/>
        <vers num="8.0.0" edition="alpha2"/>
        <vers num="8.0.0" edition="beta1"/>
        <vers num="8.0.0" edition="beta2"/>
        <vers num="8.0.0" edition="rc1"/>
        <vers num="8.0.0" edition="rc2"/>
        <vers num="8.0.1" edition="rc1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3" edition="rc1"/>
        <vers num="8.0.3" edition="rc2"/>
        <vers num="8.0.3" edition="rc3"/>
        <vers num="8.0.3" edition="rc4"/>
        <vers num="8.0.4" edition="rc1"/>
        <vers num="8.0.4" edition="rc2"/>
        <vers num="8.0.5" edition="beta"/>
        <vers num="8.0.5" edition="rc1"/>
        <vers num="8.0.6" edition="beta1"/>
        <vers num="8.0.6" edition="rc1"/>
        <vers num="8.0.7" edition="rc1"/>
        <vers num="8.0.8"/>
        <vers num="8.0.9" edition="rc1"/>
        <vers num="8.0.9" edition="rc2"/>
        <vers num="8.0.10" edition="rc1"/>
        <vers num="8.0.11" edition="rc1"/>
        <vers num="8.0.11" edition="rc2"/>
        <vers num="8.0.12" edition="rc1"/>
        <vers num="8.0.12" edition="rc2"/>
        <vers num="8.0.13" edition="rc1"/>
        <vers num="8.0.13" edition="rc2"/>
        <vers num="8.0.14" edition="rc2"/>
        <vers num="8.0.15" edition="rc1"/>
        <vers num="8.0.16" edition="rc1"/>
        <vers num="8.0.16" edition="rc2"/>
        <vers num="8.1" edition="rc2"/>
        <vers num="8.1.0" edition="alpha1"/>
        <vers num="8.1.0" edition="alpha2"/>
        <vers num="8.1.0" edition="beta1"/>
        <vers num="8.1.0" edition="beta2"/>
        <vers num="8.1.1" edition="beta"/>
        <vers num="8.1.1" edition="beta1"/>
        <vers num="8.1.1" edition="rc1"/>
        <vers num="8.1.2" edition="rc1"/>
        <vers num="8.1.3"/>
        <vers num="8.1.4" edition="rc1"/>
        <vers num="8.1.4" edition="rc2"/>
        <vers num="8.1.5" edition="rc1"/>
        <vers num="8.1.6" edition="rc1"/>
        <vers num="8.1.6" edition="rc2"/>
        <vers num="8.1.7" edition="rc1"/>
        <vers num="8.1.7" edition="rc2"/>
        <vers num="8.1.8" edition="rc1"/>
        <vers num="8.1.8" edition="rc2"/>
        <vers num="8.1.9" edition="rc1"/>
        <vers num="8.1.9" edition="rc2"/>
        <vers num="8.1.10" edition="rc1"/>
        <vers num="8.1.11" edition="rc1"/>
        <vers num="8.1.11" edition="rc2"/>
        <vers num="8.2" edition="beta1"/>
        <vers num="8.2" edition="rc1"/>
        <vers num="8.2" edition="rc2"/>
        <vers num="8.2" edition="rc3"/>
        <vers num="8.2.0"/>
        <vers num="8.2.1" edition="rc1"/>
        <vers num="8.2.1" edition="rc2"/>
        <vers num="8.2.1" edition="rc3"/>
        <vers num="8.2.1" edition="rc4"/>
        <vers num="8.2.2" edition="rc1"/>
        <vers num="8.2.3" edition="rc1"/>
        <vers num="8.2.3" edition="rc2"/>
        <vers num="8.2.4" edition="rc1"/>
        <vers num="8.2.4" edition="rc2"/>
        <vers num="8.2.5" edition="rc1"/>
        <vers num="8.2.5" edition="rc2"/>
        <vers num="8.2.6" edition="rc1"/>
        <vers num="8.2.7" edition="rc1"/>
        <vers num="8.2.8" edition="rc1"/>
        <vers num="8.2.8" edition="rc2"/>
        <vers num="8.2.9" edition="rc1"/>
        <vers num="8.2.9" edition="rc2"/>
        <vers num="9.0" edition="beta1"/>
        <vers num="9.0.0" edition="beta2"/>
        <vers num="9.0.0" edition="rc1"/>
        <vers num="9.0.0" edition="rc2"/>
        <vers num="9.0.0" edition="rc3"/>
        <vers num="9.0.1" edition="beta"/>
        <vers num="9.0.1" edition="beta2"/>
        <vers num="9.0.1" edition="rc1"/>
        <vers num="9.0.1" edition="rc2"/>
        <vers num="9.0.2" edition="rc1"/>
        <vers num="9.0.2" edition="rc2"/>
        <vers num="9.0.3" edition="rc1"/>
        <vers num="9.0.4" edition="rc1"/>
        <vers num="9.0.5" edition="rc1"/>
        <vers num="9.0.5" edition="rc2"/>
        <vers num="9.0.6" edition="rc1"/>
        <vers num="9.0.6" edition="rc2"/>
        <vers num="9.0.7" edition="rc1"/>
        <vers num="9.0.50"/>
        <vers num="9.0.51"/>
        <vers num="9.0.52" edition="rc1"/>
        <vers num="9.0.53"/>
        <vers num="9.0.54" edition="rc1"/>
        <vers num="9.0.55"/>
        <vers num="9.0.56" edition="rc1"/>
        <vers num="9.0.57" edition="rc1"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1" edition="rc1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3" edition="rc1"/>
        <vers num="10.0.4" edition="rc1"/>
        <vers num="11.0.0"/>
        <vers num="11.0.1" edition="rc1"/>
        <vers num="11.0.2" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0894" seq="2017-0894" published="2017-05-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/218876">https://hackerone.com/reports/218876</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-011" adv="1" patch="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-011</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud" vendor="nextcloud">
        <vers num="11.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0895" seq="2017-0895" published="2017-05-08" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/203594" adv="1">https://hackerone.com/reports/203594</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2017-012" adv="1">https://nextcloud.com/security/advisory/?id=nc-sa-2017-012</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud_server" vendor="nextcloud">
        <vers num="10.0.0"/>
        <vers num="10.0.1" edition="rc1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3" edition="rc1"/>
        <vers num="11.0.0"/>
        <vers num="11.0.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0896" seq="2017-0896" published="2017-06-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/zulip/zulip/commit/1f48fa27672170bba3b9a97384905bb04c18761b" patch="1">https://github.com/zulip/zulip/commit/1f48fa27672170bba3b9a97384905bb04c18761b</ref>
      <ref source="MLIST" url="https://groups.google.com/forum/#!msg/zulip-announce/sUYeJv-fFmg/2TU2TLmNAwAJ">[zulip-announce] 20170601 Zulip Server 1.5.2 released</ref>
      <ref source="MISC" url="https://hackerone.com/reports/224210">https://hackerone.com/reports/224210</ref>
    </refs>
    <vuln_soft>
      <prod name="zulip_server" vendor="zulip">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0897" seq="2017-0897" published="2017-06-22" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ExpressionEngine version 2.x &lt; 2.11.8 and version 3.x &lt; 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99242" adv="1">99242</ref>
      <ref source="CONFIRM" url="https://docs.expressionengine.com/latest/about/changelog.html#version-3-5-5" adv="1">https://docs.expressionengine.com/latest/about/changelog.html#version-3-5-5</ref>
      <ref source="CONFIRM" url="https://docs.expressionengine.com/v2/about/changelog.html#version-2-11-8" adv="1">https://docs.expressionengine.com/v2/about/changelog.html#version-2-11-8</ref>
      <ref source="CONFIRM" url="https://expressionengine.com/blog/expressionengine-3.5.5-and-2.11.8-released" adv="1">https://expressionengine.com/blog/expressionengine-3.5.5-and-2.11.8-released</ref>
      <ref source="MISC" url="https://hackerone.com/reports/215890">https://hackerone.com/reports/215890</ref>
    </refs>
    <vuln_soft>
      <prod name="expressionengine" vendor="expressionengine">
        <vers num="2.0.0" edition="public_beta"/>
        <vers num="2.0.1" edition="public_beta"/>
        <vers num="2.0.2" edition="public_beta"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
        <vers num="2.11.4"/>
        <vers num="2.11.5"/>
        <vers num="2.11.6"/>
        <vers num="2.11.7"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0898" seq="2017-0898" published="2017-09-15" modified="2018-07-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100862" adv="1">100862</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039363" adv="1">1039363</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/mruby/mruby/issues/3722" adv="1">https://github.com/mruby/mruby/issues/3722</ref>
      <ref source="MISC" url="https://hackerone.com/reports/212241" adv="1">https://hackerone.com/reports/212241</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-18">GLSA-201710-18</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3685-1/">USN-3685-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4031">DSA-4031</ref>
      <ref source="MISC" url="https://www.ruby-lang.org/en/news/2017/09/14/sprintf-buffer-underrun-cve-2017-0898/" adv="1">https://www.ruby-lang.org/en/news/2017/09/14/sprintf-buffer-underrun-cve-2017-0898/</ref>
    </refs>
    <vuln_soft>
      <prod name="ruby" vendor="ruby-lang">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0899" seq="2017-0899" published="2017-08-31" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.rubygems.org/2017/08/27/2.6.13-released.html" adv="1" patch="1">http://blog.rubygems.org/2017/08/27/2.6.13-released.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100576" adv="1">100576</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039249" adv="1">1039249</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485" adv="1">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378" adv="1">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583" adv="1">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585" adv="1">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491</ref>
      <ref source="MISC" url="https://hackerone.com/reports/226335" adv="1" patch="1">https://hackerone.com/reports/226335</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html" adv="1">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-01" adv="1">GLSA-201710-01</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3966" adv="1">DSA-3966</ref>
    </refs>
    <vuln_soft>
      <prod name="rubygems" vendor="rubygems">
        <vers num="2.6.12" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0900" seq="2017-0900" published="2017-08-31" modified="2019-05-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.rubygems.org/2017/08/27/2.6.13-released.html" adv="1" patch="1">http://blog.rubygems.org/2017/08/27/2.6.13-released.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100579" adv="1">100579</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039249" adv="1">1039249</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485" adv="1">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378" adv="1">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583" adv="1">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585" adv="1">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/8a38a4fc24c6591e6c8f43d1fadab6efeb4d6251" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/8a38a4fc24c6591e6c8f43d1fadab6efeb4d6251</ref>
      <ref source="MISC" url="https://hackerone.com/reports/243003" adv="1">https://hackerone.com/reports/243003</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html" adv="1">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-01" adv="1">GLSA-201710-01</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3966" adv="1">DSA-3966</ref>
    </refs>
    <vuln_soft>
      <prod name="rubygems" vendor="rubygems">
        <vers num="2.6.12" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0901" seq="2017-0901" published="2017-08-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.rubygems.org/2017/08/27/2.6.13-released.html" adv="1" patch="1">http://blog.rubygems.org/2017/08/27/2.6.13-released.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100580" adv="1">100580</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039249" adv="1">1039249</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485" adv="1">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378" adv="1">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583" adv="1">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585" adv="1">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/ad5c0a53a86ca5b218c7976765c0365b91d22cb2" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/ad5c0a53a86ca5b218c7976765c0365b91d22cb2</ref>
      <ref source="MISC" url="https://hackerone.com/reports/243156" adv="1" patch="1">https://hackerone.com/reports/243156</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html" adv="1">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-01" adv="1">GLSA-201710-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3553-1/" adv="1">USN-3553-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3685-1/" adv="1">USN-3685-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3966" adv="1">DSA-3966</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42611/" adv="1">42611</ref>
    </refs>
    <vuln_soft>
      <prod name="rubygems" vendor="rubygems">
        <vers num="2.6.12" prev="1"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0902" seq="2017-0902" published="2017-08-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.rubygems.org/2017/08/27/2.6.13-released.html" adv="1" patch="1">http://blog.rubygems.org/2017/08/27/2.6.13-released.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100586" adv="1">100586</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039249" adv="1">1039249</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485" adv="1">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378" adv="1">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583" adv="1">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585" adv="1">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/8d91516fb7037ecfb27622f605dc40245e0f8d32" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/8d91516fb7037ecfb27622f605dc40245e0f8d32</ref>
      <ref source="MISC" url="https://hackerone.com/reports/218088" adv="1">https://hackerone.com/reports/218088</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html" adv="1">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-01" adv="1">GLSA-201710-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3553-1/" adv="1">USN-3553-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3685-1/" adv="1">USN-3685-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-3966" adv="1">DSA-3966</ref>
    </refs>
    <vuln_soft>
      <prod name="rubygems" vendor="rubygems">
        <vers num="2.6.12" prev="1"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0903" seq="2017-0903" published="2017-10-11" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.rubygems.org/2017/10/09/2.6.14-released.html" adv="1">http://blog.rubygems.org/2017/10/09/2.6.14-released.html</ref>
      <ref source="MISC" url="http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html" adv="1">http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101275" adv="1">101275</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485" adv="1">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378" adv="1">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583" adv="1">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585" adv="1">RHSA-2018:0585</ref>
      <ref source="MISC" url="https://github.com/rubygems/rubygems/commit/510b1638ac9bba3ceb7a5d73135dafff9e5bab49" adv="1" patch="1">https://github.com/rubygems/rubygems/commit/510b1638ac9bba3ceb7a5d73135dafff9e5bab49</ref>
      <ref source="MISC" url="https://hackerone.com/reports/274990" adv="1">https://hackerone.com/reports/274990</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html" adv="1">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3553-1/" adv="1">USN-3553-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3685-1/" adv="1">USN-3685-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4031" adv="1">DSA-4031</ref>
    </refs>
    <vuln_soft>
      <prod name="rubygems" vendor="rubygems">
        <vers num="2.0.0" edition="preview2"/>
        <vers num="2.0.0" edition="preview2.1"/>
        <vers num="2.0.0" edition="preview2.2"/>
        <vers num="2.0.0" edition="rc1"/>
        <vers num="2.0.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.1.0"/>
        <vers num="2.1.0.rc.1"/>
        <vers num="2.1.0.rc.2"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0.preiew.1"/>
        <vers num="2.2.0.rc.1"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.12"/>
        <vers num="2.6.13"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0904" seq="2017-0904" published="2017-11-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://edoverflow.com/2017/ruby-resolv-bug/" adv="1">https://edoverflow.com/2017/ruby-resolv-bug/</ref>
      <ref source="CONFIRM" url="https://github.com/jtdowney/private_address_check/commit/58a0d7fe31de339c0117160567a5b33ad82b46af" adv="1">https://github.com/jtdowney/private_address_check/commit/58a0d7fe31de339c0117160567a5b33ad82b46af</ref>
      <ref source="CONFIRM" url="https://github.com/jtdowney/private_address_check/issues/1" adv="1">https://github.com/jtdowney/private_address_check/issues/1</ref>
      <ref source="MISC" url="https://hackerone.com/reports/287245" adv="1" patch="1">https://hackerone.com/reports/287245</ref>
      <ref source="MISC" url="https://hackerone.com/reports/287835" adv="1">https://hackerone.com/reports/287835</ref>
    </refs>
    <vuln_soft>
      <prod name="private_address_check" vendor="private_address_check_project">
        <vers num="0.1.0" edition=":~~~ruby~~"/>
        <vers num="0.2.0" edition=":~~~ruby~~"/>
        <vers num="0.3.0" edition=":~~~ruby~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0905" seq="2017-0905" published="2017-11-13" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other critical resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://dev.recurly.com/page/ruby-updates" adv="1">https://dev.recurly.com/page/ruby-updates</ref>
      <ref source="CONFIRM" url="https://github.com/recurly/recurly-client-ruby/commit/1bb0284d6e668b8b3d31167790ed6db1f6ccc4be" adv="1" patch="1">https://github.com/recurly/recurly-client-ruby/commit/1bb0284d6e668b8b3d31167790ed6db1f6ccc4be</ref>
      <ref source="MISC" url="https://hackerone.com/reports/288635">https://hackerone.com/reports/288635</ref>
    </refs>
    <vuln_soft>
      <prod name="recurly_client_ruby" vendor="recurly">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.1.0" edition="c"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.3.0" edition="beta1"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.8.0" edition="rc1"/>
        <vers num="2.8.0" edition="rc3"/>
        <vers num="2.8.1"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0906" seq="2017-0906" published="2017-11-13" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://dev.recurly.com/page/python-updates" adv="1">https://dev.recurly.com/page/python-updates</ref>
      <ref source="CONFIRM" url="https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742" adv="1" patch="1">https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742</ref>
      <ref source="MISC" url="https://hackerone.com/reports/288635">https://hackerone.com/reports/288635</ref>
    </refs>
    <vuln_soft>
      <prod name="recurly_client_python" vendor="recurly">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0907" seq="2017-0907" published="2017-11-13" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://dev.recurly.com/page/net-updates" adv="1">https://dev.recurly.com/page/net-updates</ref>
      <ref source="CONFIRM" url="https://github.com/recurly/recurly-client-net/commit/9eef460c0084afd5c24d66220c8b7a381cf9a1f1" adv="1" patch="1">https://github.com/recurly/recurly-client-net/commit/9eef460c0084afd5c24d66220c8b7a381cf9a1f1</ref>
      <ref source="MISC" url="https://hackerone.com/reports/288635">https://hackerone.com/reports/288635</ref>
    </refs>
    <vuln_soft>
      <prod name="recurly_client_.net" vendor="recurly">
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.0.0" edition="beta2"/>
        <vers num="1.0.0" edition="beta3"/>
        <vers num="1.0.0" edition="rc1"/>
        <vers num="1.0.0.1"/>
        <vers num="1.0.0.2"/>
        <vers num="1.0.0.3"/>
        <vers num="1.0.0.4"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers num="1.5.0"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.7.0"/>
        <vers num="1.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0908" seq="2017-0908" published="2017-11-13" modified="2017-11-13" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-16510.  Reason: This candidate is a reservation duplicate of CVE-2017-16510.  Notes: All CVE users should reference CVE-2017-16510 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-0909" seq="2017-0909" published="2017-11-16" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/jtdowney/private_address_check/pull/3" adv="1">https://github.com/jtdowney/private_address_check/pull/3</ref>
      <ref source="MISC" url="https://hackerone.com/reports/288950" adv="1" patch="1">https://hackerone.com/reports/288950</ref>
    </refs>
    <vuln_soft>
      <prod name="private_address_check" vendor="private_address_check_project">
        <vers num="0.1.0" edition=":~~~ruby~~"/>
        <vers num="0.2.0" edition=":~~~ruby~~"/>
        <vers num="0.3.0" edition=":~~~ruby~~"/>
        <vers num="0.4.0" edition=":~~~ruby~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0910" seq="2017-0910" published="2017-11-27" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://blog.zulip.org/2017/11/23/zulip-1-7-1-released/" adv="1">http://blog.zulip.org/2017/11/23/zulip-1-7-1-released/</ref>
      <ref source="CONFIRM" url="https://github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32" adv="1" patch="1">https://github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32</ref>
    </refs>
    <vuln_soft>
      <prod name="zulip_server" vendor="zulip">
        <vers num="1.1.5"/>
        <vers num="1.2.0" edition="-"/>
        <vers num="1.2.0" edition="p1"/>
        <vers num="1.2.1"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.0"/>
        <vers num="1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0911" seq="2017-0911" published="2018-02-09" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information is passed back to the application using the registered custom URL scheme (typically twitterkit-&lt;consumer-key>) on iOS. Because the callback handler did not verify the authenticity of the response, this step is vulnerable to forgery, potentially allowing attacker to associate a Twitter account with a third-party service.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://blog.twitter.com/developer/en_us/topics/tips/2018/vulnerability-in-twitter-kit-for-ios.html" adv="1">https://blog.twitter.com/developer/en_us/topics/tips/2018/vulnerability-in-twitter-kit-for-ios.html</ref>
      <ref source="CONFIRM" url="https://github.com/twitter/twitter-kit-ios/blob/b6eb49d149b056d826cbc4b53eaeb39a3ebd591e/TwitterKit/TwitterKit/Social/Identity/TWTRMobileSSO.m#L71" adv="1" patch="1">https://github.com/twitter/twitter-kit-ios/blob/b6eb49d149b056d826cbc4b53eaeb39a3ebd591e/TwitterKit/TwitterKit/Social/Identity/TWTRMobileSSO.m#L71</ref>
      <ref source="CONFIRM" url="https://github.com/twitter/twitter-kit-ios/blob/b6eb49d149b056d826cbc4b53eaeb39a3ebd591e/TwitterKit/TwitterKit/TWTRTwitter.m#L411" adv="1" patch="1">https://github.com/twitter/twitter-kit-ios/blob/b6eb49d149b056d826cbc4b53eaeb39a3ebd591e/TwitterKit/TwitterKit/TWTRTwitter.m#L411</ref>
      <ref source="CONFIRM" url="https://github.com/twitter/twitter-kit-ios/wiki/Changelog#322-november-28-2017" adv="1">https://github.com/twitter/twitter-kit-ios/wiki/Changelog#322-november-28-2017</ref>
      <ref source="MISC" url="https://hackerone.com/reports/290229" adv="1">https://hackerone.com/reports/290229</ref>
    </refs>
    <vuln_soft>
      <prod name="twitter_kit" vendor="twitter">
        <vers num="3.0" edition=":~~~iphone_os~~"/>
        <vers num="3.0.1" edition=":~~~iphone_os~~"/>
        <vers num="3.0.2" edition=":~~~iphone_os~~"/>
        <vers num="3.0.3" edition=":~~~iphone_os~~"/>
        <vers num="3.0.4" edition=":~~~iphone_os~~"/>
        <vers num="3.1.0" edition=":~~~iphone_os~~"/>
        <vers num="3.1.1" edition=":~~~iphone_os~~"/>
        <vers num="3.2.0" edition=":~~~iphone_os~~"/>
        <vers num="3.2.1" edition=":~~~iphone_os~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0912" seq="2017-0912" published="2018-07-03" modified="2019-09-13" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://community.ubnt.com/t5/UCRM/New-UCRM-upgrades-available-2-8-2-and-2-9-0-beta3/td-p/2211814" adv="1">https://community.ubnt.com/t5/UCRM/New-UCRM-upgrades-available-2-8-2-and-2-9-0-beta3/td-p/2211814</ref>
    </refs>
    <vuln_soft>
      <prod name="ucrm" vendor="ui">
        <vers num="2.5.0" edition="-"/>
        <vers num="2.5.0" edition="beta1"/>
        <vers num="2.5.0" edition="beta2"/>
        <vers num="2.5.0" edition="beta3"/>
        <vers num="2.5.0" edition="beta4"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.6.0" edition="-"/>
        <vers num="2.6.0" edition="beta1"/>
        <vers num="2.6.0" edition="beta2"/>
        <vers num="2.6.0" edition="beta3"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.7.0" edition="-"/>
        <vers num="2.7.0" edition="beta1"/>
        <vers num="2.7.0" edition="beta2"/>
        <vers num="2.7.0" edition="beta3"/>
        <vers num="2.7.0" edition="beta4"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0913" seq="2017-0913" published="2018-07-03" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://community.ubnt.com/t5/UCRM/New-UCRM-upgrades-available-2-8-2-and-2-9-0-beta3/td-p/2211814" adv="1">https://community.ubnt.com/t5/UCRM/New-UCRM-upgrades-available-2-8-2-and-2-9-0-beta3/td-p/2211814</ref>
      <ref source="MISC" url="https://hackerone.com/reports/301406" adv="1">https://hackerone.com/reports/301406</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-0914" seq="2017-0914" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/298176">https://hackerone.com/reports/298176</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0915" seq="2017-0915" published="2018-03-21" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/298873">https://hackerone.com/reports/298873</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0916" seq="2017-0916" published="2018-03-21" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/299473">https://hackerone.com/reports/299473</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="9.6.0" edition="-:~~community~~~"/>
        <vers num="9.6.0" edition="pre:~~community~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0917" seq="2017-0917" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/299525">https://hackerone.com/reports/299525</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0918" seq="2017-0918" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/301432">https://hackerone.com/reports/301432</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.4.0" edition=":~~community~~~"/>
        <vers num="8.4.0" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition="rc1:~~community~~~"/>
        <vers num="8.4.0" edition="rc2:~~community~~~"/>
        <vers num="8.4.0" edition="rc3:~~community~~~"/>
        <vers num="8.4.1" edition=":~~community~~~"/>
        <vers num="8.4.1" edition=":~~enterprise~~~"/>
        <vers num="8.4.2" edition=":~~community~~~"/>
        <vers num="8.4.2" edition=":~~enterprise~~~"/>
        <vers num="8.4.3" edition=":~~community~~~"/>
        <vers num="8.4.3" edition=":~~enterprise~~~"/>
        <vers num="8.4.4" edition=":~~community~~~"/>
        <vers num="8.4.4" edition=":~~enterprise~~~"/>
        <vers num="8.4.5" edition=":~~community~~~"/>
        <vers num="8.4.5" edition=":~~enterprise~~~"/>
        <vers num="8.4.6" edition=":~~community~~~"/>
        <vers num="8.4.6" edition=":~~enterprise~~~"/>
        <vers num="8.4.7" edition=":~~community~~~"/>
        <vers num="8.4.7" edition=":~~enterprise~~~"/>
        <vers num="8.4.8" edition=":~~community~~~"/>
        <vers num="8.4.8" edition=":~~enterprise~~~"/>
        <vers num="8.4.9" edition=":~~community~~~"/>
        <vers num="8.4.9" edition=":~~enterprise~~~"/>
        <vers num="8.4.10" edition=":~~community~~~"/>
        <vers num="8.4.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.11" edition=":~~community~~~"/>
        <vers num="8.4.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition=":~~community~~~"/>
        <vers num="8.5.0" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition="rc1:~~community~~~"/>
        <vers num="8.5.0" edition="rc2:~~community~~~"/>
        <vers num="8.5.0" edition="rc3:~~community~~~"/>
        <vers num="8.5.0" edition="rc4:~~community~~~"/>
        <vers num="8.5.1" edition=":~~community~~~"/>
        <vers num="8.5.1" edition=":~~enterprise~~~"/>
        <vers num="8.5.2" edition=":~~community~~~"/>
        <vers num="8.5.2" edition=":~~enterprise~~~"/>
        <vers num="8.5.3" edition=":~~community~~~"/>
        <vers num="8.5.3" edition=":~~enterprise~~~"/>
        <vers num="8.5.4" edition=":~~community~~~"/>
        <vers num="8.5.4" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition="-:~~community~~~"/>
        <vers num="8.5.5" edition="rc1:~~community~~~"/>
        <vers num="8.5.6" edition=":~~community~~~"/>
        <vers num="8.5.6" edition=":~~enterprise~~~"/>
        <vers num="8.5.7" edition=":~~community~~~"/>
        <vers num="8.5.7" edition=":~~enterprise~~~"/>
        <vers num="8.5.8" edition=":~~community~~~"/>
        <vers num="8.5.8" edition=":~~enterprise~~~"/>
        <vers num="8.5.9" edition=":~~community~~~"/>
        <vers num="8.5.9" edition=":~~enterprise~~~"/>
        <vers num="8.5.10" edition=":~~community~~~"/>
        <vers num="8.5.10" edition=":~~enterprise~~~"/>
        <vers num="8.5.11" edition=":~~community~~~"/>
        <vers num="8.5.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.12" edition=":~~community~~~"/>
        <vers num="8.5.12" edition=":~~enterprise~~~"/>
        <vers num="8.5.13" edition=":~~community~~~"/>
        <vers num="8.5.13" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition=":~~community~~~"/>
        <vers num="8.6.0" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition="rc1:~~community~~~"/>
        <vers num="8.6.0" edition="rc2:~~community~~~"/>
        <vers num="8.6.0" edition="rc3:~~community~~~"/>
        <vers num="8.6.0" edition="rc5:~~community~~~"/>
        <vers num="8.6.1" edition=":~~community~~~"/>
        <vers num="8.6.1" edition=":~~enterprise~~~"/>
        <vers num="8.6.2" edition=":~~community~~~"/>
        <vers num="8.6.2" edition=":~~enterprise~~~"/>
        <vers num="8.6.3" edition=":~~community~~~"/>
        <vers num="8.6.3" edition=":~~enterprise~~~"/>
        <vers num="8.6.4" edition=":~~community~~~"/>
        <vers num="8.6.4" edition=":~~enterprise~~~"/>
        <vers num="8.6.5" edition=":~~community~~~"/>
        <vers num="8.6.5" edition=":~~enterprise~~~"/>
        <vers num="8.6.6" edition=":~~community~~~"/>
        <vers num="8.6.6" edition=":~~enterprise~~~"/>
        <vers num="8.6.7" edition=":~~community~~~"/>
        <vers num="8.6.7" edition=":~~enterprise~~~"/>
        <vers num="8.6.8" edition=":~~community~~~"/>
        <vers num="8.6.8" edition=":~~enterprise~~~"/>
        <vers num="8.6.9" edition=":~~community~~~"/>
        <vers num="8.6.9" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition=":~~community~~~"/>
        <vers num="8.7.0" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition="rc1:~~community~~~"/>
        <vers num="8.7.0" edition="rc2:~~community~~~"/>
        <vers num="8.7.0" edition="rc3:~~community~~~"/>
        <vers num="8.7.0" edition="rc4:~~community~~~"/>
        <vers num="8.7.0" edition="rc5:~~community~~~"/>
        <vers num="8.7.0" edition="rc6:~~community~~~"/>
        <vers num="8.7.0" edition="rc7:~~community~~~"/>
        <vers num="8.7.1" edition=":~~community~~~"/>
        <vers num="8.7.1" edition=":~~enterprise~~~"/>
        <vers num="8.7.2" edition=":~~community~~~"/>
        <vers num="8.7.2" edition=":~~enterprise~~~"/>
        <vers num="8.7.3" edition=":~~community~~~"/>
        <vers num="8.7.3" edition=":~~enterprise~~~"/>
        <vers num="8.7.4" edition=":~~community~~~"/>
        <vers num="8.7.4" edition=":~~enterprise~~~"/>
        <vers num="8.7.5" edition=":~~community~~~"/>
        <vers num="8.7.5" edition=":~~enterprise~~~"/>
        <vers num="8.7.6" edition=":~~community~~~"/>
        <vers num="8.7.6" edition=":~~enterprise~~~"/>
        <vers num="8.7.7" edition=":~~community~~~"/>
        <vers num="8.7.7" edition=":~~enterprise~~~"/>
        <vers num="8.7.8" edition=":~~community~~~"/>
        <vers num="8.7.8" edition=":~~enterprise~~~"/>
        <vers num="8.7.9" edition=":~~community~~~"/>
        <vers num="8.7.9" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.1.6" edition=":~~community~~~"/>
        <vers num="10.1.7" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0919" seq="2017-0919" published="2018-07-03" modified="2018-09-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/301137" adv="1">https://hackerone.com/reports/301137</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="0.8.0" edition=":~~community~~~"/>
        <vers num="0.8.0" edition=":~~enterprise~~~"/>
        <vers num="0.9.1" edition=":~~community~~~"/>
        <vers num="0.9.1" edition=":~~enterprise~~~"/>
        <vers num="0.9.4" edition=":~~community~~~"/>
        <vers num="0.9.4" edition=":~~enterprise~~~"/>
        <vers num="0.9.5" edition=":~~community~~~"/>
        <vers num="0.9.6" edition=":~~community~~~"/>
        <vers num="0.9.6" edition=":~~enterprise~~~"/>
        <vers num="1.0.0" edition=":~~community~~~"/>
        <vers num="1.0.0" edition=":~~enterprise~~~"/>
        <vers num="1.0.1" edition=":~~community~~~"/>
        <vers num="1.0.1" edition=":~~enterprise~~~"/>
        <vers num="1.0.2" edition=":~~community~~~"/>
        <vers num="1.0.2" edition=":~~enterprise~~~"/>
        <vers num="1.1.0" edition=":~~community~~~"/>
        <vers num="1.1.0" edition=":~~enterprise~~~"/>
        <vers num="1.1.0" edition="-:~~community~~~"/>
        <vers num="1.1.0" edition="pre:~~community~~~"/>
        <vers num="1.2.0" edition=":~~community~~~"/>
        <vers num="1.2.0" edition=":~~enterprise~~~"/>
        <vers num="1.2.0" edition="-:~~community~~~"/>
        <vers num="1.2.0" edition="pre:~~community~~~"/>
        <vers num="1.2.1" edition=":~~community~~~"/>
        <vers num="1.2.1" edition=":~~enterprise~~~"/>
        <vers num="1.2.2" edition=":~~community~~~"/>
        <vers num="1.2.2" edition=":~~enterprise~~~"/>
        <vers num="2.0.0" edition=":~~community~~~"/>
        <vers num="2.0.0" edition=":~~enterprise~~~"/>
        <vers num="2.1.0" edition=":~~community~~~"/>
        <vers num="2.1.0" edition=":~~enterprise~~~"/>
        <vers num="2.2.0" edition=":~~community~~~"/>
        <vers num="2.2.0" edition=":~~enterprise~~~"/>
        <vers num="2.2.0" edition="-:~~community~~~"/>
        <vers num="2.2.0" edition="pre:~~community~~~"/>
        <vers num="2.3.0" edition=":~~community~~~"/>
        <vers num="2.3.0" edition=":~~enterprise~~~"/>
        <vers num="2.3.0" edition="-:~~community~~~"/>
        <vers num="2.3.0" edition="pre:~~community~~~"/>
        <vers num="2.3.1" edition=":~~community~~~"/>
        <vers num="2.3.1" edition=":~~enterprise~~~"/>
        <vers num="2.4.0" edition=":~~community~~~"/>
        <vers num="2.4.0" edition=":~~enterprise~~~"/>
        <vers num="2.4.0" edition="-:~~community~~~"/>
        <vers num="2.4.0" edition="pre:~~community~~~"/>
        <vers num="2.4.1" edition=":~~community~~~"/>
        <vers num="2.4.2" edition=":~~community~~~"/>
        <vers num="2.5.0" edition=":~~community~~~"/>
        <vers num="2.5.0" edition=":~~enterprise~~~"/>
        <vers num="2.6.0" edition=":~~community~~~"/>
        <vers num="2.6.0" edition=":~~enterprise~~~"/>
        <vers num="2.6.0" edition="-:~~community~~~"/>
        <vers num="2.6.0" edition="pre:~~community~~~"/>
        <vers num="2.6.1" edition=":~~community~~~"/>
        <vers num="2.6.2" edition=":~~community~~~"/>
        <vers num="2.6.3" edition=":~~community~~~"/>
        <vers num="2.7.0" edition=":~~community~~~"/>
        <vers num="2.7.0" edition=":~~enterprise~~~"/>
        <vers num="2.7.0" edition="-:~~community~~~"/>
        <vers num="2.7.0" edition="pre:~~community~~~"/>
        <vers num="2.8.0" edition=":~~community~~~"/>
        <vers num="2.8.0" edition=":~~enterprise~~~"/>
        <vers num="2.8.0" edition="-:~~community~~~"/>
        <vers num="2.8.0" edition="pre:~~community~~~"/>
        <vers num="2.8.1" edition=":~~community~~~"/>
        <vers num="2.8.1" edition=":~~enterprise~~~"/>
        <vers num="2.8.2" edition=":~~community~~~"/>
        <vers num="2.9.0" edition=":~~community~~~"/>
        <vers num="2.9.0" edition=":~~enterprise~~~"/>
        <vers num="2.9.1" edition=":~~community~~~"/>
        <vers num="2.9.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.0" edition=":~~community~~~"/>
        <vers num="3.0.0" edition=":~~enterprise~~~"/>
        <vers num="3.0.1" edition=":~~community~~~"/>
        <vers num="3.0.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.2" edition=":~~community~~~"/>
        <vers num="3.0.2" edition=":~~enterprise~~~"/>
        <vers num="3.0.3" edition=":~~community~~~"/>
        <vers num="3.0.3" edition=":~~enterprise~~~"/>
        <vers num="3.1.0" edition=":~~community~~~"/>
        <vers num="3.1.0" edition=":~~enterprise~~~"/>
        <vers num="4.0.0" edition=":~~community~~~"/>
        <vers num="4.0.0" edition=":~~enterprise~~~"/>
        <vers num="4.0.0" edition="-:~~community~~~"/>
        <vers num="4.0.0" edition="rc1:~~community~~~"/>
        <vers num="4.0.0" edition="rc2:~~community~~~"/>
        <vers num="4.1.0" edition=":~~community~~~"/>
        <vers num="4.1.0" edition=":~~enterprise~~~"/>
        <vers num="4.2.0" edition=":~~community~~~"/>
        <vers num="4.2.0" edition=":~~enterprise~~~"/>
        <vers num="5.0.0" edition=":~~community~~~"/>
        <vers num="5.0.0" edition=":~~enterprise~~~"/>
        <vers num="5.0.1" edition=":~~community~~~"/>
        <vers num="5.0.1" edition=":~~enterprise~~~"/>
        <vers num="5.1.0" edition=":~~community~~~"/>
        <vers num="5.1.0" edition=":~~enterprise~~~"/>
        <vers num="5.2.0" edition=":~~community~~~"/>
        <vers num="5.2.0" edition=":~~enterprise~~~"/>
        <vers num="5.2.1" edition=":~~community~~~"/>
        <vers num="5.3.0" edition=":~~community~~~"/>
        <vers num="5.3.0" edition=":~~enterprise~~~"/>
        <vers num="5.4.0" edition=":~~community~~~"/>
        <vers num="5.4.0" edition=":~~enterprise~~~"/>
        <vers num="5.4.1" edition=":~~community~~~"/>
        <vers num="5.4.1" edition=":~~enterprise~~~"/>
        <vers num="5.4.2" edition=":~~community~~~"/>
        <vers num="5.4.2" edition=":~~enterprise~~~"/>
        <vers num="6.0.0" edition=":~~community~~~"/>
        <vers num="6.0.0" edition=":~~enterprise~~~"/>
        <vers num="6.0.1" edition=":~~community~~~"/>
        <vers num="6.0.2" edition=":~~community~~~"/>
        <vers num="6.1.0" edition=":~~community~~~"/>
        <vers num="6.1.0" edition=":~~enterprise~~~"/>
        <vers num="6.2.0" edition=":~~community~~~"/>
        <vers num="6.2.0" edition=":~~enterprise~~~"/>
        <vers num="6.2.1" edition=":~~community~~~"/>
        <vers num="6.2.1" edition=":~~enterprise~~~"/>
        <vers num="6.2.2" edition=":~~community~~~"/>
        <vers num="6.2.3" edition=":~~community~~~"/>
        <vers num="6.2.4" edition=":~~community~~~"/>
        <vers num="6.3.0" edition=":~~community~~~"/>
        <vers num="6.3.0" edition=":~~enterprise~~~"/>
        <vers num="6.3.1" edition=":~~community~~~"/>
        <vers num="6.4.0" edition=":~~enterprise~~~"/>
        <vers num="6.4.0" edition="-:~~community~~~"/>
        <vers num="6.4.0" edition="pre1:~~community~~~"/>
        <vers num="6.4.0" edition="pre2:~~community~~~"/>
        <vers num="6.4.0" edition="pre3:~~community~~~"/>
        <vers num="6.4.1" edition=":~~community~~~"/>
        <vers num="6.4.2" edition=":~~community~~~"/>
        <vers num="6.4.3" edition=":~~community~~~"/>
        <vers num="6.5.0" edition=":~~enterprise~~~"/>
        <vers num="6.5.0" edition="-:~~community~~~"/>
        <vers num="6.5.0" edition="rc1:~~community~~~"/>
        <vers num="6.6.0" edition=":~~enterprise~~~"/>
        <vers num="6.6.0" edition="-:~~community~~~"/>
        <vers num="6.6.0" edition="pre1:~~community~~~"/>
        <vers num="6.6.0" edition="rc1:~~community~~~"/>
        <vers num="6.6.1" edition=":~~community~~~"/>
        <vers num="6.6.1" edition=":~~enterprise~~~"/>
        <vers num="6.6.2" edition=":~~community~~~"/>
        <vers num="6.6.2" edition=":~~enterprise~~~"/>
        <vers num="6.6.3" edition=":~~community~~~"/>
        <vers num="6.6.4" edition=":~~community~~~"/>
        <vers num="6.6.5" edition=":~~community~~~"/>
        <vers num="6.7.0" edition=":~~enterprise~~~"/>
        <vers num="6.7.0" edition="-:~~community~~~"/>
        <vers num="6.7.0" edition="rc1:~~community~~~"/>
        <vers num="6.7.1" edition=":~~community~~~"/>
        <vers num="6.7.1" edition=":~~enterprise~~~"/>
        <vers num="6.7.2" edition=":~~community~~~"/>
        <vers num="6.7.3" edition=":~~community~~~"/>
        <vers num="6.7.4" edition=":~~community~~~"/>
        <vers num="6.7.5" edition=":~~community~~~"/>
        <vers num="6.8.0" edition=":~~enterprise~~~"/>
        <vers num="6.8.0" edition="-:~~community~~~"/>
        <vers num="6.8.0" edition="rc1:~~community~~~"/>
        <vers num="6.8.1" edition=":~~community~~~"/>
        <vers num="6.8.2" edition=":~~community~~~"/>
        <vers num="6.9.0" edition=":~~enterprise~~~"/>
        <vers num="6.9.0" edition="-:~~community~~~"/>
        <vers num="6.9.0" edition="rc1:~~community~~~"/>
        <vers num="6.9.1" edition=":~~community~~~"/>
        <vers num="6.9.1" edition=":~~enterprise~~~"/>
        <vers num="6.9.2" edition=":~~community~~~"/>
        <vers num="6.9.2" edition=":~~enterprise~~~"/>
        <vers num="6.9.3" edition=":~~enterprise~~~"/>
        <vers num="6.9.4" edition=":~~enterprise~~~"/>
        <vers num="7.0.0" edition=":~~enterprise~~~"/>
        <vers num="7.0.0" edition="-:~~community~~~"/>
        <vers num="7.0.0" edition="rc1:~~community~~~"/>
        <vers num="7.1.0" edition=":~~enterprise~~~"/>
        <vers num="7.1.0" edition="-:~~community~~~"/>
        <vers num="7.1.0" edition="rc1:~~community~~~"/>
        <vers num="7.1.1" edition=":~~community~~~"/>
        <vers num="7.2.0" edition=":~~enterprise~~~"/>
        <vers num="7.2.0" edition="-:~~community~~~"/>
        <vers num="7.2.0" edition="rc1:~~community~~~"/>
        <vers num="7.2.0" edition="rc2:~~community~~~"/>
        <vers num="7.2.0" edition="rc3:~~community~~~"/>
        <vers num="7.2.0" edition="rc4:~~community~~~"/>
        <vers num="7.2.0" edition="rc5:~~community~~~"/>
        <vers num="7.2.1" edition=":~~community~~~"/>
        <vers num="7.2.2" edition=":~~community~~~"/>
        <vers num="7.2.3" edition=":~~community~~~"/>
        <vers num="7.3.0" edition=":~~enterprise~~~"/>
        <vers num="7.3.0" edition="-:~~community~~~"/>
        <vers num="7.3.0" edition="rc1:~~community~~~"/>
        <vers num="7.3.1" edition=":~~community~~~"/>
        <vers num="7.3.2" edition=":~~community~~~"/>
        <vers num="7.3.3" edition=":~~community~~~"/>
        <vers num="7.4.0" edition=":~~enterprise~~~"/>
        <vers num="7.4.0" edition="-:~~community~~~"/>
        <vers num="7.4.0" edition="rc1:~~community~~~"/>
        <vers num="7.4.1" edition=":~~community~~~"/>
        <vers num="7.4.2" edition=":~~community~~~"/>
        <vers num="7.4.3" edition=":~~community~~~"/>
        <vers num="7.4.4" edition=":~~community~~~"/>
        <vers num="7.4.4" edition=":~~enterprise~~~"/>
        <vers num="7.4.5" edition=":~~community~~~"/>
        <vers num="7.5.0" edition=":~~community~~~"/>
        <vers num="7.5.0" edition=":~~enterprise~~~"/>
        <vers num="7.5.0" edition="rc1:~~community~~~"/>
        <vers num="7.5.1" edition=":~~community~~~"/>
        <vers num="7.5.2" edition=":~~community~~~"/>
        <vers num="7.5.3" edition=":~~community~~~"/>
        <vers num="7.5.3" edition=":~~enterprise~~~"/>
        <vers num="7.6.0" edition=":~~community~~~"/>
        <vers num="7.6.0" edition=":~~enterprise~~~"/>
        <vers num="7.6.0" edition="rc1:~~community~~~"/>
        <vers num="7.6.1" edition=":~~community~~~"/>
        <vers num="7.6.1" edition=":~~enterprise~~~"/>
        <vers num="7.6.2" edition=":~~community~~~"/>
        <vers num="7.6.2" edition=":~~enterprise~~~"/>
        <vers num="7.7.0" edition=":~~community~~~"/>
        <vers num="7.7.0" edition=":~~enterprise~~~"/>
        <vers num="7.7.0" edition="rc1:~~community~~~"/>
        <vers num="7.7.0" edition="rc2:~~community~~~"/>
        <vers num="7.7.0" edition="rc3:~~community~~~"/>
        <vers num="7.7.0" edition="rc4:~~community~~~"/>
        <vers num="7.7.1" edition=":~~community~~~"/>
        <vers num="7.7.2" edition=":~~community~~~"/>
        <vers num="7.8.0" edition=":~~community~~~"/>
        <vers num="7.8.0" edition=":~~enterprise~~~"/>
        <vers num="7.8.0" edition="rc1:~~community~~~"/>
        <vers num="7.8.0" edition="rc2:~~community~~~"/>
        <vers num="7.8.0" edition="rc3:~~community~~~"/>
        <vers num="7.8.0" edition="rc4:~~community~~~"/>
        <vers num="7.8.0" edition="rc5:~~community~~~"/>
        <vers num="7.8.0" edition="rc6:~~community~~~"/>
        <vers num="7.8.1" edition=":~~community~~~"/>
        <vers num="7.8.2" edition=":~~community~~~"/>
        <vers num="7.8.3" edition=":~~community~~~"/>
        <vers num="7.8.4" edition=":~~community~~~"/>
        <vers num="7.9.0" edition=":~~community~~~"/>
        <vers num="7.9.0" edition=":~~enterprise~~~"/>
        <vers num="7.9.0" edition="rc1:~~community~~~"/>
        <vers num="7.9.0" edition="rc2:~~community~~~"/>
        <vers num="7.9.0" edition="rc3:~~community~~~"/>
        <vers num="7.9.1" edition=":~~community~~~"/>
        <vers num="7.9.2" edition=":~~community~~~"/>
        <vers num="7.9.3" edition=":~~community~~~"/>
        <vers num="7.9.4" edition=":~~community~~~"/>
        <vers num="7.10.0" edition=":~~enterprise~~~"/>
        <vers num="7.10.0" edition="-:~~community~~~"/>
        <vers num="7.10.0" edition="rc1:~~community~~~"/>
        <vers num="7.10.0" edition="rc2:~~community~~~"/>
        <vers num="7.10.0" edition="rc3:~~community~~~"/>
        <vers num="7.10.0" edition="rc4:~~community~~~"/>
        <vers num="7.10.0" edition="rc5:~~community~~~"/>
        <vers num="7.10.0" edition="rc6:~~community~~~"/>
        <vers num="7.10.0" edition="rc7:~~community~~~"/>
        <vers num="7.10.0" edition="rc8:~~community~~~"/>
        <vers num="7.10.1" edition=":~~community~~~"/>
        <vers num="7.10.1" edition=":~~enterprise~~~"/>
        <vers num="7.10.2" edition=":~~community~~~"/>
        <vers num="7.10.3" edition=":~~community~~~"/>
        <vers num="7.10.4" edition=":~~community~~~"/>
        <vers num="7.10.5" edition=":~~community~~~"/>
        <vers num="7.11.0" edition=":~~enterprise~~~"/>
        <vers num="7.11.0" edition="-:~~community~~~"/>
        <vers num="7.11.0" edition="rc1:~~community~~~"/>
        <vers num="7.11.0" edition="rc2:~~community~~~"/>
        <vers num="7.11.1" edition=":~~community~~~"/>
        <vers num="7.11.2" edition=":~~community~~~"/>
        <vers num="7.11.2" edition=":~~enterprise~~~"/>
        <vers num="7.11.3" edition=":~~community~~~"/>
        <vers num="7.11.3" edition=":~~enterprise~~~"/>
        <vers num="7.11.4" edition=":~~community~~~"/>
        <vers num="7.11.4" edition=":~~enterprise~~~"/>
        <vers num="7.12.0" edition=":~~enterprise~~~"/>
        <vers num="7.12.0" edition="-:~~community~~~"/>
        <vers num="7.12.0" edition="rc1:~~community~~~"/>
        <vers num="7.12.0" edition="rc2:~~community~~~"/>
        <vers num="7.12.0" edition="rc3:~~community~~~"/>
        <vers num="7.12.1" edition=":~~community~~~"/>
        <vers num="7.12.1" edition=":~~enterprise~~~"/>
        <vers num="7.12.2" edition=":~~community~~~"/>
        <vers num="7.12.2" edition=":~~enterprise~~~"/>
        <vers num="7.13.0" edition=":~~enterprise~~~"/>
        <vers num="7.13.0" edition="-:~~community~~~"/>
        <vers num="7.13.0" edition="rc1:~~community~~~"/>
        <vers num="7.13.0" edition="rc2:~~community~~~"/>
        <vers num="7.13.0" edition="rc3:~~community~~~"/>
        <vers num="7.13.0" edition="rc4:~~community~~~"/>
        <vers num="7.13.1" edition=":~~community~~~"/>
        <vers num="7.13.1" edition=":~~enterprise~~~"/>
        <vers num="7.13.2" edition=":~~community~~~"/>
        <vers num="7.13.2" edition=":~~enterprise~~~"/>
        <vers num="7.13.3" edition=":~~community~~~"/>
        <vers num="7.13.3" edition=":~~enterprise~~~"/>
        <vers num="7.13.4" edition=":~~community~~~"/>
        <vers num="7.13.5" edition=":~~community~~~"/>
        <vers num="7.14.0" edition=":~~community~~~"/>
        <vers num="7.14.0" edition=":~~enterprise~~~"/>
        <vers num="7.14.0" edition="rc1:~~community~~~"/>
        <vers num="7.14.0" edition="rc2:~~community~~~"/>
        <vers num="7.14.0" edition="rc3:~~community~~~"/>
        <vers num="7.14.1" edition=":~~community~~~"/>
        <vers num="7.14.1" edition=":~~enterprise~~~"/>
        <vers num="7.14.2" edition=":~~community~~~"/>
        <vers num="7.14.2" edition=":~~enterprise~~~"/>
        <vers num="7.14.3" edition=":~~community~~~"/>
        <vers num="7.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.0.0" edition=":~~enterprise~~~"/>
        <vers num="8.0.0" edition="-:~~community~~~"/>
        <vers num="8.0.0" edition="rc1:~~community~~~"/>
        <vers num="8.0.0" edition="rc2:~~community~~~"/>
        <vers num="8.0.0" edition="rc3:~~community~~~"/>
        <vers num="8.0.0" edition="rc4:~~community~~~"/>
        <vers num="8.0.1" edition=":~~community~~~"/>
        <vers num="8.0.1" edition=":~~enterprise~~~"/>
        <vers num="8.0.2" edition=":~~community~~~"/>
        <vers num="8.0.2" edition=":~~enterprise~~~"/>
        <vers num="8.0.3" edition=":~~community~~~"/>
        <vers num="8.0.3" edition=":~~enterprise~~~"/>
        <vers num="8.0.4" edition=":~~community~~~"/>
        <vers num="8.0.4" edition=":~~enterprise~~~"/>
        <vers num="8.0.5" edition=":~~community~~~"/>
        <vers num="8.0.5" edition=":~~enterprise~~~"/>
        <vers num="8.0.6" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition="-:~~community~~~"/>
        <vers num="8.1.0" edition="rc1:~~community~~~"/>
        <vers num="8.1.0" edition="rc2:~~community~~~"/>
        <vers num="8.1.1" edition=":~~community~~~"/>
        <vers num="8.1.1" edition=":~~enterprise~~~"/>
        <vers num="8.1.2" edition=":~~community~~~"/>
        <vers num="8.1.2" edition=":~~enterprise~~~"/>
        <vers num="8.1.3" edition=":~~community~~~"/>
        <vers num="8.1.3" edition=":~~enterprise~~~"/>
        <vers num="8.1.4" edition=":~~community~~~"/>
        <vers num="8.1.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition=":~~community~~~"/>
        <vers num="8.2.0" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition="rc1:~~community~~~"/>
        <vers num="8.2.0" edition="rc2:~~community~~~"/>
        <vers num="8.2.1" edition=":~~community~~~"/>
        <vers num="8.2.1" edition=":~~enterprise~~~"/>
        <vers num="8.2.2" edition=":~~community~~~"/>
        <vers num="8.2.2" edition=":~~enterprise~~~"/>
        <vers num="8.2.3" edition=":~~community~~~"/>
        <vers num="8.2.3" edition=":~~enterprise~~~"/>
        <vers num="8.2.4" edition=":~~community~~~"/>
        <vers num="8.2.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.5" edition=":~~community~~~"/>
        <vers num="8.2.5" edition=":~~enterprise~~~"/>
        <vers num="8.2.6" edition=":~~community~~~"/>
        <vers num="8.2.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition=":~~community~~~"/>
        <vers num="8.3.0" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition="rc1:~~community~~~"/>
        <vers num="8.3.0" edition="rc2:~~community~~~"/>
        <vers num="8.3.0" edition="rc3:~~community~~~"/>
        <vers num="8.3.1" edition=":~~community~~~"/>
        <vers num="8.3.1" edition=":~~enterprise~~~"/>
        <vers num="8.3.2" edition=":~~community~~~"/>
        <vers num="8.3.2" edition=":~~enterprise~~~"/>
        <vers num="8.3.3" edition=":~~community~~~"/>
        <vers num="8.3.3" edition=":~~enterprise~~~"/>
        <vers num="8.3.4" edition=":~~community~~~"/>
        <vers num="8.3.4" edition=":~~enterprise~~~"/>
        <vers num="8.3.5" edition=":~~community~~~"/>
        <vers num="8.3.5" edition=":~~enterprise~~~"/>
        <vers num="8.3.6" edition=":~~community~~~"/>
        <vers num="8.3.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.7" edition=":~~community~~~"/>
        <vers num="8.3.7" edition=":~~enterprise~~~"/>
        <vers num="8.3.8" edition=":~~community~~~"/>
        <vers num="8.3.8" edition=":~~enterprise~~~"/>
        <vers num="8.3.9" edition=":~~community~~~"/>
        <vers num="8.3.9" edition=":~~enterprise~~~"/>
        <vers num="8.3.10" edition=":~~community~~~"/>
        <vers num="8.3.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition=":~~community~~~"/>
        <vers num="8.4.0" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition="rc1:~~community~~~"/>
        <vers num="8.4.0" edition="rc2:~~community~~~"/>
        <vers num="8.4.0" edition="rc3:~~community~~~"/>
        <vers num="8.4.1" edition=":~~community~~~"/>
        <vers num="8.4.1" edition=":~~enterprise~~~"/>
        <vers num="8.4.2" edition=":~~community~~~"/>
        <vers num="8.4.2" edition=":~~enterprise~~~"/>
        <vers num="8.4.3" edition=":~~community~~~"/>
        <vers num="8.4.3" edition=":~~enterprise~~~"/>
        <vers num="8.4.4" edition=":~~community~~~"/>
        <vers num="8.4.4" edition=":~~enterprise~~~"/>
        <vers num="8.4.5" edition=":~~community~~~"/>
        <vers num="8.4.5" edition=":~~enterprise~~~"/>
        <vers num="8.4.6" edition=":~~community~~~"/>
        <vers num="8.4.6" edition=":~~enterprise~~~"/>
        <vers num="8.4.7" edition=":~~community~~~"/>
        <vers num="8.4.7" edition=":~~enterprise~~~"/>
        <vers num="8.4.8" edition=":~~community~~~"/>
        <vers num="8.4.8" edition=":~~enterprise~~~"/>
        <vers num="8.4.9" edition=":~~community~~~"/>
        <vers num="8.4.9" edition=":~~enterprise~~~"/>
        <vers num="8.4.10" edition=":~~community~~~"/>
        <vers num="8.4.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.11" edition=":~~community~~~"/>
        <vers num="8.4.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition=":~~community~~~"/>
        <vers num="8.5.0" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition="rc1:~~community~~~"/>
        <vers num="8.5.0" edition="rc2:~~community~~~"/>
        <vers num="8.5.0" edition="rc3:~~community~~~"/>
        <vers num="8.5.0" edition="rc4:~~community~~~"/>
        <vers num="8.5.1" edition=":~~community~~~"/>
        <vers num="8.5.1" edition=":~~enterprise~~~"/>
        <vers num="8.5.2" edition=":~~community~~~"/>
        <vers num="8.5.2" edition=":~~enterprise~~~"/>
        <vers num="8.5.3" edition=":~~community~~~"/>
        <vers num="8.5.3" edition=":~~enterprise~~~"/>
        <vers num="8.5.4" edition=":~~community~~~"/>
        <vers num="8.5.4" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition="-:~~community~~~"/>
        <vers num="8.5.5" edition="rc1:~~community~~~"/>
        <vers num="8.5.6" edition=":~~community~~~"/>
        <vers num="8.5.6" edition=":~~enterprise~~~"/>
        <vers num="8.5.7" edition=":~~community~~~"/>
        <vers num="8.5.7" edition=":~~enterprise~~~"/>
        <vers num="8.5.8" edition=":~~community~~~"/>
        <vers num="8.5.8" edition=":~~enterprise~~~"/>
        <vers num="8.5.9" edition=":~~community~~~"/>
        <vers num="8.5.9" edition=":~~enterprise~~~"/>
        <vers num="8.5.10" edition=":~~community~~~"/>
        <vers num="8.5.10" edition=":~~enterprise~~~"/>
        <vers num="8.5.11" edition=":~~community~~~"/>
        <vers num="8.5.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.12" edition=":~~community~~~"/>
        <vers num="8.5.12" edition=":~~enterprise~~~"/>
        <vers num="8.5.13" edition=":~~community~~~"/>
        <vers num="8.5.13" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition=":~~community~~~"/>
        <vers num="8.6.0" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition="rc1:~~community~~~"/>
        <vers num="8.6.0" edition="rc2:~~community~~~"/>
        <vers num="8.6.0" edition="rc3:~~community~~~"/>
        <vers num="8.6.0" edition="rc5:~~community~~~"/>
        <vers num="8.6.1" edition=":~~community~~~"/>
        <vers num="8.6.1" edition=":~~enterprise~~~"/>
        <vers num="8.6.2" edition=":~~community~~~"/>
        <vers num="8.6.2" edition=":~~enterprise~~~"/>
        <vers num="8.6.3" edition=":~~community~~~"/>
        <vers num="8.6.3" edition=":~~enterprise~~~"/>
        <vers num="8.6.4" edition=":~~community~~~"/>
        <vers num="8.6.4" edition=":~~enterprise~~~"/>
        <vers num="8.6.5" edition=":~~community~~~"/>
        <vers num="8.6.5" edition=":~~enterprise~~~"/>
        <vers num="8.6.6" edition=":~~community~~~"/>
        <vers num="8.6.6" edition=":~~enterprise~~~"/>
        <vers num="8.6.7" edition=":~~community~~~"/>
        <vers num="8.6.7" edition=":~~enterprise~~~"/>
        <vers num="8.6.8" edition=":~~community~~~"/>
        <vers num="8.6.8" edition=":~~enterprise~~~"/>
        <vers num="8.6.9" edition=":~~community~~~"/>
        <vers num="8.6.9" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition=":~~community~~~"/>
        <vers num="8.7.0" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition="rc1:~~community~~~"/>
        <vers num="8.7.0" edition="rc2:~~community~~~"/>
        <vers num="8.7.0" edition="rc3:~~community~~~"/>
        <vers num="8.7.0" edition="rc4:~~community~~~"/>
        <vers num="8.7.0" edition="rc5:~~community~~~"/>
        <vers num="8.7.0" edition="rc6:~~community~~~"/>
        <vers num="8.7.0" edition="rc7:~~community~~~"/>
        <vers num="8.7.1" edition=":~~community~~~"/>
        <vers num="8.7.1" edition=":~~enterprise~~~"/>
        <vers num="8.7.2" edition=":~~community~~~"/>
        <vers num="8.7.2" edition=":~~enterprise~~~"/>
        <vers num="8.7.3" edition=":~~community~~~"/>
        <vers num="8.7.3" edition=":~~enterprise~~~"/>
        <vers num="8.7.4" edition=":~~community~~~"/>
        <vers num="8.7.4" edition=":~~enterprise~~~"/>
        <vers num="8.7.5" edition=":~~community~~~"/>
        <vers num="8.7.5" edition=":~~enterprise~~~"/>
        <vers num="8.7.6" edition=":~~community~~~"/>
        <vers num="8.7.6" edition=":~~enterprise~~~"/>
        <vers num="8.7.7" edition=":~~community~~~"/>
        <vers num="8.7.7" edition=":~~enterprise~~~"/>
        <vers num="8.7.8" edition=":~~community~~~"/>
        <vers num="8.7.8" edition=":~~enterprise~~~"/>
        <vers num="8.7.9" edition=":~~community~~~"/>
        <vers num="8.7.9" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="9.6.0" edition="-:~~community~~~"/>
        <vers num="9.6.0" edition="pre:~~community~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0920" seq="2017-0920" published="2018-03-22" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/301336">https://hackerone.com/reports/301336</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4206">DSA-4206</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="9.6.0" edition="-:~~community~~~"/>
        <vers num="9.6.0" edition="pre:~~community~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0921" seq="2017-0921" published="2018-07-03" modified="2018-09-04" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/" adv="1">https://about.gitlab.com/2018/05/29/security-release-gitlab-10-dot-8-dot-2-released/</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="0.8.0" edition=":~~community~~~"/>
        <vers num="0.8.0" edition=":~~enterprise~~~"/>
        <vers num="0.9.1" edition=":~~community~~~"/>
        <vers num="0.9.1" edition=":~~enterprise~~~"/>
        <vers num="0.9.4" edition=":~~community~~~"/>
        <vers num="0.9.4" edition=":~~enterprise~~~"/>
        <vers num="0.9.5" edition=":~~community~~~"/>
        <vers num="0.9.6" edition=":~~community~~~"/>
        <vers num="0.9.6" edition=":~~enterprise~~~"/>
        <vers num="1.0.0" edition=":~~community~~~"/>
        <vers num="1.0.0" edition=":~~enterprise~~~"/>
        <vers num="1.0.1" edition=":~~community~~~"/>
        <vers num="1.0.1" edition=":~~enterprise~~~"/>
        <vers num="1.0.2" edition=":~~community~~~"/>
        <vers num="1.0.2" edition=":~~enterprise~~~"/>
        <vers num="1.1.0" edition=":~~community~~~"/>
        <vers num="1.1.0" edition=":~~enterprise~~~"/>
        <vers num="1.1.0" edition="-:~~community~~~"/>
        <vers num="1.1.0" edition="pre:~~community~~~"/>
        <vers num="1.2.0" edition=":~~community~~~"/>
        <vers num="1.2.0" edition=":~~enterprise~~~"/>
        <vers num="1.2.0" edition="-:~~community~~~"/>
        <vers num="1.2.0" edition="pre:~~community~~~"/>
        <vers num="1.2.1" edition=":~~community~~~"/>
        <vers num="1.2.1" edition=":~~enterprise~~~"/>
        <vers num="1.2.2" edition=":~~community~~~"/>
        <vers num="1.2.2" edition=":~~enterprise~~~"/>
        <vers num="2.0.0" edition=":~~community~~~"/>
        <vers num="2.0.0" edition=":~~enterprise~~~"/>
        <vers num="2.1.0" edition=":~~community~~~"/>
        <vers num="2.1.0" edition=":~~enterprise~~~"/>
        <vers num="2.2.0" edition=":~~community~~~"/>
        <vers num="2.2.0" edition=":~~enterprise~~~"/>
        <vers num="2.2.0" edition="-:~~community~~~"/>
        <vers num="2.2.0" edition="pre:~~community~~~"/>
        <vers num="2.3.0" edition=":~~community~~~"/>
        <vers num="2.3.0" edition=":~~enterprise~~~"/>
        <vers num="2.3.0" edition="-:~~community~~~"/>
        <vers num="2.3.0" edition="pre:~~community~~~"/>
        <vers num="2.3.1" edition=":~~community~~~"/>
        <vers num="2.3.1" edition=":~~enterprise~~~"/>
        <vers num="2.4.0" edition=":~~community~~~"/>
        <vers num="2.4.0" edition=":~~enterprise~~~"/>
        <vers num="2.4.0" edition="-:~~community~~~"/>
        <vers num="2.4.0" edition="pre:~~community~~~"/>
        <vers num="2.4.1" edition=":~~community~~~"/>
        <vers num="2.4.2" edition=":~~community~~~"/>
        <vers num="2.5.0" edition=":~~community~~~"/>
        <vers num="2.5.0" edition=":~~enterprise~~~"/>
        <vers num="2.6.0" edition=":~~community~~~"/>
        <vers num="2.6.0" edition=":~~enterprise~~~"/>
        <vers num="2.6.0" edition="-:~~community~~~"/>
        <vers num="2.6.0" edition="pre:~~community~~~"/>
        <vers num="2.6.1" edition=":~~community~~~"/>
        <vers num="2.6.2" edition=":~~community~~~"/>
        <vers num="2.6.3" edition=":~~community~~~"/>
        <vers num="2.7.0" edition=":~~community~~~"/>
        <vers num="2.7.0" edition=":~~enterprise~~~"/>
        <vers num="2.7.0" edition="-:~~community~~~"/>
        <vers num="2.7.0" edition="pre:~~community~~~"/>
        <vers num="2.8.0" edition=":~~community~~~"/>
        <vers num="2.8.0" edition=":~~enterprise~~~"/>
        <vers num="2.8.0" edition="-:~~community~~~"/>
        <vers num="2.8.0" edition="pre:~~community~~~"/>
        <vers num="2.8.1" edition=":~~community~~~"/>
        <vers num="2.8.1" edition=":~~enterprise~~~"/>
        <vers num="2.8.2" edition=":~~community~~~"/>
        <vers num="2.9.0" edition=":~~community~~~"/>
        <vers num="2.9.0" edition=":~~enterprise~~~"/>
        <vers num="2.9.1" edition=":~~community~~~"/>
        <vers num="2.9.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.0" edition=":~~community~~~"/>
        <vers num="3.0.0" edition=":~~enterprise~~~"/>
        <vers num="3.0.1" edition=":~~community~~~"/>
        <vers num="3.0.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.2" edition=":~~community~~~"/>
        <vers num="3.0.2" edition=":~~enterprise~~~"/>
        <vers num="3.0.3" edition=":~~community~~~"/>
        <vers num="3.0.3" edition=":~~enterprise~~~"/>
        <vers num="3.1.0" edition=":~~community~~~"/>
        <vers num="3.1.0" edition=":~~enterprise~~~"/>
        <vers num="4.0.0" edition=":~~community~~~"/>
        <vers num="4.0.0" edition=":~~enterprise~~~"/>
        <vers num="4.0.0" edition="-:~~community~~~"/>
        <vers num="4.0.0" edition="rc1:~~community~~~"/>
        <vers num="4.0.0" edition="rc2:~~community~~~"/>
        <vers num="4.1.0" edition=":~~community~~~"/>
        <vers num="4.1.0" edition=":~~enterprise~~~"/>
        <vers num="4.2.0" edition=":~~community~~~"/>
        <vers num="4.2.0" edition=":~~enterprise~~~"/>
        <vers num="5.0.0" edition=":~~community~~~"/>
        <vers num="5.0.0" edition=":~~enterprise~~~"/>
        <vers num="5.0.1" edition=":~~community~~~"/>
        <vers num="5.0.1" edition=":~~enterprise~~~"/>
        <vers num="5.1.0" edition=":~~community~~~"/>
        <vers num="5.1.0" edition=":~~enterprise~~~"/>
        <vers num="5.2.0" edition=":~~community~~~"/>
        <vers num="5.2.0" edition=":~~enterprise~~~"/>
        <vers num="5.2.1" edition=":~~community~~~"/>
        <vers num="5.3.0" edition=":~~community~~~"/>
        <vers num="5.3.0" edition=":~~enterprise~~~"/>
        <vers num="5.4.0" edition=":~~community~~~"/>
        <vers num="5.4.0" edition=":~~enterprise~~~"/>
        <vers num="5.4.1" edition=":~~community~~~"/>
        <vers num="5.4.1" edition=":~~enterprise~~~"/>
        <vers num="5.4.2" edition=":~~community~~~"/>
        <vers num="5.4.2" edition=":~~enterprise~~~"/>
        <vers num="6.0.0" edition=":~~community~~~"/>
        <vers num="6.0.0" edition=":~~enterprise~~~"/>
        <vers num="6.0.1" edition=":~~community~~~"/>
        <vers num="6.0.2" edition=":~~community~~~"/>
        <vers num="6.1.0" edition=":~~community~~~"/>
        <vers num="6.1.0" edition=":~~enterprise~~~"/>
        <vers num="6.2.0" edition=":~~community~~~"/>
        <vers num="6.2.0" edition=":~~enterprise~~~"/>
        <vers num="6.2.1" edition=":~~community~~~"/>
        <vers num="6.2.1" edition=":~~enterprise~~~"/>
        <vers num="6.2.2" edition=":~~community~~~"/>
        <vers num="6.2.3" edition=":~~community~~~"/>
        <vers num="6.2.4" edition=":~~community~~~"/>
        <vers num="6.3.0" edition=":~~community~~~"/>
        <vers num="6.3.0" edition=":~~enterprise~~~"/>
        <vers num="6.3.1" edition=":~~community~~~"/>
        <vers num="6.4.0" edition=":~~enterprise~~~"/>
        <vers num="6.4.0" edition="-:~~community~~~"/>
        <vers num="6.4.0" edition="pre1:~~community~~~"/>
        <vers num="6.4.0" edition="pre2:~~community~~~"/>
        <vers num="6.4.0" edition="pre3:~~community~~~"/>
        <vers num="6.4.1" edition=":~~community~~~"/>
        <vers num="6.4.2" edition=":~~community~~~"/>
        <vers num="6.4.3" edition=":~~community~~~"/>
        <vers num="6.5.0" edition=":~~enterprise~~~"/>
        <vers num="6.5.0" edition="-:~~community~~~"/>
        <vers num="6.5.0" edition="rc1:~~community~~~"/>
        <vers num="6.6.0" edition=":~~enterprise~~~"/>
        <vers num="6.6.0" edition="-:~~community~~~"/>
        <vers num="6.6.0" edition="pre1:~~community~~~"/>
        <vers num="6.6.0" edition="rc1:~~community~~~"/>
        <vers num="6.6.1" edition=":~~community~~~"/>
        <vers num="6.6.1" edition=":~~enterprise~~~"/>
        <vers num="6.6.2" edition=":~~community~~~"/>
        <vers num="6.6.2" edition=":~~enterprise~~~"/>
        <vers num="6.6.3" edition=":~~community~~~"/>
        <vers num="6.6.4" edition=":~~community~~~"/>
        <vers num="6.6.5" edition=":~~community~~~"/>
        <vers num="6.7.0" edition=":~~enterprise~~~"/>
        <vers num="6.7.0" edition="-:~~community~~~"/>
        <vers num="6.7.0" edition="rc1:~~community~~~"/>
        <vers num="6.7.1" edition=":~~community~~~"/>
        <vers num="6.7.1" edition=":~~enterprise~~~"/>
        <vers num="6.7.2" edition=":~~community~~~"/>
        <vers num="6.7.3" edition=":~~community~~~"/>
        <vers num="6.7.4" edition=":~~community~~~"/>
        <vers num="6.7.5" edition=":~~community~~~"/>
        <vers num="6.8.0" edition=":~~enterprise~~~"/>
        <vers num="6.8.0" edition="-:~~community~~~"/>
        <vers num="6.8.0" edition="rc1:~~community~~~"/>
        <vers num="6.8.1" edition=":~~community~~~"/>
        <vers num="6.8.2" edition=":~~community~~~"/>
        <vers num="6.9.0" edition=":~~enterprise~~~"/>
        <vers num="6.9.0" edition="-:~~community~~~"/>
        <vers num="6.9.0" edition="rc1:~~community~~~"/>
        <vers num="6.9.1" edition=":~~community~~~"/>
        <vers num="6.9.1" edition=":~~enterprise~~~"/>
        <vers num="6.9.2" edition=":~~community~~~"/>
        <vers num="6.9.2" edition=":~~enterprise~~~"/>
        <vers num="6.9.3" edition=":~~enterprise~~~"/>
        <vers num="6.9.4" edition=":~~enterprise~~~"/>
        <vers num="7.0.0" edition=":~~enterprise~~~"/>
        <vers num="7.0.0" edition="-:~~community~~~"/>
        <vers num="7.0.0" edition="rc1:~~community~~~"/>
        <vers num="7.1.0" edition=":~~enterprise~~~"/>
        <vers num="7.1.0" edition="-:~~community~~~"/>
        <vers num="7.1.0" edition="rc1:~~community~~~"/>
        <vers num="7.1.1" edition=":~~community~~~"/>
        <vers num="7.2.0" edition=":~~enterprise~~~"/>
        <vers num="7.2.0" edition="-:~~community~~~"/>
        <vers num="7.2.0" edition="rc1:~~community~~~"/>
        <vers num="7.2.0" edition="rc2:~~community~~~"/>
        <vers num="7.2.0" edition="rc3:~~community~~~"/>
        <vers num="7.2.0" edition="rc4:~~community~~~"/>
        <vers num="7.2.0" edition="rc5:~~community~~~"/>
        <vers num="7.2.1" edition=":~~community~~~"/>
        <vers num="7.2.2" edition=":~~community~~~"/>
        <vers num="7.2.3" edition=":~~community~~~"/>
        <vers num="7.3.0" edition=":~~enterprise~~~"/>
        <vers num="7.3.0" edition="-:~~community~~~"/>
        <vers num="7.3.0" edition="rc1:~~community~~~"/>
        <vers num="7.3.1" edition=":~~community~~~"/>
        <vers num="7.3.2" edition=":~~community~~~"/>
        <vers num="7.3.3" edition=":~~community~~~"/>
        <vers num="7.4.0" edition=":~~enterprise~~~"/>
        <vers num="7.4.0" edition="-:~~community~~~"/>
        <vers num="7.4.0" edition="rc1:~~community~~~"/>
        <vers num="7.4.1" edition=":~~community~~~"/>
        <vers num="7.4.2" edition=":~~community~~~"/>
        <vers num="7.4.3" edition=":~~community~~~"/>
        <vers num="7.4.4" edition=":~~community~~~"/>
        <vers num="7.4.4" edition=":~~enterprise~~~"/>
        <vers num="7.4.5" edition=":~~community~~~"/>
        <vers num="7.5.0" edition=":~~community~~~"/>
        <vers num="7.5.0" edition=":~~enterprise~~~"/>
        <vers num="7.5.0" edition="rc1:~~community~~~"/>
        <vers num="7.5.1" edition=":~~community~~~"/>
        <vers num="7.5.2" edition=":~~community~~~"/>
        <vers num="7.5.3" edition=":~~community~~~"/>
        <vers num="7.5.3" edition=":~~enterprise~~~"/>
        <vers num="7.6.0" edition=":~~community~~~"/>
        <vers num="7.6.0" edition=":~~enterprise~~~"/>
        <vers num="7.6.0" edition="rc1:~~community~~~"/>
        <vers num="7.6.1" edition=":~~community~~~"/>
        <vers num="7.6.1" edition=":~~enterprise~~~"/>
        <vers num="7.6.2" edition=":~~community~~~"/>
        <vers num="7.6.2" edition=":~~enterprise~~~"/>
        <vers num="7.7.0" edition=":~~community~~~"/>
        <vers num="7.7.0" edition=":~~enterprise~~~"/>
        <vers num="7.7.0" edition="rc1:~~community~~~"/>
        <vers num="7.7.0" edition="rc2:~~community~~~"/>
        <vers num="7.7.0" edition="rc3:~~community~~~"/>
        <vers num="7.7.0" edition="rc4:~~community~~~"/>
        <vers num="7.7.1" edition=":~~community~~~"/>
        <vers num="7.7.2" edition=":~~community~~~"/>
        <vers num="7.8.0" edition=":~~community~~~"/>
        <vers num="7.8.0" edition=":~~enterprise~~~"/>
        <vers num="7.8.0" edition="rc1:~~community~~~"/>
        <vers num="7.8.0" edition="rc2:~~community~~~"/>
        <vers num="7.8.0" edition="rc3:~~community~~~"/>
        <vers num="7.8.0" edition="rc4:~~community~~~"/>
        <vers num="7.8.0" edition="rc5:~~community~~~"/>
        <vers num="7.8.0" edition="rc6:~~community~~~"/>
        <vers num="7.8.1" edition=":~~community~~~"/>
        <vers num="7.8.2" edition=":~~community~~~"/>
        <vers num="7.8.3" edition=":~~community~~~"/>
        <vers num="7.8.4" edition=":~~community~~~"/>
        <vers num="7.9.0" edition=":~~community~~~"/>
        <vers num="7.9.0" edition=":~~enterprise~~~"/>
        <vers num="7.9.0" edition="rc1:~~community~~~"/>
        <vers num="7.9.0" edition="rc2:~~community~~~"/>
        <vers num="7.9.0" edition="rc3:~~community~~~"/>
        <vers num="7.9.1" edition=":~~community~~~"/>
        <vers num="7.9.2" edition=":~~community~~~"/>
        <vers num="7.9.3" edition=":~~community~~~"/>
        <vers num="7.9.4" edition=":~~community~~~"/>
        <vers num="7.10.0" edition=":~~enterprise~~~"/>
        <vers num="7.10.0" edition="-:~~community~~~"/>
        <vers num="7.10.0" edition="rc1:~~community~~~"/>
        <vers num="7.10.0" edition="rc2:~~community~~~"/>
        <vers num="7.10.0" edition="rc3:~~community~~~"/>
        <vers num="7.10.0" edition="rc4:~~community~~~"/>
        <vers num="7.10.0" edition="rc5:~~community~~~"/>
        <vers num="7.10.0" edition="rc6:~~community~~~"/>
        <vers num="7.10.0" edition="rc7:~~community~~~"/>
        <vers num="7.10.0" edition="rc8:~~community~~~"/>
        <vers num="7.10.1" edition=":~~community~~~"/>
        <vers num="7.10.1" edition=":~~enterprise~~~"/>
        <vers num="7.10.2" edition=":~~community~~~"/>
        <vers num="7.10.3" edition=":~~community~~~"/>
        <vers num="7.10.4" edition=":~~community~~~"/>
        <vers num="7.10.5" edition=":~~community~~~"/>
        <vers num="7.11.0" edition=":~~enterprise~~~"/>
        <vers num="7.11.0" edition="-:~~community~~~"/>
        <vers num="7.11.0" edition="rc1:~~community~~~"/>
        <vers num="7.11.0" edition="rc2:~~community~~~"/>
        <vers num="7.11.1" edition=":~~community~~~"/>
        <vers num="7.11.2" edition=":~~community~~~"/>
        <vers num="7.11.2" edition=":~~enterprise~~~"/>
        <vers num="7.11.3" edition=":~~community~~~"/>
        <vers num="7.11.3" edition=":~~enterprise~~~"/>
        <vers num="7.11.4" edition=":~~community~~~"/>
        <vers num="7.11.4" edition=":~~enterprise~~~"/>
        <vers num="7.12.0" edition=":~~enterprise~~~"/>
        <vers num="7.12.0" edition="-:~~community~~~"/>
        <vers num="7.12.0" edition="rc1:~~community~~~"/>
        <vers num="7.12.0" edition="rc2:~~community~~~"/>
        <vers num="7.12.0" edition="rc3:~~community~~~"/>
        <vers num="7.12.1" edition=":~~community~~~"/>
        <vers num="7.12.1" edition=":~~enterprise~~~"/>
        <vers num="7.12.2" edition=":~~community~~~"/>
        <vers num="7.12.2" edition=":~~enterprise~~~"/>
        <vers num="7.13.0" edition=":~~enterprise~~~"/>
        <vers num="7.13.0" edition="-:~~community~~~"/>
        <vers num="7.13.0" edition="rc1:~~community~~~"/>
        <vers num="7.13.0" edition="rc2:~~community~~~"/>
        <vers num="7.13.0" edition="rc3:~~community~~~"/>
        <vers num="7.13.0" edition="rc4:~~community~~~"/>
        <vers num="7.13.1" edition=":~~community~~~"/>
        <vers num="7.13.1" edition=":~~enterprise~~~"/>
        <vers num="7.13.2" edition=":~~community~~~"/>
        <vers num="7.13.2" edition=":~~enterprise~~~"/>
        <vers num="7.13.3" edition=":~~community~~~"/>
        <vers num="7.13.3" edition=":~~enterprise~~~"/>
        <vers num="7.13.4" edition=":~~community~~~"/>
        <vers num="7.13.5" edition=":~~community~~~"/>
        <vers num="7.14.0" edition=":~~community~~~"/>
        <vers num="7.14.0" edition=":~~enterprise~~~"/>
        <vers num="7.14.0" edition="rc1:~~community~~~"/>
        <vers num="7.14.0" edition="rc2:~~community~~~"/>
        <vers num="7.14.0" edition="rc3:~~community~~~"/>
        <vers num="7.14.1" edition=":~~community~~~"/>
        <vers num="7.14.1" edition=":~~enterprise~~~"/>
        <vers num="7.14.2" edition=":~~community~~~"/>
        <vers num="7.14.2" edition=":~~enterprise~~~"/>
        <vers num="7.14.3" edition=":~~community~~~"/>
        <vers num="7.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.0.0" edition=":~~enterprise~~~"/>
        <vers num="8.0.0" edition="-:~~community~~~"/>
        <vers num="8.0.0" edition="rc1:~~community~~~"/>
        <vers num="8.0.0" edition="rc2:~~community~~~"/>
        <vers num="8.0.0" edition="rc3:~~community~~~"/>
        <vers num="8.0.0" edition="rc4:~~community~~~"/>
        <vers num="8.0.1" edition=":~~community~~~"/>
        <vers num="8.0.1" edition=":~~enterprise~~~"/>
        <vers num="8.0.2" edition=":~~community~~~"/>
        <vers num="8.0.2" edition=":~~enterprise~~~"/>
        <vers num="8.0.3" edition=":~~community~~~"/>
        <vers num="8.0.3" edition=":~~enterprise~~~"/>
        <vers num="8.0.4" edition=":~~community~~~"/>
        <vers num="8.0.4" edition=":~~enterprise~~~"/>
        <vers num="8.0.5" edition=":~~community~~~"/>
        <vers num="8.0.5" edition=":~~enterprise~~~"/>
        <vers num="8.0.6" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition="-:~~community~~~"/>
        <vers num="8.1.0" edition="rc1:~~community~~~"/>
        <vers num="8.1.0" edition="rc2:~~community~~~"/>
        <vers num="8.1.1" edition=":~~community~~~"/>
        <vers num="8.1.1" edition=":~~enterprise~~~"/>
        <vers num="8.1.2" edition=":~~community~~~"/>
        <vers num="8.1.2" edition=":~~enterprise~~~"/>
        <vers num="8.1.3" edition=":~~community~~~"/>
        <vers num="8.1.3" edition=":~~enterprise~~~"/>
        <vers num="8.1.4" edition=":~~community~~~"/>
        <vers num="8.1.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition=":~~community~~~"/>
        <vers num="8.2.0" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition="rc1:~~community~~~"/>
        <vers num="8.2.0" edition="rc2:~~community~~~"/>
        <vers num="8.2.1" edition=":~~community~~~"/>
        <vers num="8.2.1" edition=":~~enterprise~~~"/>
        <vers num="8.2.2" edition=":~~community~~~"/>
        <vers num="8.2.2" edition=":~~enterprise~~~"/>
        <vers num="8.2.3" edition=":~~community~~~"/>
        <vers num="8.2.3" edition=":~~enterprise~~~"/>
        <vers num="8.2.4" edition=":~~community~~~"/>
        <vers num="8.2.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.5" edition=":~~community~~~"/>
        <vers num="8.2.5" edition=":~~enterprise~~~"/>
        <vers num="8.2.6" edition=":~~community~~~"/>
        <vers num="8.2.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition=":~~community~~~"/>
        <vers num="8.3.0" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition="rc1:~~community~~~"/>
        <vers num="8.3.0" edition="rc2:~~community~~~"/>
        <vers num="8.3.0" edition="rc3:~~community~~~"/>
        <vers num="8.3.1" edition=":~~community~~~"/>
        <vers num="8.3.1" edition=":~~enterprise~~~"/>
        <vers num="8.3.2" edition=":~~community~~~"/>
        <vers num="8.3.2" edition=":~~enterprise~~~"/>
        <vers num="8.3.3" edition=":~~community~~~"/>
        <vers num="8.3.3" edition=":~~enterprise~~~"/>
        <vers num="8.3.4" edition=":~~community~~~"/>
        <vers num="8.3.4" edition=":~~enterprise~~~"/>
        <vers num="8.3.5" edition=":~~community~~~"/>
        <vers num="8.3.5" edition=":~~enterprise~~~"/>
        <vers num="8.3.6" edition=":~~community~~~"/>
        <vers num="8.3.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.7" edition=":~~community~~~"/>
        <vers num="8.3.7" edition=":~~enterprise~~~"/>
        <vers num="8.3.8" edition=":~~community~~~"/>
        <vers num="8.3.8" edition=":~~enterprise~~~"/>
        <vers num="8.3.9" edition=":~~community~~~"/>
        <vers num="8.3.9" edition=":~~enterprise~~~"/>
        <vers num="8.3.10" edition=":~~community~~~"/>
        <vers num="8.3.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition=":~~community~~~"/>
        <vers num="8.4.0" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition="rc1:~~community~~~"/>
        <vers num="8.4.0" edition="rc2:~~community~~~"/>
        <vers num="8.4.0" edition="rc3:~~community~~~"/>
        <vers num="8.4.1" edition=":~~community~~~"/>
        <vers num="8.4.1" edition=":~~enterprise~~~"/>
        <vers num="8.4.2" edition=":~~community~~~"/>
        <vers num="8.4.2" edition=":~~enterprise~~~"/>
        <vers num="8.4.3" edition=":~~community~~~"/>
        <vers num="8.4.3" edition=":~~enterprise~~~"/>
        <vers num="8.4.4" edition=":~~community~~~"/>
        <vers num="8.4.4" edition=":~~enterprise~~~"/>
        <vers num="8.4.5" edition=":~~community~~~"/>
        <vers num="8.4.5" edition=":~~enterprise~~~"/>
        <vers num="8.4.6" edition=":~~community~~~"/>
        <vers num="8.4.6" edition=":~~enterprise~~~"/>
        <vers num="8.4.7" edition=":~~community~~~"/>
        <vers num="8.4.7" edition=":~~enterprise~~~"/>
        <vers num="8.4.8" edition=":~~community~~~"/>
        <vers num="8.4.8" edition=":~~enterprise~~~"/>
        <vers num="8.4.9" edition=":~~community~~~"/>
        <vers num="8.4.9" edition=":~~enterprise~~~"/>
        <vers num="8.4.10" edition=":~~community~~~"/>
        <vers num="8.4.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.11" edition=":~~community~~~"/>
        <vers num="8.4.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition=":~~community~~~"/>
        <vers num="8.5.0" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition="rc1:~~community~~~"/>
        <vers num="8.5.0" edition="rc2:~~community~~~"/>
        <vers num="8.5.0" edition="rc3:~~community~~~"/>
        <vers num="8.5.0" edition="rc4:~~community~~~"/>
        <vers num="8.5.1" edition=":~~community~~~"/>
        <vers num="8.5.1" edition=":~~enterprise~~~"/>
        <vers num="8.5.2" edition=":~~community~~~"/>
        <vers num="8.5.2" edition=":~~enterprise~~~"/>
        <vers num="8.5.3" edition=":~~community~~~"/>
        <vers num="8.5.3" edition=":~~enterprise~~~"/>
        <vers num="8.5.4" edition=":~~community~~~"/>
        <vers num="8.5.4" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition="-:~~community~~~"/>
        <vers num="8.5.5" edition="rc1:~~community~~~"/>
        <vers num="8.5.6" edition=":~~community~~~"/>
        <vers num="8.5.6" edition=":~~enterprise~~~"/>
        <vers num="8.5.7" edition=":~~community~~~"/>
        <vers num="8.5.7" edition=":~~enterprise~~~"/>
        <vers num="8.5.8" edition=":~~community~~~"/>
        <vers num="8.5.8" edition=":~~enterprise~~~"/>
        <vers num="8.5.9" edition=":~~community~~~"/>
        <vers num="8.5.9" edition=":~~enterprise~~~"/>
        <vers num="8.5.10" edition=":~~community~~~"/>
        <vers num="8.5.10" edition=":~~enterprise~~~"/>
        <vers num="8.5.11" edition=":~~community~~~"/>
        <vers num="8.5.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.12" edition=":~~community~~~"/>
        <vers num="8.5.12" edition=":~~enterprise~~~"/>
        <vers num="8.5.13" edition=":~~community~~~"/>
        <vers num="8.5.13" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition=":~~community~~~"/>
        <vers num="8.6.0" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition="rc1:~~community~~~"/>
        <vers num="8.6.0" edition="rc2:~~community~~~"/>
        <vers num="8.6.0" edition="rc3:~~community~~~"/>
        <vers num="8.6.0" edition="rc5:~~community~~~"/>
        <vers num="8.6.1" edition=":~~community~~~"/>
        <vers num="8.6.1" edition=":~~enterprise~~~"/>
        <vers num="8.6.2" edition=":~~community~~~"/>
        <vers num="8.6.2" edition=":~~enterprise~~~"/>
        <vers num="8.6.3" edition=":~~community~~~"/>
        <vers num="8.6.3" edition=":~~enterprise~~~"/>
        <vers num="8.6.4" edition=":~~community~~~"/>
        <vers num="8.6.4" edition=":~~enterprise~~~"/>
        <vers num="8.6.5" edition=":~~community~~~"/>
        <vers num="8.6.5" edition=":~~enterprise~~~"/>
        <vers num="8.6.6" edition=":~~community~~~"/>
        <vers num="8.6.6" edition=":~~enterprise~~~"/>
        <vers num="8.6.7" edition=":~~community~~~"/>
        <vers num="8.6.7" edition=":~~enterprise~~~"/>
        <vers num="8.6.8" edition=":~~community~~~"/>
        <vers num="8.6.8" edition=":~~enterprise~~~"/>
        <vers num="8.6.9" edition=":~~community~~~"/>
        <vers num="8.6.9" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition=":~~community~~~"/>
        <vers num="8.7.0" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition="rc1:~~community~~~"/>
        <vers num="8.7.0" edition="rc2:~~community~~~"/>
        <vers num="8.7.0" edition="rc3:~~community~~~"/>
        <vers num="8.7.0" edition="rc4:~~community~~~"/>
        <vers num="8.7.0" edition="rc5:~~community~~~"/>
        <vers num="8.7.0" edition="rc6:~~community~~~"/>
        <vers num="8.7.0" edition="rc7:~~community~~~"/>
        <vers num="8.7.1" edition=":~~community~~~"/>
        <vers num="8.7.1" edition=":~~enterprise~~~"/>
        <vers num="8.7.2" edition=":~~community~~~"/>
        <vers num="8.7.2" edition=":~~enterprise~~~"/>
        <vers num="8.7.3" edition=":~~community~~~"/>
        <vers num="8.7.3" edition=":~~enterprise~~~"/>
        <vers num="8.7.4" edition=":~~community~~~"/>
        <vers num="8.7.4" edition=":~~enterprise~~~"/>
        <vers num="8.7.5" edition=":~~community~~~"/>
        <vers num="8.7.5" edition=":~~enterprise~~~"/>
        <vers num="8.7.6" edition=":~~community~~~"/>
        <vers num="8.7.6" edition=":~~enterprise~~~"/>
        <vers num="8.7.7" edition=":~~community~~~"/>
        <vers num="8.7.7" edition=":~~enterprise~~~"/>
        <vers num="8.7.8" edition=":~~community~~~"/>
        <vers num="8.7.8" edition=":~~enterprise~~~"/>
        <vers num="8.7.9" edition=":~~community~~~"/>
        <vers num="8.7.9" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="9.6.0" edition="-:~~community~~~"/>
        <vers num="9.6.0" edition="pre:~~community~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0922" seq="2017-0922" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/301123">https://hackerone.com/reports/301123</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0923" seq="2017-0923" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/293740">https://hackerone.com/reports/293740</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0924" seq="2017-0924" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="MISC" url="https://hackerone.com/reports/294099">https://hackerone.com/reports/294099</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0925" seq="2017-0925" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="CONFIRM" url="https://gitlab.com/gitlab-org/gitlab-ee/issues/3847">https://gitlab.com/gitlab-org/gitlab-ee/issues/3847</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.0.0" edition=":~~enterprise~~~"/>
        <vers num="8.0.0" edition="-:~~community~~~"/>
        <vers num="8.0.0" edition="rc1:~~community~~~"/>
        <vers num="8.0.0" edition="rc2:~~community~~~"/>
        <vers num="8.0.0" edition="rc3:~~community~~~"/>
        <vers num="8.0.0" edition="rc4:~~community~~~"/>
        <vers num="8.0.1" edition=":~~community~~~"/>
        <vers num="8.0.1" edition=":~~enterprise~~~"/>
        <vers num="8.0.2" edition=":~~community~~~"/>
        <vers num="8.0.2" edition=":~~enterprise~~~"/>
        <vers num="8.0.3" edition=":~~community~~~"/>
        <vers num="8.0.3" edition=":~~enterprise~~~"/>
        <vers num="8.0.4" edition=":~~community~~~"/>
        <vers num="8.0.4" edition=":~~enterprise~~~"/>
        <vers num="8.0.5" edition=":~~community~~~"/>
        <vers num="8.0.5" edition=":~~enterprise~~~"/>
        <vers num="8.0.6" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition=":~~enterprise~~~"/>
        <vers num="8.1.0" edition="-:~~community~~~"/>
        <vers num="8.1.0" edition="rc1:~~community~~~"/>
        <vers num="8.1.0" edition="rc2:~~community~~~"/>
        <vers num="8.1.1" edition=":~~community~~~"/>
        <vers num="8.1.1" edition=":~~enterprise~~~"/>
        <vers num="8.1.2" edition=":~~community~~~"/>
        <vers num="8.1.2" edition=":~~enterprise~~~"/>
        <vers num="8.1.3" edition=":~~community~~~"/>
        <vers num="8.1.3" edition=":~~enterprise~~~"/>
        <vers num="8.1.4" edition=":~~community~~~"/>
        <vers num="8.1.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition=":~~community~~~"/>
        <vers num="8.2.0" edition=":~~enterprise~~~"/>
        <vers num="8.2.0" edition="rc1:~~community~~~"/>
        <vers num="8.2.0" edition="rc2:~~community~~~"/>
        <vers num="8.2.1" edition=":~~community~~~"/>
        <vers num="8.2.1" edition=":~~enterprise~~~"/>
        <vers num="8.2.2" edition=":~~community~~~"/>
        <vers num="8.2.2" edition=":~~enterprise~~~"/>
        <vers num="8.2.3" edition=":~~community~~~"/>
        <vers num="8.2.3" edition=":~~enterprise~~~"/>
        <vers num="8.2.4" edition=":~~community~~~"/>
        <vers num="8.2.4" edition=":~~enterprise~~~"/>
        <vers num="8.2.5" edition=":~~community~~~"/>
        <vers num="8.2.5" edition=":~~enterprise~~~"/>
        <vers num="8.2.6" edition=":~~community~~~"/>
        <vers num="8.2.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition=":~~community~~~"/>
        <vers num="8.3.0" edition=":~~enterprise~~~"/>
        <vers num="8.3.0" edition="rc1:~~community~~~"/>
        <vers num="8.3.0" edition="rc2:~~community~~~"/>
        <vers num="8.3.0" edition="rc3:~~community~~~"/>
        <vers num="8.3.1" edition=":~~community~~~"/>
        <vers num="8.3.1" edition=":~~enterprise~~~"/>
        <vers num="8.3.2" edition=":~~community~~~"/>
        <vers num="8.3.2" edition=":~~enterprise~~~"/>
        <vers num="8.3.3" edition=":~~community~~~"/>
        <vers num="8.3.3" edition=":~~enterprise~~~"/>
        <vers num="8.3.4" edition=":~~community~~~"/>
        <vers num="8.3.4" edition=":~~enterprise~~~"/>
        <vers num="8.3.5" edition=":~~community~~~"/>
        <vers num="8.3.5" edition=":~~enterprise~~~"/>
        <vers num="8.3.6" edition=":~~community~~~"/>
        <vers num="8.3.6" edition=":~~enterprise~~~"/>
        <vers num="8.3.7" edition=":~~community~~~"/>
        <vers num="8.3.7" edition=":~~enterprise~~~"/>
        <vers num="8.3.8" edition=":~~community~~~"/>
        <vers num="8.3.8" edition=":~~enterprise~~~"/>
        <vers num="8.3.9" edition=":~~community~~~"/>
        <vers num="8.3.9" edition=":~~enterprise~~~"/>
        <vers num="8.3.10" edition=":~~community~~~"/>
        <vers num="8.3.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition=":~~community~~~"/>
        <vers num="8.4.0" edition=":~~enterprise~~~"/>
        <vers num="8.4.0" edition="rc1:~~community~~~"/>
        <vers num="8.4.0" edition="rc2:~~community~~~"/>
        <vers num="8.4.0" edition="rc3:~~community~~~"/>
        <vers num="8.4.1" edition=":~~community~~~"/>
        <vers num="8.4.1" edition=":~~enterprise~~~"/>
        <vers num="8.4.2" edition=":~~community~~~"/>
        <vers num="8.4.2" edition=":~~enterprise~~~"/>
        <vers num="8.4.3" edition=":~~community~~~"/>
        <vers num="8.4.3" edition=":~~enterprise~~~"/>
        <vers num="8.4.4" edition=":~~community~~~"/>
        <vers num="8.4.4" edition=":~~enterprise~~~"/>
        <vers num="8.4.5" edition=":~~community~~~"/>
        <vers num="8.4.5" edition=":~~enterprise~~~"/>
        <vers num="8.4.6" edition=":~~community~~~"/>
        <vers num="8.4.6" edition=":~~enterprise~~~"/>
        <vers num="8.4.7" edition=":~~community~~~"/>
        <vers num="8.4.7" edition=":~~enterprise~~~"/>
        <vers num="8.4.8" edition=":~~community~~~"/>
        <vers num="8.4.8" edition=":~~enterprise~~~"/>
        <vers num="8.4.9" edition=":~~community~~~"/>
        <vers num="8.4.9" edition=":~~enterprise~~~"/>
        <vers num="8.4.10" edition=":~~community~~~"/>
        <vers num="8.4.10" edition=":~~enterprise~~~"/>
        <vers num="8.4.11" edition=":~~community~~~"/>
        <vers num="8.4.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition=":~~community~~~"/>
        <vers num="8.5.0" edition=":~~enterprise~~~"/>
        <vers num="8.5.0" edition="rc1:~~community~~~"/>
        <vers num="8.5.0" edition="rc2:~~community~~~"/>
        <vers num="8.5.0" edition="rc3:~~community~~~"/>
        <vers num="8.5.0" edition="rc4:~~community~~~"/>
        <vers num="8.5.1" edition=":~~community~~~"/>
        <vers num="8.5.1" edition=":~~enterprise~~~"/>
        <vers num="8.5.2" edition=":~~community~~~"/>
        <vers num="8.5.2" edition=":~~enterprise~~~"/>
        <vers num="8.5.3" edition=":~~community~~~"/>
        <vers num="8.5.3" edition=":~~enterprise~~~"/>
        <vers num="8.5.4" edition=":~~community~~~"/>
        <vers num="8.5.4" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition="-:~~community~~~"/>
        <vers num="8.5.5" edition="rc1:~~community~~~"/>
        <vers num="8.5.6" edition=":~~community~~~"/>
        <vers num="8.5.6" edition=":~~enterprise~~~"/>
        <vers num="8.5.7" edition=":~~community~~~"/>
        <vers num="8.5.7" edition=":~~enterprise~~~"/>
        <vers num="8.5.8" edition=":~~community~~~"/>
        <vers num="8.5.8" edition=":~~enterprise~~~"/>
        <vers num="8.5.9" edition=":~~community~~~"/>
        <vers num="8.5.9" edition=":~~enterprise~~~"/>
        <vers num="8.5.10" edition=":~~community~~~"/>
        <vers num="8.5.10" edition=":~~enterprise~~~"/>
        <vers num="8.5.11" edition=":~~community~~~"/>
        <vers num="8.5.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.12" edition=":~~community~~~"/>
        <vers num="8.5.12" edition=":~~enterprise~~~"/>
        <vers num="8.5.13" edition=":~~community~~~"/>
        <vers num="8.5.13" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition=":~~community~~~"/>
        <vers num="8.6.0" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition="rc1:~~community~~~"/>
        <vers num="8.6.0" edition="rc2:~~community~~~"/>
        <vers num="8.6.0" edition="rc3:~~community~~~"/>
        <vers num="8.6.0" edition="rc5:~~community~~~"/>
        <vers num="8.6.1" edition=":~~community~~~"/>
        <vers num="8.6.1" edition=":~~enterprise~~~"/>
        <vers num="8.6.2" edition=":~~community~~~"/>
        <vers num="8.6.2" edition=":~~enterprise~~~"/>
        <vers num="8.6.3" edition=":~~community~~~"/>
        <vers num="8.6.3" edition=":~~enterprise~~~"/>
        <vers num="8.6.4" edition=":~~community~~~"/>
        <vers num="8.6.4" edition=":~~enterprise~~~"/>
        <vers num="8.6.5" edition=":~~community~~~"/>
        <vers num="8.6.5" edition=":~~enterprise~~~"/>
        <vers num="8.6.6" edition=":~~community~~~"/>
        <vers num="8.6.6" edition=":~~enterprise~~~"/>
        <vers num="8.6.7" edition=":~~community~~~"/>
        <vers num="8.6.7" edition=":~~enterprise~~~"/>
        <vers num="8.6.8" edition=":~~community~~~"/>
        <vers num="8.6.8" edition=":~~enterprise~~~"/>
        <vers num="8.6.9" edition=":~~community~~~"/>
        <vers num="8.6.9" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition=":~~community~~~"/>
        <vers num="8.7.0" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition="rc1:~~community~~~"/>
        <vers num="8.7.0" edition="rc2:~~community~~~"/>
        <vers num="8.7.0" edition="rc3:~~community~~~"/>
        <vers num="8.7.0" edition="rc4:~~community~~~"/>
        <vers num="8.7.0" edition="rc5:~~community~~~"/>
        <vers num="8.7.0" edition="rc6:~~community~~~"/>
        <vers num="8.7.0" edition="rc7:~~community~~~"/>
        <vers num="8.7.1" edition=":~~community~~~"/>
        <vers num="8.7.1" edition=":~~enterprise~~~"/>
        <vers num="8.7.2" edition=":~~community~~~"/>
        <vers num="8.7.2" edition=":~~enterprise~~~"/>
        <vers num="8.7.3" edition=":~~community~~~"/>
        <vers num="8.7.3" edition=":~~enterprise~~~"/>
        <vers num="8.7.4" edition=":~~community~~~"/>
        <vers num="8.7.4" edition=":~~enterprise~~~"/>
        <vers num="8.7.5" edition=":~~community~~~"/>
        <vers num="8.7.5" edition=":~~enterprise~~~"/>
        <vers num="8.7.6" edition=":~~community~~~"/>
        <vers num="8.7.6" edition=":~~enterprise~~~"/>
        <vers num="8.7.7" edition=":~~community~~~"/>
        <vers num="8.7.7" edition=":~~enterprise~~~"/>
        <vers num="8.7.8" edition=":~~community~~~"/>
        <vers num="8.7.8" edition=":~~enterprise~~~"/>
        <vers num="8.7.9" edition=":~~community~~~"/>
        <vers num="8.7.9" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0926" seq="2017-0926" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="CONFIRM" url="https://gitlab.com/gitlab-org/gitlab-ce/issues/32198">https://gitlab.com/gitlab-org/gitlab-ce/issues/32198</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4145" adv="1">DSA-4145</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.8.0" edition=":~~community~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition="rc1:~~community~~~"/>
        <vers num="8.8.0" edition="rc2:~~community~~~"/>
        <vers num="8.8.1" edition=":~~community~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~community~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~community~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~community~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~community~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~community~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~community~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~community~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~community~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~community~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition="rc1:~~community~~~"/>
        <vers num="8.9.0" edition="rc2:~~community~~~"/>
        <vers num="8.9.0" edition="rc3:~~community~~~"/>
        <vers num="8.9.0" edition="rc4:~~community~~~"/>
        <vers num="8.9.0" edition="rc5:~~community~~~"/>
        <vers num="8.9.0" edition="rc6:~~community~~~"/>
        <vers num="8.9.0" edition="rc7:~~community~~~"/>
        <vers num="8.9.0" edition="rc8:~~community~~~"/>
        <vers num="8.9.1" edition=":~~community~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~community~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~community~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~community~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~community~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~community~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~community~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.8" edition=":~~community~~~"/>
        <vers num="8.9.8" edition=":~~enterprise~~~"/>
        <vers num="8.9.9" edition=":~~community~~~"/>
        <vers num="8.9.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~community~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~community~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~community~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition="pre:~~community~~~"/>
        <vers num="8.10.0" edition="rc1:~~community~~~"/>
        <vers num="8.10.0" edition="rc10:~~community~~~"/>
        <vers num="8.10.0" edition="rc11:~~community~~~"/>
        <vers num="8.10.0" edition="rc12:~~community~~~"/>
        <vers num="8.10.0" edition="rc13:~~community~~~"/>
        <vers num="8.10.0" edition="rc2:~~community~~~"/>
        <vers num="8.10.0" edition="rc3:~~community~~~"/>
        <vers num="8.10.0" edition="rc4:~~community~~~"/>
        <vers num="8.10.0" edition="rc5:~~community~~~"/>
        <vers num="8.10.0" edition="rc6:~~community~~~"/>
        <vers num="8.10.0" edition="rc7:~~community~~~"/>
        <vers num="8.10.0" edition="rc8:~~community~~~"/>
        <vers num="8.10.0" edition="rc9:~~community~~~"/>
        <vers num="8.10.1" edition=":~~community~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~community~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~community~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~community~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~community~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~community~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~community~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~community~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~community~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~community~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~community~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~community~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~community~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~community~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition="pre:~~community~~~"/>
        <vers num="8.11.0" edition="rc1:~~community~~~"/>
        <vers num="8.11.0" edition="rc2:~~community~~~"/>
        <vers num="8.11.0" edition="rc3:~~community~~~"/>
        <vers num="8.11.0" edition="rc4:~~community~~~"/>
        <vers num="8.11.0" edition="rc5:~~community~~~"/>
        <vers num="8.11.0" edition="rc6:~~community~~~"/>
        <vers num="8.11.0" edition="rc7:~~community~~~"/>
        <vers num="8.11.1" edition=":~~community~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~community~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~community~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~community~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~community~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~community~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~community~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~community~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~community~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~community~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~community~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~community~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition="pre:~~community~~~"/>
        <vers num="8.12.0" edition="rc1:~~community~~~"/>
        <vers num="8.12.0" edition="rc2:~~community~~~"/>
        <vers num="8.12.0" edition="rc3:~~community~~~"/>
        <vers num="8.12.0" edition="rc4:~~community~~~"/>
        <vers num="8.12.0" edition="rc5:~~community~~~"/>
        <vers num="8.12.0" edition="rc6:~~community~~~"/>
        <vers num="8.12.0" edition="rc7:~~community~~~"/>
        <vers num="8.12.1" edition=":~~community~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~community~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~community~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~community~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~community~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~community~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~community~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~community~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~community~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~community~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~community~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~community~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.12.13" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~community~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition="pre:~~community~~~"/>
        <vers num="8.13.0" edition="rc1:~~community~~~"/>
        <vers num="8.13.0" edition="rc2:~~community~~~"/>
        <vers num="8.13.0" edition="rc3:~~community~~~"/>
        <vers num="8.13.0" edition="rc4:~~community~~~"/>
        <vers num="8.13.0" edition="rc5:~~community~~~"/>
        <vers num="8.13.0" edition="rc6:~~community~~~"/>
        <vers num="8.13.0" edition="rc7:~~community~~~"/>
        <vers num="8.13.1" edition=":~~community~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~community~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~community~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~community~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~community~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~community~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~community~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~community~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~community~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~community~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~community~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.13.12" edition=":~~community~~~"/>
        <vers num="8.13.12" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~community~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition="pre:~~community~~~"/>
        <vers num="8.14.0" edition="rc1:~~community~~~"/>
        <vers num="8.14.0" edition="rc2:~~community~~~"/>
        <vers num="8.14.0" edition="rc3:~~community~~~"/>
        <vers num="8.14.0" edition="rc4:~~community~~~"/>
        <vers num="8.14.0" edition="rc5:~~community~~~"/>
        <vers num="8.14.1" edition=":~~community~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~community~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~community~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~community~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~community~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~community~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.7" edition=":~~community~~~"/>
        <vers num="8.14.7" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~community~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~community~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~community~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~community~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~community~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~community~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~community~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~community~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.5" edition=":~~community~~~"/>
        <vers num="8.15.5" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~community~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~community~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~community~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0927" seq="2017-0927" published="2018-03-21" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/" adv="1">https://about.gitlab.com/2018/01/16/gitlab-10-dot-3-dot-4-released/</ref>
      <ref source="CONFIRM" url="https://gitlab.com/gitlab-org/gitlab-ce/issues/37594" adv="1">https://gitlab.com/gitlab-org/gitlab-ce/issues/37594</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.16.0" edition=":~~community~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition="pre:~~community~~~"/>
        <vers num="8.16.0" edition="rc1:~~community~~~"/>
        <vers num="8.16.0" edition="rc2:~~community~~~"/>
        <vers num="8.16.0" edition="rc3:~~community~~~"/>
        <vers num="8.16.0" edition="rc4:~~community~~~"/>
        <vers num="8.16.0" edition="rc5:~~community~~~"/>
        <vers num="8.16.0" edition="rc6:~~community~~~"/>
        <vers num="8.16.1" edition=":~~community~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~community~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~community~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~community~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~community~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~community~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~community~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~community~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~community~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~community~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition="pre:~~community~~~"/>
        <vers num="8.17.0" edition="rc1:~~community~~~"/>
        <vers num="8.17.0" edition="rc2:~~community~~~"/>
        <vers num="8.17.0" edition="rc3:~~community~~~"/>
        <vers num="8.17.0" edition="rc4:~~community~~~"/>
        <vers num="8.17.0" edition="rc5:~~community~~~"/>
        <vers num="8.17.1" edition=":~~community~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~community~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~community~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~community~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~community~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~community~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="8.17.7" edition=":~~community~~~"/>
        <vers num="8.17.7" edition=":~~enterprise~~~"/>
        <vers num="8.17.8" edition=":~~community~~~"/>
        <vers num="8.17.8" edition=":~~enterprise~~~"/>
        <vers num="8.18.0" edition="-:~~community~~~"/>
        <vers num="8.18.0" edition="pre:~~community~~~"/>
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition="rc1:~~community~~~"/>
        <vers num="9.0.0" edition="rc2:~~community~~~"/>
        <vers num="9.0.0" edition="rc3:~~community~~~"/>
        <vers num="9.0.0" edition="rc4:~~community~~~"/>
        <vers num="9.0.0" edition="rc5:~~community~~~"/>
        <vers num="9.0.0" edition="rc6:~~community~~~"/>
        <vers num="9.0.0" edition="rc7:~~community~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.0.11" edition=":~~community~~~"/>
        <vers num="9.0.11" edition=":~~enterprise~~~"/>
        <vers num="9.0.12" edition=":~~community~~~"/>
        <vers num="9.0.12" edition=":~~enterprise~~~"/>
        <vers num="9.0.13" edition=":~~community~~~"/>
        <vers num="9.0.13" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition="pre:~~community~~~"/>
        <vers num="9.1.0" edition="rc1:~~community~~~"/>
        <vers num="9.1.0" edition="rc2:~~community~~~"/>
        <vers num="9.1.0" edition="rc3:~~community~~~"/>
        <vers num="9.1.0" edition="rc4:~~community~~~"/>
        <vers num="9.1.0" edition="rc5:~~community~~~"/>
        <vers num="9.1.0" edition="rc6:~~community~~~"/>
        <vers num="9.1.0" edition="rc7:~~community~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.1.8" edition=":~~community~~~"/>
        <vers num="9.1.8" edition=":~~enterprise~~~"/>
        <vers num="9.1.9" edition=":~~community~~~"/>
        <vers num="9.1.9" edition=":~~enterprise~~~"/>
        <vers num="9.1.10" edition=":~~community~~~"/>
        <vers num="9.1.10" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition="pre:~~community~~~"/>
        <vers num="9.2.0" edition="rc1:~~community~~~"/>
        <vers num="9.2.0" edition="rc2:~~community~~~"/>
        <vers num="9.2.0" edition="rc3:~~community~~~"/>
        <vers num="9.2.0" edition="rc4:~~community~~~"/>
        <vers num="9.2.0" edition="rc5:~~community~~~"/>
        <vers num="9.2.0" edition="rc6:~~community~~~"/>
        <vers num="9.2.0" edition="rc7:~~community~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.8" edition=":~~community~~~"/>
        <vers num="9.2.8" edition=":~~enterprise~~~"/>
        <vers num="9.2.9" edition=":~~community~~~"/>
        <vers num="9.2.9" edition=":~~enterprise~~~"/>
        <vers num="9.2.10" edition=":~~community~~~"/>
        <vers num="9.2.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~community~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition="pre:~~community~~~"/>
        <vers num="9.3.0" edition="rc1:~~community~~~"/>
        <vers num="9.3.0" edition="rc2:~~community~~~"/>
        <vers num="9.3.0" edition="rc3:~~community~~~"/>
        <vers num="9.3.0" edition="rc4:~~community~~~"/>
        <vers num="9.3.0" edition="rc5:~~community~~~"/>
        <vers num="9.3.0" edition="rc6:~~community~~~"/>
        <vers num="9.3.0" edition="rc7:~~community~~~"/>
        <vers num="9.3.1" edition=":~~community~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~community~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~community~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~community~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~community~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~community~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~community~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.8" edition=":~~community~~~"/>
        <vers num="9.3.8" edition=":~~enterprise~~~"/>
        <vers num="9.3.9" edition=":~~community~~~"/>
        <vers num="9.3.9" edition=":~~enterprise~~~"/>
        <vers num="9.3.10" edition=":~~community~~~"/>
        <vers num="9.3.10" edition=":~~enterprise~~~"/>
        <vers num="9.3.11" edition=":~~community~~~"/>
        <vers num="9.3.11" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition=":~~community~~~"/>
        <vers num="9.4.0" edition=":~~enterprise~~~"/>
        <vers num="9.4.0" edition="rc1:~~community~~~"/>
        <vers num="9.4.0" edition="rc2:~~community~~~"/>
        <vers num="9.4.0" edition="rc3:~~community~~~"/>
        <vers num="9.4.0" edition="rc4:~~community~~~"/>
        <vers num="9.4.0" edition="rc5:~~community~~~"/>
        <vers num="9.4.0" edition="rc6:~~community~~~"/>
        <vers num="9.4.1" edition=":~~community~~~"/>
        <vers num="9.4.1" edition=":~~enterprise~~~"/>
        <vers num="9.4.2" edition=":~~community~~~"/>
        <vers num="9.4.2" edition=":~~enterprise~~~"/>
        <vers num="9.4.3" edition=":~~community~~~"/>
        <vers num="9.4.3" edition=":~~enterprise~~~"/>
        <vers num="9.4.4" edition=":~~community~~~"/>
        <vers num="9.4.4" edition=":~~enterprise~~~"/>
        <vers num="9.4.5" edition=":~~community~~~"/>
        <vers num="9.4.5" edition=":~~enterprise~~~"/>
        <vers num="9.4.6" edition=":~~community~~~"/>
        <vers num="9.4.6" edition=":~~enterprise~~~"/>
        <vers num="9.4.7" edition=":~~community~~~"/>
        <vers num="9.4.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition=":~~community~~~"/>
        <vers num="9.5.0" edition=":~~enterprise~~~"/>
        <vers num="9.5.0" edition="pre:~~community~~~"/>
        <vers num="9.5.0" edition="rc1:~~community~~~"/>
        <vers num="9.5.0" edition="rc2:~~community~~~"/>
        <vers num="9.5.0" edition="rc4:~~community~~~"/>
        <vers num="9.5.0" edition="rc5:~~community~~~"/>
        <vers num="9.5.0" edition="rc6:~~community~~~"/>
        <vers num="9.5.0" edition="rc8:~~community~~~"/>
        <vers num="9.5.1" edition=":~~community~~~"/>
        <vers num="9.5.1" edition=":~~enterprise~~~"/>
        <vers num="9.5.2" edition=":~~community~~~"/>
        <vers num="9.5.2" edition=":~~enterprise~~~"/>
        <vers num="9.5.3" edition=":~~community~~~"/>
        <vers num="9.5.3" edition=":~~enterprise~~~"/>
        <vers num="9.5.4" edition=":~~community~~~"/>
        <vers num="9.5.4" edition=":~~enterprise~~~"/>
        <vers num="9.5.5" edition=":~~community~~~"/>
        <vers num="9.5.5" edition=":~~enterprise~~~"/>
        <vers num="9.5.6" edition=":~~community~~~"/>
        <vers num="9.5.6" edition=":~~enterprise~~~"/>
        <vers num="9.5.7" edition=":~~community~~~"/>
        <vers num="9.5.7" edition=":~~enterprise~~~"/>
        <vers num="9.5.8" edition=":~~community~~~"/>
        <vers num="9.5.8" edition=":~~enterprise~~~"/>
        <vers num="9.5.9" edition=":~~community~~~"/>
        <vers num="9.5.9" edition=":~~enterprise~~~"/>
        <vers num="9.5.10" edition=":~~community~~~"/>
        <vers num="9.5.10" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition=":~~community~~~"/>
        <vers num="10.0.0" edition=":~~enterprise~~~"/>
        <vers num="10.0.0" edition="rc1:~~community~~~"/>
        <vers num="10.0.0" edition="rc2:~~community~~~"/>
        <vers num="10.0.0" edition="rc3:~~community~~~"/>
        <vers num="10.0.0" edition="rc4:~~community~~~"/>
        <vers num="10.0.0" edition="rc5:~~community~~~"/>
        <vers num="10.0.0" edition="rc6:~~community~~~"/>
        <vers num="10.0.1" edition=":~~community~~~"/>
        <vers num="10.0.1" edition=":~~enterprise~~~"/>
        <vers num="10.0.2" edition=":~~community~~~"/>
        <vers num="10.0.2" edition=":~~enterprise~~~"/>
        <vers num="10.0.3" edition=":~~community~~~"/>
        <vers num="10.0.3" edition=":~~enterprise~~~"/>
        <vers num="10.0.4" edition=":~~community~~~"/>
        <vers num="10.0.4" edition=":~~enterprise~~~"/>
        <vers num="10.0.5" edition=":~~community~~~"/>
        <vers num="10.0.5" edition=":~~enterprise~~~"/>
        <vers num="10.0.6" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~community~~~"/>
        <vers num="10.0.7" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition=":~~community~~~"/>
        <vers num="10.1.0" edition=":~~enterprise~~~"/>
        <vers num="10.1.0" edition="pre:~~community~~~"/>
        <vers num="10.1.0" edition="rc1:~~community~~~"/>
        <vers num="10.1.0" edition="rc2:~~community~~~"/>
        <vers num="10.1.0" edition="rc3:~~community~~~"/>
        <vers num="10.1.0" edition="rc4:~~community~~~"/>
        <vers num="10.1.1" edition=":~~community~~~"/>
        <vers num="10.1.1" edition=":~~enterprise~~~"/>
        <vers num="10.1.2" edition=":~~community~~~"/>
        <vers num="10.1.2" edition=":~~enterprise~~~"/>
        <vers num="10.1.3" edition=":~~community~~~"/>
        <vers num="10.1.3" edition=":~~enterprise~~~"/>
        <vers num="10.1.4" edition=":~~community~~~"/>
        <vers num="10.1.4" edition=":~~enterprise~~~"/>
        <vers num="10.1.5" edition=":~~community~~~"/>
        <vers num="10.1.5" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition=":~~community~~~"/>
        <vers num="10.2.0" edition=":~~enterprise~~~"/>
        <vers num="10.2.0" edition="pre:~~community~~~"/>
        <vers num="10.2.0" edition="rc1:~~community~~~"/>
        <vers num="10.2.0" edition="rc2:~~community~~~"/>
        <vers num="10.2.0" edition="rc3:~~community~~~"/>
        <vers num="10.2.0" edition="rc4:~~community~~~"/>
        <vers num="10.2.1" edition=":~~community~~~"/>
        <vers num="10.2.1" edition=":~~enterprise~~~"/>
        <vers num="10.2.2" edition=":~~community~~~"/>
        <vers num="10.2.2" edition=":~~enterprise~~~"/>
        <vers num="10.2.3" edition=":~~community~~~"/>
        <vers num="10.2.3" edition=":~~enterprise~~~"/>
        <vers num="10.2.4" edition=":~~community~~~"/>
        <vers num="10.2.4" edition=":~~enterprise~~~"/>
        <vers num="10.2.5" edition=":~~community~~~"/>
        <vers num="10.2.5" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition=":~~community~~~"/>
        <vers num="10.3.0" edition=":~~enterprise~~~"/>
        <vers num="10.3.0" edition="pre:~~community~~~"/>
        <vers num="10.3.0" edition="rc1:~~community~~~"/>
        <vers num="10.3.0" edition="rc2:~~community~~~"/>
        <vers num="10.3.0" edition="rc3:~~community~~~"/>
        <vers num="10.3.0" edition="rc4:~~community~~~"/>
        <vers num="10.3.0" edition="rc5:~~community~~~"/>
        <vers num="10.3.1" edition=":~~community~~~"/>
        <vers num="10.3.1" edition=":~~enterprise~~~"/>
        <vers num="10.3.2" edition=":~~community~~~"/>
        <vers num="10.3.2" edition=":~~enterprise~~~"/>
        <vers num="10.3.3" edition=":~~community~~~"/>
        <vers num="10.3.3" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0928" seq="2017-0928" published="2018-06-04" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/guardian/html-janitor/issues/35" adv="1">https://github.com/guardian/html-janitor/issues/35</ref>
      <ref source="MISC" url="https://hackerone.com/reports/308158" adv="1">https://hackerone.com/reports/308158</ref>
    </refs>
    <vuln_soft>
      <prod name="html-janitor" vendor="theguardian">
        <vers num="2.0.2" edition=":~~~node.js~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0929" seq="2017-0929" published="2018-07-03" modified="2018-09-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/dnnsoftware/Dnn.Platform/commit/d3953db85fee77bb5e6383747692c507ef8b94c3" adv="1">https://github.com/dnnsoftware/Dnn.Platform/commit/d3953db85fee77bb5e6383747692c507ef8b94c3</ref>
    </refs>
    <vuln_soft>
      <prod name="dotnetnuke" vendor="dnnsoftware">
        <vers num="7.1.2.164"/>
        <vers num="7.1.2.165"/>
        <vers num="7.1.2.166"/>
        <vers num="7.1.2.167"/>
        <vers num="7.1.2.168"/>
        <vers num="7.1.2.169"/>
        <vers num="7.1.2.170"/>
        <vers num="7.1.2.171"/>
        <vers num="7.1.2.172"/>
        <vers num="7.1.2.173"/>
        <vers num="7.1.2.174"/>
        <vers num="7.1.2.175"/>
        <vers num="7.1.2.176"/>
        <vers num="7.1.2.177"/>
        <vers num="7.1.2.178"/>
        <vers num="7.1.2.179"/>
        <vers num="7.1.2.180"/>
        <vers num="7.1.2.181"/>
        <vers num="7.1.2.182"/>
        <vers num="7.1.2.183"/>
        <vers num="7.1.2.184"/>
        <vers num="7.1.2.185"/>
        <vers num="7.1.2.186"/>
        <vers num="7.1.2.187"/>
        <vers num="7.1.2.188"/>
        <vers num="7.1.2.189"/>
        <vers num="7.1.2.190"/>
        <vers num="7.1.2.191"/>
        <vers num="7.1.2.192"/>
        <vers num="7.1.2.193"/>
        <vers num="7.1.2.194"/>
        <vers num="7.1.2.195"/>
        <vers num="7.1.2.196"/>
        <vers num="7.1.2.197"/>
        <vers num="7.1.2.198"/>
        <vers num="7.1.2.199"/>
        <vers num="7.1.2.200"/>
        <vers num="7.1.2.201"/>
        <vers num="7.1.2.202"/>
        <vers num="7.1.2.203"/>
        <vers num="7.1.2.204"/>
        <vers num="7.1.2.205"/>
        <vers num="7.1.2.206"/>
        <vers num="7.1.2.207"/>
        <vers num="7.1.2.208"/>
        <vers num="7.1.2.209"/>
        <vers num="7.1.2.210"/>
        <vers num="7.1.2.211"/>
        <vers num="7.1.2.212"/>
        <vers num="7.1.2.213"/>
        <vers num="7.1.2.214"/>
        <vers num="7.1.2.215"/>
        <vers num="7.1.2.216"/>
        <vers num="7.1.2.217"/>
        <vers num="7.1.2.218"/>
        <vers num="7.1.2.219"/>
        <vers num="7.1.2.220"/>
        <vers num="7.1.2.221"/>
        <vers num="7.1.2.222"/>
        <vers num="7.1.2.223"/>
        <vers num="7.1.2.224"/>
        <vers num="7.1.2.225"/>
        <vers num="7.1.2.226"/>
        <vers num="7.1.2.227"/>
        <vers num="7.1.2.228"/>
        <vers num="7.2.0.607"/>
        <vers num="7.2.1.367"/>
        <vers num="7.3.0.499"/>
        <vers num="7.3.1.20"/>
        <vers num="7.3.2.109"/>
        <vers num="7.3.3.118"/>
        <vers num="7.3.4.45"/>
        <vers num="7.4.0.353"/>
        <vers num="7.5.0.875" edition="alpha"/>
        <vers num="7.5.0.885" edition="alpha"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.1.0"/>
        <vers num="9.1.1"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0930" seq="2017-0930" published="2018-06-04" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/296282" adv="1">https://hackerone.com/reports/296282</ref>
    </refs>
    <vuln_soft>
      <prod name="augustine" vendor="augustine_project">
        <vers num="0.2.3" edition=":~~~node.js~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0931" seq="2017-0931" published="2018-06-04" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/guardian/html-janitor/issues/34" adv="1">https://github.com/guardian/html-janitor/issues/34</ref>
      <ref source="MISC" url="https://hackerone.com/reports/308155" adv="1">https://hackerone.com/reports/308155</ref>
    </refs>
    <vuln_soft>
      <prod name="html-janitor" vendor="theguardian">
        <vers num="2.0.2" edition=":~~~node.js~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0932" seq="2017-0932" published="2018-03-22" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionality. An attacker with access to an operator (read-only) account and ssh connection to the devices could escalate privileges to admin (root) access in the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117" adv="1" patch="1">https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117</ref>
      <ref source="MISC" url="https://hackerone.com/reports/239719" adv="1">https://hackerone.com/reports/239719</ref>
    </refs>
    <vuln_soft>
      <prod name="edgeos" vendor="ubnt">
        <vers num="1.9.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0933" seq="2017-0933" published="2018-03-22" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524" adv="1" patch="1">https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524</ref>
      <ref source="MISC" url="https://hackerone.com/reports/240098" adv="1">https://hackerone.com/reports/240098</ref>
    </refs>
    <vuln_soft>
      <prod name="edgeos" vendor="ubnt">
        <vers num="1.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0934" seq="2017-0934" published="2018-03-22" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524" adv="1" patch="1">https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524</ref>
      <ref source="MISC" url="https://hackerone.com/reports/241044" adv="1">https://hackerone.com/reports/241044</ref>
    </refs>
    <vuln_soft>
      <prod name="edgeos" vendor="ubnt">
        <vers num="1.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0935" seq="2017-0935" published="2018-03-22" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117" adv="1" patch="1">https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-3/ba-p/2054117</ref>
      <ref source="MISC" url="https://hackerone.com/reports/242407" adv="1">https://hackerone.com/reports/242407</ref>
    </refs>
    <vuln_soft>
      <prod name="edgeos" vendor="ubnt">
        <vers num="1.9.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0936" seq="2017-0936" published="2018-03-28" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/297751" adv="1">https://hackerone.com/reports/297751</ref>
      <ref source="CONFIRM" url="https://nextcloud.com/security/advisory/?id=nc-sa-2018-001" adv="1">https://nextcloud.com/security/advisory/?id=nc-sa-2018-001</ref>
    </refs>
    <vuln_soft>
      <prod name="nextcloud_server" vendor="nextcloud">
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.1"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="3.0" edition="alpha1"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0.1"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.0" edition="rc"/>
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.5.0" edition="beta1"/>
        <vers num="4.5.0" edition="beta2"/>
        <vers num="4.5.0" edition="beta3"/>
        <vers num="4.5.0" edition="beta4"/>
        <vers num="4.5.0" edition="rc1"/>
        <vers num="4.5.0" edition="rc2"/>
        <vers num="4.5.0" edition="rc3"/>
        <vers num="4.5.1" edition="alpha"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.5.9"/>
        <vers num="4.5.10" edition="rc1"/>
        <vers num="4.5.11"/>
        <vers num="4.5.12"/>
        <vers num="4.5.13"/>
        <vers num="5.0.0" edition="alpha1"/>
        <vers num="5.0.0" edition="beta1"/>
        <vers num="5.0.0" edition="beta2"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition="rc1"/>
        <vers num="5.0.5" edition="rc1"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14" edition="alpha"/>
        <vers num="5.0.15" edition="rc1"/>
        <vers num="5.0.16" edition="rc1"/>
        <vers num="5.0.17" edition="beta1"/>
        <vers num="5.0.19"/>
        <vers num="6.0.0" edition="alpha"/>
        <vers num="6.0.0" edition="alpha2"/>
        <vers num="6.0.0" edition="beta2"/>
        <vers num="6.0.0" edition="beta3"/>
        <vers num="6.0.0" edition="beta4"/>
        <vers num="6.0.0" edition="beta5"/>
        <vers num="6.0.0" edition="rc1"/>
        <vers num="6.0.0" edition="rc2"/>
        <vers num="6.0.0" edition="rc3"/>
        <vers num="6.0.0" edition="rc4"/>
        <vers num="6.0.1" edition="rc1"/>
        <vers num="6.0.2" edition="rc1"/>
        <vers num="6.0.3" edition="rc1"/>
        <vers num="6.0.4" edition="beta1"/>
        <vers num="6.0.5" edition="rc1"/>
        <vers num="6.0.6" edition="rc1"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8" edition="rc1"/>
        <vers num="6.0.8" edition="rc2"/>
        <vers num="6.0.9" edition="beta"/>
        <vers num="6.0.9" edition="rc1"/>
        <vers num="6.0.10" edition="beta1"/>
        <vers num="7.0.0" edition="alpha2"/>
        <vers num="7.0.0" edition="beta1"/>
        <vers num="7.0.0" edition="rc1"/>
        <vers num="7.0.0" edition="rc2"/>
        <vers num="7.0.0" edition="rc3"/>
        <vers num="7.0.1" edition="rc1"/>
        <vers num="7.0.2" edition="rc1"/>
        <vers num="7.0.3" edition="alpha1"/>
        <vers num="7.0.3" edition="rc1"/>
        <vers num="7.0.3" edition="rc2"/>
        <vers num="7.0.3" edition="rc3"/>
        <vers num="7.0.4" edition="rc1"/>
        <vers num="7.0.4" edition="rc2"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6" edition="rc1"/>
        <vers num="7.0.6" edition="rc2"/>
        <vers num="7.0.7" edition="beta"/>
        <vers num="7.0.7" edition="rc1"/>
        <vers num="7.0.8" edition="beta1"/>
        <vers num="7.0.8" edition="rc1"/>
        <vers num="7.0.9" edition="rc1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11" edition="rc1"/>
        <vers num="7.0.11" edition="rc2"/>
        <vers num="7.0.12" edition="rc1"/>
        <vers num="7.0.13" edition="rc1"/>
        <vers num="7.0.13" edition="rc2"/>
        <vers num="7.0.14" edition="rc1"/>
        <vers num="7.0.14" edition="rc2"/>
        <vers num="7.0.15" edition="rc1"/>
        <vers num="7.0.15" edition="rc2"/>
        <vers num="8.0.0" edition="alpha1"/>
        <vers num="8.0.0" edition="alpha2"/>
        <vers num="8.0.0" edition="beta1"/>
        <vers num="8.0.0" edition="beta2"/>
        <vers num="8.0.0" edition="rc1"/>
        <vers num="8.0.0" edition="rc2"/>
        <vers num="8.0.1" edition="rc1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3" edition="rc1"/>
        <vers num="8.0.3" edition="rc2"/>
        <vers num="8.0.3" edition="rc3"/>
        <vers num="8.0.3" edition="rc4"/>
        <vers num="8.0.4" edition="rc1"/>
        <vers num="8.0.4" edition="rc2"/>
        <vers num="8.0.5" edition="beta"/>
        <vers num="8.0.5" edition="rc1"/>
        <vers num="8.0.6" edition="beta1"/>
        <vers num="8.0.6" edition="rc1"/>
        <vers num="8.0.7" edition="rc1"/>
        <vers num="8.0.8"/>
        <vers num="8.0.9" edition="rc1"/>
        <vers num="8.0.9" edition="rc2"/>
        <vers num="8.0.10" edition="rc1"/>
        <vers num="8.0.11" edition="rc1"/>
        <vers num="8.0.11" edition="rc2"/>
        <vers num="8.0.12" edition="rc1"/>
        <vers num="8.0.12" edition="rc2"/>
        <vers num="8.0.13" edition="rc1"/>
        <vers num="8.0.13" edition="rc2"/>
        <vers num="8.0.14" edition="rc2"/>
        <vers num="8.0.15" edition="rc1"/>
        <vers num="8.0.16" edition="rc1"/>
        <vers num="8.0.16" edition="rc2"/>
        <vers num="8.1" edition="rc2"/>
        <vers num="8.1.0" edition="alpha1"/>
        <vers num="8.1.0" edition="alpha2"/>
        <vers num="8.1.0" edition="beta1"/>
        <vers num="8.1.0" edition="beta2"/>
        <vers num="8.1.1" edition="beta"/>
        <vers num="8.1.1" edition="beta1"/>
        <vers num="8.1.1" edition="rc1"/>
        <vers num="8.1.2" edition="rc1"/>
        <vers num="8.1.3"/>
        <vers num="8.1.4" edition="rc1"/>
        <vers num="8.1.4" edition="rc2"/>
        <vers num="8.1.5" edition="rc1"/>
        <vers num="8.1.6" edition="rc1"/>
        <vers num="8.1.6" edition="rc2"/>
        <vers num="8.1.7" edition="rc1"/>
        <vers num="8.1.7" edition="rc2"/>
        <vers num="8.1.8" edition="rc1"/>
        <vers num="8.1.8" edition="rc2"/>
        <vers num="8.1.9" edition="rc1"/>
        <vers num="8.1.9" edition="rc2"/>
        <vers num="8.1.10" edition="rc1"/>
        <vers num="8.1.11" edition="rc1"/>
        <vers num="8.1.11" edition="rc2"/>
        <vers num="8.2" edition="beta1"/>
        <vers num="8.2" edition="rc1"/>
        <vers num="8.2" edition="rc2"/>
        <vers num="8.2" edition="rc3"/>
        <vers num="8.2.0"/>
        <vers num="8.2.1" edition="rc1"/>
        <vers num="8.2.1" edition="rc2"/>
        <vers num="8.2.1" edition="rc3"/>
        <vers num="8.2.1" edition="rc4"/>
        <vers num="8.2.2" edition="rc1"/>
        <vers num="8.2.3" edition="rc1"/>
        <vers num="8.2.3" edition="rc2"/>
        <vers num="8.2.4" edition="rc1"/>
        <vers num="8.2.4" edition="rc2"/>
        <vers num="8.2.5" edition="rc1"/>
        <vers num="8.2.5" edition="rc2"/>
        <vers num="8.2.6" edition="rc1"/>
        <vers num="8.2.7" edition="rc1"/>
        <vers num="8.2.8" edition="rc1"/>
        <vers num="8.2.8" edition="rc2"/>
        <vers num="8.2.9" edition="rc1"/>
        <vers num="8.2.9" edition="rc2"/>
        <vers num="9.0" edition="beta1"/>
        <vers num="9.0.0" edition="beta2"/>
        <vers num="9.0.0" edition="rc1"/>
        <vers num="9.0.0" edition="rc2"/>
        <vers num="9.0.0" edition="rc3"/>
        <vers num="9.0.1" edition="beta"/>
        <vers num="9.0.1" edition="beta2"/>
        <vers num="9.0.1" edition="rc1"/>
        <vers num="9.0.1" edition="rc2"/>
        <vers num="9.0.2" edition="rc1"/>
        <vers num="9.0.2" edition="rc2"/>
        <vers num="9.0.3" edition="rc1"/>
        <vers num="9.0.4" edition="rc1"/>
        <vers num="9.0.5" edition="rc1"/>
        <vers num="9.0.5" edition="rc2"/>
        <vers num="9.0.6" edition="rc1"/>
        <vers num="9.0.6" edition="rc2"/>
        <vers num="9.0.7" edition="rc1"/>
        <vers num="9.0.50"/>
        <vers num="9.0.51"/>
        <vers num="9.0.52" edition="rc1"/>
        <vers num="9.0.53"/>
        <vers num="9.0.54" edition="rc1"/>
        <vers num="9.0.55"/>
        <vers num="9.0.56" edition="rc1"/>
        <vers num="9.0.57" edition="rc1"/>
        <vers num="9.0.58" edition="rc1"/>
        <vers num="9.1.0" edition="beta1"/>
        <vers num="9.1.0" edition="beta2"/>
        <vers num="9.1.0" edition="rc1"/>
        <vers num="9.1.0" edition="rc2"/>
        <vers num="9.1.0" edition="rc3"/>
        <vers num="9.1.0" edition="rc4"/>
        <vers num="9.1.1" edition="rc1"/>
        <vers num="9.1.1" edition="rc2"/>
        <vers num="9.1.1" edition="rc3"/>
        <vers num="9.1.2" edition="rc1"/>
        <vers num="9.1.2" edition="rc2"/>
        <vers num="9.1.3" edition="rc1"/>
        <vers num="10.0" edition="rc1"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1" edition="rc1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3" edition="rc1"/>
        <vers num="10.0.4" edition="rc1"/>
        <vers num="10.0.5" edition="rc1"/>
        <vers num="10.0.5" edition="rc2"/>
        <vers num="10.0.6" edition="rc1"/>
        <vers num="11.0" edition="rc2"/>
        <vers num="11.0.0"/>
        <vers num="11.0.1" edition="rc1"/>
        <vers num="11.0.2" edition="rc1"/>
        <vers num="11.0.3" edition="rc1"/>
        <vers num="11.0.3" edition="rc2"/>
        <vers num="11.0.4" edition="rc1"/>
        <vers num="11.0.5" edition="rc1"/>
        <vers num="11.0.6" edition="rc1"/>
        <vers num="12.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-0938" seq="2017-0938" published="2019-02-12" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of Service attack in airMAX &lt; 8.3.2 , airMAX &lt; 6.0.7 and EdgeMAX &lt; 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v6-0-7-Has-Been-Released/ba-p/2056522" adv="1">https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v6-0-7-Has-Been-Released/ba-p/2056522</ref>
      <ref source="MISC" url="https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v8-3-2-Has-Been-Released/ba-p/2049215" adv="1">https://community.ubnt.com/t5/airMAX-Updates-Blog/airOS-v8-3-2-Has-Been-Released/ba-p/2049215</ref>
      <ref source="MISC" url="https://hackerone.com/reports/221625" adv="1">https://hackerone.com/reports/221625</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10000" seq="2017-10000" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. While the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000000" seq="2017-1000000" published="2019-02-19" modified="2019-02-19" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  This issue lacks details and  cannot be determined if it is a security issue or not.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000001" seq="2017-1000001" published="2017-07-17" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/fedora-infra/fedmsg/blob/0.18.2/CHANGELOG.rst" adv="1">https://github.com/fedora-infra/fedmsg/blob/0.18.2/CHANGELOG.rst</ref>
    </refs>
    <vuln_soft>
      <prod name="fedmsg" vendor="fedoraproject">
        <vers num="0.18.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000002" seq="2017-1000002" published="2017-07-17" modified="2017-07-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55" adv="1">http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55</ref>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/view.php?id=5681">http://www.atutor.ca/atutor/mantis/view.php?id=5681</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99599" adv="1">99599</ref>
    </refs>
    <vuln_soft>
      <prod name="atutor" vendor="atutor">
        <vers num="2.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000003" seq="2017-1000003" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Module component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Alternative Content component resulting in privilege escalation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55">http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55</ref>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/view.php?id=5681">http://www.atutor.ca/atutor/mantis/view.php?id=5681</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99599" adv="1">99599</ref>
    </refs>
    <vuln_soft>
      <prod name="atutor" vendor="atutor">
        <vers num="2.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000004" seq="2017-1000004" published="2017-07-17" modified="2017-08-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55" adv="1">http://www.atutor.ca/atutor/mantis/changelog_page.php?version_id=55</ref>
      <ref source="CONFIRM" url="http://www.atutor.ca/atutor/mantis/view.php?id=5681">http://www.atutor.ca/atutor/mantis/view.php?id=5681</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99599" adv="1">99599</ref>
    </refs>
    <vuln_soft>
      <prod name="atutor" vendor="atutor">
        <vers num="2.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000005" seq="2017-1000005" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the name of databases, tables and columns resulting in potential account takeover and scraping of data (stealing data).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/osalabs/phpminiadmin" adv="1">https://github.com/osalabs/phpminiadmin</ref>
    </refs>
    <vuln_soft>
      <prod name="phpminiadmin" vendor="phpminiadmin_project">
        <vers num="1.9.160930"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000006" seq="2017-1000006" published="2017-07-17" modified="2017-07-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://help.plot.ly/security-advisories/2016-08-08-plotlyjs-xss-advisory/" adv="1">http://help.plot.ly/security-advisories/2016-08-08-plotlyjs-xss-advisory/</ref>
    </refs>
    <vuln_soft>
      <prod name="plotly.js" vendor="plotly">
        <vers num="1.11.0"/>
        <vers num="1.12.0"/>
        <vers num="1.13.0"/>
        <vers num="1.14.0"/>
        <vers num="1.14.1"/>
        <vers num="1.14.2"/>
        <vers num="1.15.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000007" seq="2017-1000007" published="2017-07-17" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/twisted/txaws/issues/24" adv="1">https://github.com/twisted/txaws/issues/24</ref>
    </refs>
    <vuln_soft>
      <prod name="txaws" vendor="twistedmatrix">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000008" seq="2017-1000008" published="2017-07-17" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdb6235a" adv="1">https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdb6235a</ref>
    </refs>
    <vuln_soft>
      <prod name="chyrp_lite" vendor="chyrp-lite_project">
        <vers num="2016.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000009" seq="2017-1000009" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Akeneo PIM CE and EE &lt;1.6.6, &lt;1.5.15, &lt;1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2" adv="1" patch="1">https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2</ref>
      <ref source="CONFIRM" url="https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes" adv="1" patch="1">https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes</ref>
      <ref source="CONFIRM" url="https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2" adv="1" patch="1">https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2</ref>
    </refs>
    <vuln_soft>
      <prod name="pim" vendor="akeneo">
        <vers num="1.4.0" edition=":~~community~~~"/>
        <vers num="1.4.0" edition=":~~enterprise~~~"/>
        <vers num="1.4.0" edition="beta1:~~community~~~"/>
        <vers num="1.4.0" edition="beta1:~~enterprise~~~"/>
        <vers num="1.4.0" edition="beta2:~~community~~~"/>
        <vers num="1.4.0" edition="beta2:~~enterprise~~~"/>
        <vers num="1.4.0" edition="beta3:~~community~~~"/>
        <vers num="1.4.0" edition="beta3:~~enterprise~~~"/>
        <vers num="1.4.0" edition="rc1:~~community~~~"/>
        <vers num="1.4.0" edition="rc1:~~enterprise~~~"/>
        <vers num="1.4.1" edition=":~~community~~~"/>
        <vers num="1.4.1" edition=":~~enterprise~~~"/>
        <vers num="1.4.2" edition=":~~community~~~"/>
        <vers num="1.4.2" edition=":~~enterprise~~~"/>
        <vers num="1.4.3" edition=":~~community~~~"/>
        <vers num="1.4.3" edition=":~~enterprise~~~"/>
        <vers num="1.4.4" edition=":~~community~~~"/>
        <vers num="1.4.4" edition=":~~enterprise~~~"/>
        <vers num="1.4.5" edition=":~~community~~~"/>
        <vers num="1.4.5" edition=":~~enterprise~~~"/>
        <vers num="1.4.6" edition=":~~community~~~"/>
        <vers num="1.4.6" edition=":~~enterprise~~~"/>
        <vers num="1.4.7" edition=":~~community~~~"/>
        <vers num="1.4.7" edition=":~~enterprise~~~"/>
        <vers num="1.4.8" edition=":~~community~~~"/>
        <vers num="1.4.8" edition=":~~enterprise~~~"/>
        <vers num="1.4.9" edition=":~~community~~~"/>
        <vers num="1.4.9" edition=":~~enterprise~~~"/>
        <vers num="1.4.10" edition=":~~community~~~"/>
        <vers num="1.4.10" edition=":~~enterprise~~~"/>
        <vers num="1.4.11" edition=":~~community~~~"/>
        <vers num="1.4.11" edition=":~~enterprise~~~"/>
        <vers num="1.4.12" edition=":~~community~~~"/>
        <vers num="1.4.12" edition=":~~enterprise~~~"/>
        <vers num="1.4.13" edition=":~~community~~~"/>
        <vers num="1.4.13" edition=":~~enterprise~~~"/>
        <vers num="1.4.14" edition=":~~community~~~"/>
        <vers num="1.4.14" edition=":~~enterprise~~~"/>
        <vers num="1.4.15" edition=":~~community~~~"/>
        <vers num="1.4.15" edition=":~~enterprise~~~"/>
        <vers num="1.4.16" edition=":~~community~~~"/>
        <vers num="1.4.16" edition=":~~enterprise~~~"/>
        <vers num="1.4.17" edition=":~~community~~~"/>
        <vers num="1.4.17" edition=":~~enterprise~~~"/>
        <vers num="1.4.18" edition=":~~community~~~"/>
        <vers num="1.4.18" edition=":~~enterprise~~~"/>
        <vers num="1.4.19" edition=":~~community~~~"/>
        <vers num="1.4.19" edition=":~~enterprise~~~"/>
        <vers num="1.4.20" edition=":~~community~~~"/>
        <vers num="1.4.20" edition=":~~enterprise~~~"/>
        <vers num="1.4.21" edition=":~~community~~~"/>
        <vers num="1.4.21" edition=":~~enterprise~~~"/>
        <vers num="1.4.22" edition=":~~community~~~"/>
        <vers num="1.4.22" edition=":~~enterprise~~~"/>
        <vers num="1.4.23" edition=":~~community~~~"/>
        <vers num="1.4.23" edition=":~~enterprise~~~"/>
        <vers num="1.4.24" edition=":~~community~~~"/>
        <vers num="1.4.24" edition=":~~enterprise~~~"/>
        <vers num="1.4.25" edition=":~~community~~~"/>
        <vers num="1.4.25" edition=":~~enterprise~~~"/>
        <vers num="1.4.26" edition=":~~community~~~"/>
        <vers num="1.4.26" edition=":~~enterprise~~~"/>
        <vers num="1.4.27" edition=":~~community~~~"/>
        <vers num="1.4.27" edition=":~~enterprise~~~"/>
        <vers num="1.5.0" edition=":~~community~~~"/>
        <vers num="1.5.0" edition=":~~enterprise~~~"/>
        <vers num="1.5.0" edition="alpha1:~~community~~~"/>
        <vers num="1.5.0" edition="alpha1:~~enterprise~~~"/>
        <vers num="1.5.0" edition="beta1:~~community~~~"/>
        <vers num="1.5.0" edition="beta1:~~enterprise~~~"/>
        <vers num="1.5.0" edition="rc1:~~community~~~"/>
        <vers num="1.5.0" edition="rc1:~~enterprise~~~"/>
        <vers num="1.5.1" edition=":~~community~~~"/>
        <vers num="1.5.1" edition=":~~enterprise~~~"/>
        <vers num="1.5.2" edition=":~~community~~~"/>
        <vers num="1.5.2" edition=":~~enterprise~~~"/>
        <vers num="1.5.3" edition=":~~community~~~"/>
        <vers num="1.5.3" edition=":~~enterprise~~~"/>
        <vers num="1.5.4" edition=":~~community~~~"/>
        <vers num="1.5.4" edition=":~~enterprise~~~"/>
        <vers num="1.5.5" edition=":~~community~~~"/>
        <vers num="1.5.5" edition=":~~enterprise~~~"/>
        <vers num="1.5.6" edition=":~~community~~~"/>
        <vers num="1.5.6" edition=":~~enterprise~~~"/>
        <vers num="1.5.7" edition=":~~community~~~"/>
        <vers num="1.5.7" edition=":~~enterprise~~~"/>
        <vers num="1.5.8" edition=":~~community~~~"/>
        <vers num="1.5.8" edition=":~~enterprise~~~"/>
        <vers num="1.5.9" edition=":~~community~~~"/>
        <vers num="1.5.9" edition=":~~enterprise~~~"/>
        <vers num="1.5.10" edition=":~~community~~~"/>
        <vers num="1.5.10" edition=":~~enterprise~~~"/>
        <vers num="1.5.11" edition=":~~community~~~"/>
        <vers num="1.5.11" edition=":~~enterprise~~~"/>
        <vers num="1.5.12" edition=":~~community~~~"/>
        <vers num="1.5.12" edition=":~~enterprise~~~"/>
        <vers num="1.5.13" edition=":~~community~~~"/>
        <vers num="1.5.13" edition=":~~enterprise~~~"/>
        <vers num="1.5.14" edition=":~~community~~~"/>
        <vers num="1.5.14" edition=":~~enterprise~~~"/>
        <vers num="1.6.0" edition=":~~community~~~"/>
        <vers num="1.6.0" edition=":~~enterprise~~~"/>
        <vers num="1.6.0" edition="alpha1:~~community~~~"/>
        <vers num="1.6.0" edition="alpha1:~~enterprise~~~"/>
        <vers num="1.6.0" edition="alpha2:~~community~~~"/>
        <vers num="1.6.0" edition="alpha2:~~enterprise~~~"/>
        <vers num="1.6.0" edition="rc1:~~community~~~"/>
        <vers num="1.6.0" edition="rc1:~~enterprise~~~"/>
        <vers num="1.6.1" edition=":~~community~~~"/>
        <vers num="1.6.1" edition=":~~enterprise~~~"/>
        <vers num="1.6.2" edition=":~~community~~~"/>
        <vers num="1.6.2" edition=":~~enterprise~~~"/>
        <vers num="1.6.3" edition=":~~community~~~"/>
        <vers num="1.6.3" edition=":~~enterprise~~~"/>
        <vers num="1.6.4" edition=":~~community~~~"/>
        <vers num="1.6.4" edition=":~~enterprise~~~"/>
        <vers num="1.6.5" edition=":~~community~~~"/>
        <vers num="1.6.5" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000010" seq="2017-1000010" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Audacity version 2.1.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/140365/Audacity-2.1.2-DLL-Hijacking.html" adv="1">https://packetstormsecurity.com/files/140365/Audacity-2.1.2-DLL-Hijacking.html</ref>
    </refs>
    <vuln_soft>
      <prod name="audacity" vendor="audacity">
        <vers num="2.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000011" seq="2017-1000011" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/Samnan/MyWebSQL" adv="1">https://github.com/Samnan/MyWebSQL</ref>
    </refs>
    <vuln_soft>
      <prod name="mywebsql" vendor="mywebsql">
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000012" seq="2017-1000012" published="2017-07-17" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/DSB/MySQLDumper" adv="1">https://github.com/DSB/MySQLDumper</ref>
    </refs>
    <vuln_soft>
      <prod name="mysqldumper" vendor="mysqldumper">
        <vers num="1.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000013" seq="2017-1000013" published="2017-07-17" modified="2019-03-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95720" adv="1">95720</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-1" adv="1" patch="1">https://www.phpmyadmin.net/security/PMASA-2017-1</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4.1"/>
        <vers num="4.0.4.2"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.10.1"/>
        <vers num="4.0.10.2"/>
        <vers num="4.0.10.3"/>
        <vers num="4.0.10.4"/>
        <vers num="4.0.10.5"/>
        <vers num="4.0.10.6"/>
        <vers num="4.0.10.7"/>
        <vers num="4.0.10.8"/>
        <vers num="4.0.10.9"/>
        <vers num="4.0.10.10"/>
        <vers num="4.0.10.11"/>
        <vers num="4.0.10.12"/>
        <vers num="4.0.10.13"/>
        <vers num="4.0.10.14"/>
        <vers num="4.0.10.15"/>
        <vers num="4.0.10.16"/>
        <vers num="4.0.10.17"/>
        <vers num="4.0.10.18"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.1.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.6.1"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.13.1"/>
        <vers num="4.4.14.1"/>
        <vers num="4.4.15"/>
        <vers num="4.4.15.1"/>
        <vers num="4.4.15.2"/>
        <vers num="4.4.15.3"/>
        <vers num="4.4.15.4"/>
        <vers num="4.4.15.5"/>
        <vers num="4.4.15.6"/>
        <vers num="4.4.15.7"/>
        <vers num="4.4.15.8"/>
        <vers num="4.4.15.9"/>
        <vers num="4.6.0" edition="alpha1"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000014" seq="2017-1000014" published="2017-07-17" modified="2019-03-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95721" adv="1">95721</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-3" adv="1" patch="1">https://www.phpmyadmin.net/security/PMASA-2017-3</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4.1"/>
        <vers num="4.0.4.2"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.10.1"/>
        <vers num="4.0.10.2"/>
        <vers num="4.0.10.3"/>
        <vers num="4.0.10.4"/>
        <vers num="4.0.10.5"/>
        <vers num="4.0.10.6"/>
        <vers num="4.0.10.7"/>
        <vers num="4.0.10.8"/>
        <vers num="4.0.10.9"/>
        <vers num="4.0.10.10"/>
        <vers num="4.0.10.11"/>
        <vers num="4.0.10.12"/>
        <vers num="4.0.10.13"/>
        <vers num="4.0.10.14"/>
        <vers num="4.0.10.15"/>
        <vers num="4.0.10.16"/>
        <vers num="4.0.10.17"/>
        <vers num="4.0.10.18"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.1.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.6.1"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.13.1"/>
        <vers num="4.4.14.1"/>
        <vers num="4.4.15"/>
        <vers num="4.4.15.1"/>
        <vers num="4.4.15.2"/>
        <vers num="4.4.15.3"/>
        <vers num="4.4.15.4"/>
        <vers num="4.4.15.5"/>
        <vers num="4.4.15.6"/>
        <vers num="4.4.15.7"/>
        <vers num="4.4.15.8"/>
        <vers num="4.4.15.9"/>
        <vers num="4.6.0" edition="alpha1"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000015" seq="2017-1000015" published="2017-07-17" modified="2019-03-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95726" adv="1">95726</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-4" adv="1">https://www.phpmyadmin.net/security/PMASA-2017-4</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4.1"/>
        <vers num="4.0.4.2"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.10.1"/>
        <vers num="4.0.10.2"/>
        <vers num="4.0.10.3"/>
        <vers num="4.0.10.4"/>
        <vers num="4.0.10.5"/>
        <vers num="4.0.10.6"/>
        <vers num="4.0.10.7"/>
        <vers num="4.0.10.8"/>
        <vers num="4.0.10.9"/>
        <vers num="4.0.10.10"/>
        <vers num="4.0.10.11"/>
        <vers num="4.0.10.12"/>
        <vers num="4.0.10.13"/>
        <vers num="4.0.10.14"/>
        <vers num="4.0.10.15"/>
        <vers num="4.0.10.16"/>
        <vers num="4.0.10.17"/>
        <vers num="4.0.10.18"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.1.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.6.1"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.13.1"/>
        <vers num="4.4.14.1"/>
        <vers num="4.4.15"/>
        <vers num="4.4.15.1"/>
        <vers num="4.4.15.2"/>
        <vers num="4.4.15.3"/>
        <vers num="4.4.15.4"/>
        <vers num="4.4.15.5"/>
        <vers num="4.4.15.6"/>
        <vers num="4.4.15.7"/>
        <vers num="4.4.15.8"/>
        <vers num="4.4.15.9"/>
        <vers num="4.6.0" edition="alpha1"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000016" seq="2017-1000016" published="2017-07-17" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-5" adv="1">https://www.phpmyadmin.net/security/PMASA-2017-5</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.5.1"/>
        <vers num="4.6.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000017" seq="2017-1000017" published="2017-07-17" modified="2019-03-25" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95732" adv="1">95732</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-6" adv="1">https://www.phpmyadmin.net/security/PMASA-2017-6</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4.1"/>
        <vers num="4.0.4.2"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.10.1"/>
        <vers num="4.0.10.2"/>
        <vers num="4.0.10.3"/>
        <vers num="4.0.10.4"/>
        <vers num="4.0.10.5"/>
        <vers num="4.0.10.6"/>
        <vers num="4.0.10.7"/>
        <vers num="4.0.10.8"/>
        <vers num="4.0.10.9"/>
        <vers num="4.0.10.10"/>
        <vers num="4.0.10.11"/>
        <vers num="4.0.10.12"/>
        <vers num="4.0.10.13"/>
        <vers num="4.0.10.14"/>
        <vers num="4.0.10.15"/>
        <vers num="4.0.10.16"/>
        <vers num="4.0.10.17"/>
        <vers num="4.0.10.18"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.1.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.6.1"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.13.1"/>
        <vers num="4.4.14"/>
        <vers num="4.4.14.1"/>
        <vers num="4.4.15"/>
        <vers num="4.4.15.1"/>
        <vers num="4.4.15.2"/>
        <vers num="4.4.15.3"/>
        <vers num="4.4.15.4"/>
        <vers num="4.4.15.5"/>
        <vers num="4.4.15.6"/>
        <vers num="4.4.15.7"/>
        <vers num="4.4.15.8"/>
        <vers num="4.4.15.9"/>
        <vers num="4.4.15.10"/>
        <vers num="4.6.0" edition="alpha1"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.5.1"/>
        <vers num="4.6.5.2"/>
        <vers num="4.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000018" seq="2017-1000018" published="2017-07-17" modified="2019-03-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/95738" adv="1">95738</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-7" adv="1" patch="1">https://www.phpmyadmin.net/security/PMASA-2017-7</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4.1"/>
        <vers num="4.0.4.2"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.10.1"/>
        <vers num="4.0.10.2"/>
        <vers num="4.0.10.3"/>
        <vers num="4.0.10.4"/>
        <vers num="4.0.10.5"/>
        <vers num="4.0.10.6"/>
        <vers num="4.0.10.7"/>
        <vers num="4.0.10.8"/>
        <vers num="4.0.10.9"/>
        <vers num="4.0.10.10"/>
        <vers num="4.0.10.11"/>
        <vers num="4.0.10.12"/>
        <vers num="4.0.10.13"/>
        <vers num="4.0.10.14"/>
        <vers num="4.0.10.15"/>
        <vers num="4.0.10.16"/>
        <vers num="4.0.10.17"/>
        <vers num="4.0.10.18"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.1.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.6.1"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.13.1"/>
        <vers num="4.4.14"/>
        <vers num="4.4.14.1"/>
        <vers num="4.4.15"/>
        <vers num="4.4.15.1"/>
        <vers num="4.4.15.2"/>
        <vers num="4.4.15.3"/>
        <vers num="4.4.15.4"/>
        <vers num="4.4.15.5"/>
        <vers num="4.4.15.6"/>
        <vers num="4.4.15.7"/>
        <vers num="4.4.15.8"/>
        <vers num="4.4.15.9"/>
        <vers num="4.6.0" edition="alpha1"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.5.1"/>
        <vers num="4.6.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000019" seq="2017-1000019" published="2017-05-07" modified="2017-05-07" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-5938.  Reason: This candidate is a reservation duplicate of CVE-2017-5938.  Notes: All CVE users should reference CVE-2017-5938 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000020" seq="2017-1000020" published="2017-07-17" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does not ask for any sign of authentication resulting in Authentication Bypass. An attacker can take complete advantage of this bug and take over the device remotely or locally. The bug has been successfully tested and reproduced in some versions of SOHO Routers manufactured by TOTOLINK, GREATEK and others."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://ecos.sourceware.org/ecos/problemreport.html" adv="1">http://ecos.sourceware.org/ecos/problemreport.html</ref>
    </refs>
    <vuln_soft>
      <prod name="embedded_web_servers" vendor="ecos">
        <vers num="1.3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000021" seq="2017-1000021" published="2017-07-17" modified="2019-03-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.randorisec.fr/logicaldoc-from-guest-to-root/" adv="1">http://blog.randorisec.fr/logicaldoc-from-guest-to-root/</ref>
    </refs>
    <vuln_soft>
      <prod name="logicaldoc" vendor="logicaldoc">
        <vers num="7.5.3" prev="1" edition=":~~community~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000022" seq="2017-1000022" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.randorisec.fr/logicaldoc-from-guest-to-root/" adv="1">http://blog.randorisec.fr/logicaldoc-from-guest-to-root/</ref>
    </refs>
    <vuln_soft>
      <prod name="logicaldoc" vendor="logicaldoc">
        <vers num="7.5.3" prev="1" edition=":~~community~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000023" seq="2017-1000023" published="2017-07-17" modified="2019-03-14" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.randorisec.fr/logicaldoc-from-guest-to-root/" adv="1">http://blog.randorisec.fr/logicaldoc-from-guest-to-root/</ref>
    </refs>
    <vuln_soft>
      <prod name="logicaldoc" vendor="logicaldoc">
        <vers num="7.5.3" prev="1" edition=":~~community~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000024" seq="2017-1000024" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://mail.gnome.org/archives/shotwell-list/2017-January/msg00048.html" adv="1">[shotwell] 20170131 ATTENTION! Shotwell 0.24.5 and 0.25.4 released</ref>
    </refs>
    <vuln_soft>
      <prod name="shotwell" vendor="gnome">
        <vers num="0.24.0"/>
        <vers num="0.24.1"/>
        <vers num="0.24.2"/>
        <vers num="0.24.3"/>
        <vers num="0.24.4"/>
        <vers num="0.25.0"/>
        <vers num="0.25.1"/>
        <vers num="0.25.2"/>
        <vers num="0.25.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000025" seq="2017-1000025" published="2017-07-17" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.gnome.org/show_bug.cgi?id=752738" adv="1">https://bugzilla.gnome.org/show_bug.cgi?id=752738</ref>
      <ref source="MISC" url="https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/silver" adv="1">https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/silver</ref>
    </refs>
    <vuln_soft>
      <prod name="epiphany" vendor="gnome">
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.9"/>
        <vers num="3.18.10"/>
        <vers num="3.20.0"/>
        <vers num="3.20.1"/>
        <vers num="3.20.2"/>
        <vers num="3.20.3"/>
        <vers num="3.20.4"/>
        <vers num="3.20.5"/>
        <vers num="3.20.6"/>
        <vers num="3.22.0"/>
        <vers num="3.22.1"/>
        <vers num="3.22.2"/>
        <vers num="3.22.3"/>
        <vers num="3.22.4"/>
        <vers num="3.22.5"/>
        <vers num="3.23.1"/>
        <vers num="3.23.1.1"/>
        <vers num="3.23.1.2"/>
        <vers num="3.23.2"/>
        <vers num="3.23.2.1"/>
        <vers num="3.23.3"/>
        <vers num="3.23.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000026" seq="2017-1000026" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/chef/mixlib-archive/blob/master/CHANGELOG.md" adv="1">https://github.com/chef/mixlib-archive/blob/master/CHANGELOG.md</ref>
    </refs>
    <vuln_soft>
      <prod name="mixlib-archive" vendor="chef_project">
        <vers num="0.3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000027" seq="2017-1000027" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/" adv="1">https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/</ref>
      <ref source="MISC" url="https://forums.contribs.org/index.php/topic,52838.0.html" adv="1">https://forums.contribs.org/index.php/topic,52838.0.html</ref>
    </refs>
    <vuln_soft>
      <prod name="sme_server" vendor="koozali">
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.2"/>
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000028" seq="2017-1000028" published="2017-07-17" modified="2019-05-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45196/" adv="1">45196</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45198/" adv="1">45198</ref>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-016/?fid=6904" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-016/?fid=6904</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="4.1" edition=":~~open_source~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000029" seq="2017-1000029" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-011/?fid=8037" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-011/?fid=8037</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.0.1" edition=":~~open_source~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000030" seq="2017-1000030" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of administrative user and grant access to the web-based administration interface.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-011/?fid=8037" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-011/?fid=8037</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.0.1" edition=":~~open_source~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000031" seq="2017-1000031" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-007/?fid=7789" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-007/?fid=7789</ref>
    </refs>
    <vuln_soft>
      <prod name="cacti" vendor="cacti">
        <vers num="0.8.8b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000032" seq="2017-1000032" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-007/" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-007/</ref>
    </refs>
    <vuln_soft>
      <prod name="cacti" vendor="cacti">
        <vers num="0.8.8b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000033" seq="2017-1000033" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Wordpress Plugin Vospari Forms version &lt; 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://cjc.im/advisories/0007/" adv="1">https://cjc.im/advisories/0007/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8862" adv="1">https://wpvulndb.com/vulnerabilities/8862</ref>
    </refs>
    <vuln_soft>
      <prod name="vospari_forms" vendor="vospari_forms_project">
        <vers num="1.3" prev="1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000034" seq="2017-1000034" published="2017-07-17" modified="2017-08-04" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Akka versions &lt;=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.html" adv="1">http://doc.akka.io/docs/akka/2.4/security/2017-02-10-java-serialization.html</ref>
    </refs>
    <vuln_soft>
      <prod name="akka" vendor="akka">
        <vers num="2.4.16" prev="1"/>
        <vers num="2.5" edition="m1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000035" seq="2017-1000035" published="2017-07-17" modified="2017-10-06" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://git.tt-rss.org/git/tt-rss/commit/829d478f1b054c8ce1eeb4f15170dc4a1abb3e47">https://git.tt-rss.org/git/tt-rss/commit/829d478f1b054c8ce1eeb4f15170dc4a1abb3e47</ref>
    </refs>
    <vuln_soft>
      <prod name="tiny_tiny_rss" vendor="tt-rss">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000036" seq="2017-1000036" published="2017-07-17" modified="2017-10-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000037" seq="2017-1000037" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when automatically loading environment variables from files in $PWD RVM automatically executes hooks located in $PWD resulting in code execution RVM automatically installs gems as specified by files in $PWD resulting in code execution RVM automatically does "bundle install" on a Gemfile specified by .versions.conf in $PWD resulting in code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/justinsteven/advisories/blob/master/2017_rvm_cd_command_execution.md" adv="1">https://github.com/justinsteven/advisories/blob/master/2017_rvm_cd_command_execution.md</ref>
    </refs>
    <vuln_soft>
      <prod name="rvm" vendor="rvm_project">
        <vers num="1.28.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000038" seq="2017-1000038" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://security.dxw.com/advisories/stored-xss-in-relevanssi-could-allow-an-unauthenticated-attacker-to-do-almost-anything-an-admin-can-do/" adv="1">https://security.dxw.com/advisories/stored-xss-in-relevanssi-could-allow-an-unauthenticated-attacker-to-do-almost-anything-an-admin-can-do/</ref>
    </refs>
    <vuln_soft>
      <prod name="relevanssi" vendor="relevanssi">
        <vers num="3.5.7.1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000039" seq="2017-1000039" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://framagit.org/framasoft/framadate/issues/220" adv="1">https://framagit.org/framasoft/framadate/issues/220</ref>
    </refs>
    <vuln_soft>
      <prod name="framadate" vendor="framasoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000040" seq="2017-1000040" published="2017-05-07" modified="2017-05-07" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-7853.  Reason: This candidate is a reservation duplicate of CVE-2017-7853.  Notes: All CVE users should reference CVE-2017-7853 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000041" seq="2017-1000041" published="2017-05-07" modified="2017-05-07" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-7271.  Reason: This candidate is a reservation duplicate of CVE-2017-7271.  Notes: All CVE users should reference CVE-2017-7271 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000042" seq="2017-1000042" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/54327" adv="1">https://hackerone.com/reports/54327</ref>
      <ref source="CONFIRM" url="https://nodesecurity.io/advisories/49" adv="1">https://nodesecurity.io/advisories/49</ref>
    </refs>
    <vuln_soft>
      <prod name="mapbox" vendor="mapbox_project">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.0" edition="beta"/>
        <vers num="1.6.0" edition="beta0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2" edition="beta0"/>
        <vers num="1.6.4"/>
        <vers num="2.0.0" edition="beta0"/>
        <vers num="2.0.0" edition="beta1"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000043" seq="2017-1000043" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackerone.com/reports/99245" adv="1">https://hackerone.com/reports/99245</ref>
      <ref source="CONFIRM" url="https://nodesecurity.io/advisories/74" adv="1">https://nodesecurity.io/advisories/74</ref>
    </refs>
    <vuln_soft>
      <prod name="mapbox" vendor="mapbox_project">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.0" edition="beta"/>
        <vers num="1.6.0" edition="beta0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2" edition="beta0"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="2.0.0" edition="beta0"/>
        <vers num="2.0.0" edition="beta1"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000044" seq="2017-1000044" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://git.gnome.org/browse/gtk-vnc/commit/?id=f3fc5e57a78d4be9872f1394f697b9929873a737" adv="1" patch="1">https://git.gnome.org/browse/gtk-vnc/commit/?id=f3fc5e57a78d4be9872f1394f697b9929873a737</ref>
    </refs>
    <vuln_soft>
      <prod name="gtk-vnc" vendor="gnome">
        <vers num="0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000045" seq="2017-1000045" published="2017-07-17" modified="2017-10-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000046" seq="2017-1000046" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mautic 2.6.1 and earlier fails to set flags on session cookies</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.trustmatta.com/advisories/MATTA-2017-002.txt">https://www.trustmatta.com/advisories/MATTA-2017-002.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="mautic" vendor="mautic">
        <vers num="2.6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000047" seq="2017-1000047" published="2017-07-17" modified="2017-07-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/justinsteven/advisories/blob/master/2017_rbenv_ruby_version_directory_traversal.md" adv="1">https://github.com/justinsteven/advisories/blob/master/2017_rbenv_ruby_version_directory_traversal.md</ref>
    </refs>
    <vuln_soft>
      <prod name="rbenv" vendor="rbenv">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000048" seq="2017-1000048" published="2017-07-17" modified="2017-12-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2672">RHSA-2017:2672</ref>
      <ref source="CONFIRM" url="https://github.com/ljharb/qs/issues/200" adv="1">https://github.com/ljharb/qs/issues/200</ref>
    </refs>
    <vuln_soft>
      <prod name="qs" vendor="qs_project">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="3.0.0"/>
        <vers num="3.1.0"/>
        <vers num="4.0.0"/>
        <vers num="5.0.0"/>
        <vers num="5.1.0"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.3.0"/>
        <vers num="6.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000049" seq="2017-1000049" published="2017-07-17" modified="2017-07-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2015-8864.  Reason: This candidate is a reservation duplicate of CVE-2015-8864.  Notes: All CVE users should reference CVE-2015-8864 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000050" seq="2017-1000050" published="2017-07-17" modified="2018-11-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/03/06/1" adv="1">[oss-security] 20170305 CVE-Request JasPer 2.0.12 NULL Pointer Dereference jp2_encode (jp2_enc.c)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96595" adv="1">96595</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3253">RHSA-2018:3253</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3505">RHSA-2018:3505</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201908-03">GLSA-201908-03</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3693-1/">USN-3693-1</ref>
    </refs>
    <vuln_soft>
      <prod name="jasper" vendor="jasper_project">
        <vers num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000051" seq="2017-1000051" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://blog.cryptpad.fr/2017/03/06/Security-growing-pains/" adv="1">https://blog.cryptpad.fr/2017/03/06/Security-growing-pains/</ref>
      <ref source="CONFIRM" url="https://github.com/xwiki-labs/cryptpad/releases/tag/1.1.1" adv="1">https://github.com/xwiki-labs/cryptpad/releases/tag/1.1.1</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptpad" vendor="xwiki">
        <vers num="1.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000052" seq="2017-1000052" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://elixirforum.com/t/security-releases-for-plug/3913" adv="1">https://elixirforum.com/t/security-releases-for-plug/3913</ref>
    </refs>
    <vuln_soft>
      <prod name="plug" vendor="elixir-plug">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000053" seq="2017-1000053" published="2017-07-17" modified="2017-08-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://elixirforum.com/t/security-releases-for-plug/3913" adv="1">https://elixirforum.com/t/security-releases-for-plug/3913</ref>
    </refs>
    <vuln_soft>
      <prod name="plug" vendor="elixir-plug">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000054" seq="2017-1000054" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.theblazehen.com/posts/CVE-2017-xxxxxx-rocketchat-xss-with-markdown-url-handling-in-messages/">https://www.theblazehen.com/posts/CVE-2017-xxxxxx-rocketchat-xss-with-markdown-url-handling-in-messages/</ref>
    </refs>
    <vuln_soft>
      <prod name="rocket.chat" vendor="rocketchat">
        <vers num="0.8.0"/>
        <vers num="0.9.0"/>
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.11.0"/>
        <vers num="0.12.0"/>
        <vers num="0.12.1"/>
        <vers num="0.13.0"/>
        <vers num="0.14.0"/>
        <vers num="0.15.0"/>
        <vers num="0.16.0"/>
        <vers num="0.17.0"/>
        <vers num="0.18.0"/>
        <vers num="0.18.1"/>
        <vers num="0.19.0"/>
        <vers num="0.20.0"/>
        <vers num="0.21.0"/>
        <vers num="0.22.0"/>
        <vers num="0.23.0"/>
        <vers num="0.24.0"/>
        <vers num="0.25.0"/>
        <vers num="0.26.0"/>
        <vers num="0.27.0"/>
        <vers num="0.28.0"/>
        <vers num="0.29.0"/>
        <vers num="0.30.0"/>
        <vers num="0.31.0"/>
        <vers num="0.32.0"/>
        <vers num="0.33.0"/>
        <vers num="0.34.0"/>
        <vers num="0.35.0"/>
        <vers num="0.36.0"/>
        <vers num="0.37.0"/>
        <vers num="0.37.1"/>
        <vers num="0.38.0"/>
        <vers num="0.39.0"/>
        <vers num="0.40.1"/>
        <vers num="0.41.0"/>
        <vers num="0.42.0"/>
        <vers num="0.43.0"/>
        <vers num="0.44.0"/>
        <vers num="0.45.0"/>
        <vers num="0.46.0"/>
        <vers num="0.47.0"/>
        <vers num="0.47.1"/>
        <vers num="0.48.0"/>
        <vers num="0.48.1"/>
        <vers num="0.48.2"/>
        <vers num="0.49.0"/>
        <vers num="0.49.1"/>
        <vers num="0.49.2"/>
        <vers num="0.49.3"/>
        <vers num="0.49.4"/>
        <vers num="0.50.0"/>
        <vers num="0.50.1"/>
        <vers num="0.51.0"/>
        <vers num="0.52.0"/>
        <vers num="0.53.0"/>
        <vers num="0.54.0"/>
        <vers num="0.54.1"/>
        <vers num="0.54.2"/>
        <vers num="0.55.0"/>
        <vers num="0.55.1"/>
        <vers num="0.56.0"/>
        <vers num="0.57.0" edition="rc0"/>
        <vers num="0.57.0" edition="rc1"/>
        <vers num="0.57.0" edition="rc2"/>
        <vers num="0.57.0" edition="rc3"/>
        <vers num="0.57.1"/>
        <vers num="0.57.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000055" seq="2017-1000055" published="2017-07-17" modified="2017-07-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000056" seq="2017-1000056" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/kubernetes/kubernetes/issues/43459" adv="1">https://github.com/kubernetes/kubernetes/issues/43459</ref>
    </refs>
    <vuln_soft>
      <prod name="kubernetes" vendor="kubernetes">
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000057" seq="2017-1000057" published="2017-07-17" modified="2017-10-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000058" seq="2017-1000058" published="2017-07-17" modified="2017-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://chevereto.com/changelog" adv="1">https://chevereto.com/changelog</ref>
    </refs>
    <vuln_soft>
      <prod name="chevereto" vendor="chevereto">
        <vers num="3.8.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000059" seq="2017-1000059" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.compass-security.com/research/advisories/" adv="1">https://www.compass-security.com/research/advisories/</ref>
    </refs>
    <vuln_soft>
      <prod name="live_helper_chat" vendor="livehelperchat">
        <vers num="2.06" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000060" seq="2017-1000060" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://rioru.github.io/pentest/web/2017/03/28/from-unauthenticated-to-root-supervision.html" adv="1">https://rioru.github.io/pentest/web/2017/03/28/from-unauthenticated-to-root-supervision.html</ref>
    </refs>
    <vuln_soft>
      <prod name="eyesofnetwork" vendor="eyesofnetwork">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000061" seq="2017-1000061" published="2017-07-17" modified="2018-01-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2492">RHSA-2017:2492</ref>
      <ref source="CONFIRM" url="https://github.com/lsh123/xmlsec/issues/43" adv="1" patch="1">https://github.com/lsh123/xmlsec/issues/43</ref>
    </refs>
    <vuln_soft>
      <prod name="xmlsec" vendor="xmlsec_project">
        <vers num="1.2.23" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000062" seq="2017-1000062" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13" adv="1">https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13</ref>
    </refs>
    <vuln_soft>
      <prod name="kitto" vendor="kitto_project">
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000063" seq="2017-1000063" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13" adv="1">https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13</ref>
    </refs>
    <vuln_soft>
      <prod name="kitto" vendor="kitto_project">
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000064" seq="2017-1000064" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13" adv="1">https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13</ref>
    </refs>
    <vuln_soft>
      <prod name="kitto" vendor="kitto_project">
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000065" seq="2017-1000065" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/openmediavault/openmediavault/commit/b2db1e24d0e52b961b5c3b3329b6ee717cac53a2" adv="1" patch="1">https://github.com/openmediavault/openmediavault/commit/b2db1e24d0e52b961b5c3b3329b6ee717cac53a2</ref>
    </refs>
    <vuln_soft>
      <prod name="openmediavault" vendor="openmediavault">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000066" seq="2017-1000066" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://keepass.info/news/news_all.html" adv="1">http://keepass.info/news/news_all.html</ref>
    </refs>
    <vuln_soft>
      <prod name="keepass" vendor="keepass">
        <vers num="1.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000067" seq="2017-1000067" published="2017-07-17" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/modxcms/revolution/blob/9bf1c6cf7bdc12190b404f93ce7798b39c07bc59/core/xpdo/changelog.txt" adv="1">https://github.com/modxcms/revolution/blob/9bf1c6cf7bdc12190b404f93ce7798b39c07bc59/core/xpdo/changelog.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="revolution" vendor="modx">
        <vers num="2.0.0" edition="rc1"/>
        <vers num="2.0.0" edition="rc2"/>
        <vers num="2.0.0" edition="rc3"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0" edition="p12"/>
        <vers num="2.1.1" edition="p12"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.2.0" edition="rc1"/>
        <vers num="2.2.0" edition="rc2"/>
        <vers num="2.2.0" edition="rc3"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000068" seq="2017-1000068" published="2017-07-17" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disable arbitrary running splits and cause denial of service to clients in the field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/Betterment/test_track/releases/tag/v1.0.1" adv="1">https://github.com/Betterment/test_track/releases/tag/v1.0.1</ref>
    </refs>
    <vuln_soft>
      <prod name="test_track" vendor="betterment">
        <vers num="1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000069" seq="2017-1000069" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CSRF in Bitly oauth2_proxy 2.1 during authentication flow</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/bitly/oauth2_proxy/pull/360" adv="1" patch="1">https://github.com/bitly/oauth2_proxy/pull/360</ref>
    </refs>
    <vuln_soft>
      <prod name="oauth2_proxy" vendor="oauth2_proxy_project">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000070" seq="2017-1000070" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/bitly/oauth2_proxy/pull/359" adv="1" patch="1">https://github.com/bitly/oauth2_proxy/pull/359</ref>
      <ref source="MISC" url="https://tools.ietf.org/html/rfc6819#section-5.2.3.5">https://tools.ietf.org/html/rfc6819#section-5.2.3.5</ref>
    </refs>
    <vuln_soft>
      <prod name="oauth2_proxy" vendor="oauth2_proxy_project">
        <vers num="2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000071" seq="2017-1000071" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99609" adv="1">99609</ref>
      <ref source="CONFIRM" url="https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLog" adv="1">https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLog</ref>
      <ref source="CONFIRM" url="https://github.com/Jasig/phpCAS/issues/228" adv="1">https://github.com/Jasig/phpCAS/issues/228</ref>
    </refs>
    <vuln_soft>
      <prod name="phpcas" vendor="apereo">
        <vers num="1.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000072" seq="2017-1000072" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/marcobambini/gravity/issues/123" adv="1" patch="1">https://github.com/marcobambini/gravity/issues/123</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000073" seq="2017-1000073" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/marcobambini/gravity/issues/129" adv="1" patch="1">https://github.com/marcobambini/gravity/issues/129</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000074" seq="2017-1000074" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/marcobambini/gravity/issues/131" adv="1" patch="1">https://github.com/marcobambini/gravity/issues/131</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000075" seq="2017-1000075" published="2017-07-17" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/marcobambini/gravity/issues/133" adv="1" patch="1">https://github.com/marcobambini/gravity/issues/133</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000076" seq="2017-1000076" published="2017-10-04" modified="2017-10-04" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference  providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000077" seq="2017-1000077" published="2017-10-04" modified="2017-10-04" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference  providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000078" seq="2017-1000078" published="2017-07-17" modified="2018-01-24">
    <desc>
      <descript source="cve">Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration</descript>
    </desc>
    <refs>
      <ref source="CONFIRM" url="https://wiki.onosproject.org/display/ONOS/Security+advisories">https://wiki.onosproject.org/display/ONOS/Security+advisories</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000079" seq="2017-1000079" published="2017-07-17" modified="2018-01-24">
    <desc>
      <descript source="cve">Linux foundation ONOS 1.9.0 is vulnerable to a DoS.</descript>
    </desc>
    <refs>
      <ref source="CONFIRM" url="https://wiki.onosproject.org/display/ONOS/Security+advisories">https://wiki.onosproject.org/display/ONOS/Security+advisories</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000080" seq="2017-1000080" published="2017-07-17" modified="2018-01-24">
    <desc>
      <descript source="cve">Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.</descript>
    </desc>
    <refs>
      <ref source="CONFIRM" url="https://wiki.onosproject.org/display/ONOS/Security+advisories">https://wiki.onosproject.org/display/ONOS/Security+advisories</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000081" seq="2017-1000081" published="2017-07-17" modified="2018-01-24">
    <desc>
      <descript source="cve">Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.</descript>
    </desc>
    <refs>
      <ref source="CONFIRM" url="https://wiki.onosproject.org/display/ONOS/Security+advisories">https://wiki.onosproject.org/display/ONOS/Security+advisories</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000082" seq="2017-1000082" published="2017-07-07" modified="2017-07-22" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/07/02/1" adv="1" patch="1">[oss-security] 20170702 systemd fails to parse user that should run service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99507">99507</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038839">1038839</ref>
      <ref source="CONFIRM" url="https://github.com/systemd/systemd/issues/6237" adv="1" patch="1">https://github.com/systemd/systemd/issues/6237</ref>
    </refs>
    <vuln_soft>
      <prod name="systemd" vendor="freedesktop">
        <vers num="233" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000083" seq="2017-1000083" published="2017-09-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/oss-sec/2017/q3/128" adv="1">http://seclists.org/oss-sec/2017/q3/128</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3911" adv="1">DSA-3911</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99597" adv="1">99597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2388" adv="1">RHSA-2017:2388</ref>
      <ref source="MISC" url="https://bugzilla.gnome.org/show_bug.cgi?id=784630" adv="1">https://bugzilla.gnome.org/show_bug.cgi?id=784630</ref>
      <ref source="MISC" url="https://github.com/GNOME/evince/commit/717df38fd8509bf883b70d680c9b1b3cf36732ee" adv="1" patch="1">https://github.com/GNOME/evince/commit/717df38fd8509bf883b70d680c9b1b3cf36732ee</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45824/" adv="1">45824</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/46341/" adv="1">46341</ref>
    </refs>
    <vuln_soft>
      <prod name="evince" vendor="gnome">
        <vers num="3.24.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000084" seq="2017-1000084" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="parameterized_trigger" vendor="jenkins">
        <vers num="1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1" edition=":~~~jenkins~~"/>
        <vers num="1.2" edition=":~~~jenkins~~"/>
        <vers num="1.3" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition=":~~~jenkins~~"/>
        <vers num="1.5" edition=":~~~jenkins~~"/>
        <vers num="1.6" edition=":~~~jenkins~~"/>
        <vers num="2.0" edition=":~~~jenkins~~"/>
        <vers num="2.1" edition=":~~~jenkins~~"/>
        <vers num="2.2" edition=":~~~jenkins~~"/>
        <vers num="2.3" edition=":~~~jenkins~~"/>
        <vers num="2.4" edition=":~~~jenkins~~"/>
        <vers num="2.5" edition=":~~~jenkins~~"/>
        <vers num="2.6" edition=":~~~jenkins~~"/>
        <vers num="2.7" edition=":~~~jenkins~~"/>
        <vers num="2.8" edition=":~~~jenkins~~"/>
        <vers num="2.9" edition=":~~~jenkins~~"/>
        <vers num="2.10" edition=":~~~jenkins~~"/>
        <vers num="2.11" edition=":~~~jenkins~~"/>
        <vers num="2.12" edition=":~~~jenkins~~"/>
        <vers num="2.13" edition=":~~~jenkins~~"/>
        <vers num="2.14" edition=":~~~jenkins~~"/>
        <vers num="2.15" edition=":~~~jenkins~~"/>
        <vers num="2.16" edition=":~~~jenkins~~"/>
        <vers num="2.17" edition=":~~~jenkins~~"/>
        <vers num="2.18" edition=":~~~jenkins~~"/>
        <vers num="2.19" edition=":~~~jenkins~~"/>
        <vers num="2.20" edition=":~~~jenkins~~"/>
        <vers num="2.21" edition=":~~~jenkins~~"/>
        <vers num="2.22" edition=":~~~jenkins~~"/>
        <vers num="2.23" edition=":~~~jenkins~~"/>
        <vers num="2.24" edition=":~~~jenkins~~"/>
        <vers num="2.25" edition=":~~~jenkins~~"/>
        <vers num="2.26" edition=":~~~jenkins~~"/>
        <vers num="2.27" edition=":~~~jenkins~~"/>
        <vers num="2.28" edition=":~~~jenkins~~"/>
        <vers num="2.29" edition=":~~~jenkins~~"/>
        <vers num="2.30" edition=":~~~jenkins~~"/>
        <vers num="2.31" edition=":~~~jenkins~~"/>
        <vers num="2.32" edition=":~~~jenkins~~"/>
        <vers num="2.33" edition=":~~~jenkins~~"/>
        <vers num="2.34" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000085" seq="2017-1000085" published="2017-10-04" modified="2017-11-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web server or Subversion server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99574" adv="1">99574</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="subversion" vendor="jenkins">
        <vers num="2.8" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000086" seq="2017-1000086" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100437" adv="1">100437</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="periodic_backup" vendor="jenkins">
        <vers num="1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1" edition=":~~~jenkins~~"/>
        <vers num="1.2" edition=":~~~jenkins~~"/>
        <vers num="1.3" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000087" seq="2017-1000087" published="2017-10-04" modified="2017-11-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="github_branch_source" vendor="jenkins">
        <vers num="0.1" edition="beta-1:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-2:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-3:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-4:~~~jenkins~~"/>
        <vers num="1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1" edition=":~~~jenkins~~"/>
        <vers num="1.2" edition=":~~~jenkins~~"/>
        <vers num="1.3" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition="beta-1:~~~jenkins~~"/>
        <vers num="1.5" edition=":~~~jenkins~~"/>
        <vers num="1.6" edition=":~~~jenkins~~"/>
        <vers num="1.7" edition=":~~~jenkins~~"/>
        <vers num="1.8" edition=":~~~jenkins~~"/>
        <vers num="1.8.1" edition=":~~~jenkins~~"/>
        <vers num="1.9" edition=":~~~jenkins~~"/>
        <vers num="1.10" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.0.1" edition=":~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-3:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-4:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-5:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-6:~~~jenkins~~"/>
        <vers num="2.0.2" edition=":~~~jenkins~~"/>
        <vers num="2.0.3" edition=":~~~jenkins~~"/>
        <vers num="2.0.4" edition=":~~~jenkins~~"/>
        <vers num="2.0.4" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.5" edition=":~~~jenkins~~"/>
        <vers num="2.0.6" edition=":~~~jenkins~~"/>
        <vers num="2.0.7" prev="1" edition=":~~~jenkins~~"/>
        <vers num="2.2.0" edition=":~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-1:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-2:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-3:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-4:~~~jenkins~~"/>
        <vers num="2.2.0" edition="beta-1:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000088" seq="2017-1000088" published="2017-10-04" modified="2017-11-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input validation, which meant users were able to use javascript: schemes for these links.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="sidebar_link" vendor="jenkins">
        <vers num="1.8" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000089" seq="2017-1000089" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="pipeline:_build_step" vendor="jenkins">
        <vers num="2.5" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000090" seq="2017-1000090" published="2017-10-04" modified="2017-11-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization configuration, preventing legitimate access to Jenkins.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="role-based_authorization_strategy" vendor="jenkins">
        <vers num="2.5.0" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000091" seq="2017-1000091" published="2017-10-04" modified="2017-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access to Jenkins to connect to any web server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="github_branch_source" vendor="jenkins">
        <vers num="0.1" edition="beta-1:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-2:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-3:~~~jenkins~~"/>
        <vers num="0.1" edition="beta-4:~~~jenkins~~"/>
        <vers num="1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1" edition=":~~~jenkins~~"/>
        <vers num="1.2" edition=":~~~jenkins~~"/>
        <vers num="1.3" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition=":~~~jenkins~~"/>
        <vers num="1.4" edition="beta-1:~~~jenkins~~"/>
        <vers num="1.5" edition=":~~~jenkins~~"/>
        <vers num="1.6" edition=":~~~jenkins~~"/>
        <vers num="1.7" edition=":~~~jenkins~~"/>
        <vers num="1.8" edition=":~~~jenkins~~"/>
        <vers num="1.8.1" edition=":~~~jenkins~~"/>
        <vers num="1.9" edition=":~~~jenkins~~"/>
        <vers num="1.10" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.0.1" edition=":~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-3:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-4:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-5:~~~jenkins~~"/>
        <vers num="2.0.1" edition="beta-6:~~~jenkins~~"/>
        <vers num="2.0.2" edition=":~~~jenkins~~"/>
        <vers num="2.0.3" edition=":~~~jenkins~~"/>
        <vers num="2.0.4" edition=":~~~jenkins~~"/>
        <vers num="2.0.4" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.5" edition=":~~~jenkins~~"/>
        <vers num="2.0.6" edition=":~~~jenkins~~"/>
        <vers num="2.0.7" edition=":~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-1:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-2:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-3:~~~jenkins~~"/>
        <vers num="2.2.0" edition="alpha-4:~~~jenkins~~"/>
        <vers num="2.2.0" edition="beta-1:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000092" seq="2017-1000092" published="2017-10-04" modified="2017-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a maliciously crafted Jenkins URL which would result in the Jenkins Git client sending the username and password to an attacker-controlled server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100435" adv="1">100435</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="git" vendor="jenkins">
        <vers num="0.1.0" edition=":~~~jenkins~~"/>
        <vers num="0.2.0" edition=":~~~jenkins~~"/>
        <vers num="0.3.0" edition=":~~~jenkins~~"/>
        <vers num="0.4.0" edition=":~~~jenkins~~"/>
        <vers num="0.5.0" edition=":~~~jenkins~~"/>
        <vers num="0.6.0" edition=":~~~jenkins~~"/>
        <vers num="0.7.0" edition=":~~~jenkins~~"/>
        <vers num="0.7.1" edition=":~~~jenkins~~"/>
        <vers num="0.7.2" edition=":~~~jenkins~~"/>
        <vers num="0.7.3" edition=":~~~jenkins~~"/>
        <vers num="0.8.0" edition=":~~~jenkins~~"/>
        <vers num="0.8.1" edition=":~~~jenkins~~"/>
        <vers num="0.8.2" edition=":~~~jenkins~~"/>
        <vers num="0.9.0" edition=":~~~jenkins~~"/>
        <vers num="0.9.1" edition=":~~~jenkins~~"/>
        <vers num="0.9.2" edition=":~~~jenkins~~"/>
        <vers num="1.0.0" edition=":~~~jenkins~~"/>
        <vers num="1.0.1" edition=":~~~jenkins~~"/>
        <vers num="1.1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1.1" edition=":~~~jenkins~~"/>
        <vers num="1.1.2" edition=":~~~jenkins~~"/>
        <vers num="1.1.3" edition=":~~~jenkins~~"/>
        <vers num="1.1.4" edition=":~~~jenkins~~"/>
        <vers num="1.1.5" edition=":~~~jenkins~~"/>
        <vers num="1.1.6" edition=":~~~jenkins~~"/>
        <vers num="1.1.7" edition=":~~~jenkins~~"/>
        <vers num="1.1.8" edition=":~~~jenkins~~"/>
        <vers num="1.1.9" edition=":~~~jenkins~~"/>
        <vers num="1.1.10" edition=":~~~jenkins~~"/>
        <vers num="1.1.11" edition=":~~~jenkins~~"/>
        <vers num="1.1.12" edition=":~~~jenkins~~"/>
        <vers num="1.1.13" edition=":~~~jenkins~~"/>
        <vers num="1.1.14" edition=":~~~jenkins~~"/>
        <vers num="1.1.15" edition=":~~~jenkins~~"/>
        <vers num="1.1.16" edition=":~~~jenkins~~"/>
        <vers num="1.1.17" edition=":~~~jenkins~~"/>
        <vers num="1.1.18" edition=":~~~jenkins~~"/>
        <vers num="1.1.19" edition=":~~~jenkins~~"/>
        <vers num="1.1.20" edition=":~~~jenkins~~"/>
        <vers num="1.1.21" edition=":~~~jenkins~~"/>
        <vers num="1.1.22" edition=":~~~jenkins~~"/>
        <vers num="1.1.23" edition=":~~~jenkins~~"/>
        <vers num="1.1.24" edition=":~~~jenkins~~"/>
        <vers num="1.1.25" edition=":~~~jenkins~~"/>
        <vers num="1.1.26" edition=":~~~jenkins~~"/>
        <vers num="1.1.27" edition=":~~~jenkins~~"/>
        <vers num="1.1.28" edition=":~~~jenkins~~"/>
        <vers num="1.1.29" edition=":~~~jenkins~~"/>
        <vers num="1.2.0" edition=":~~~jenkins~~"/>
        <vers num="1.3.0" edition=":~~~jenkins~~"/>
        <vers num="1.4.0" edition=":~~~jenkins~~"/>
        <vers num="1.5.0" edition=":~~~jenkins~~"/>
        <vers num="1.6.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.0.0" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition="alpha-1:~~~jenkins~~"/>
        <vers num="2.0.0" edition="alpha-2:~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.0.0" edition="beta-3:~~~jenkins~~"/>
        <vers num="2.0.1" edition=":~~~jenkins~~"/>
        <vers num="2.0.2" edition=":~~~jenkins~~"/>
        <vers num="2.0.3" edition=":~~~jenkins~~"/>
        <vers num="2.0.4" edition=":~~~jenkins~~"/>
        <vers num="2.1.0" edition=":~~~jenkins~~"/>
        <vers num="2.2.0" edition=":~~~jenkins~~"/>
        <vers num="2.2.1" edition=":~~~jenkins~~"/>
        <vers num="2.2.2" edition=":~~~jenkins~~"/>
        <vers num="2.2.3" edition=":~~~jenkins~~"/>
        <vers num="2.2.4" edition=":~~~jenkins~~"/>
        <vers num="2.2.5" edition=":~~~jenkins~~"/>
        <vers num="2.2.6" edition=":~~~jenkins~~"/>
        <vers num="2.2.7" edition=":~~~jenkins~~"/>
        <vers num="2.2.8" edition=":~~~jenkins~~"/>
        <vers num="2.2.9" edition=":~~~jenkins~~"/>
        <vers num="2.2.10" edition=":~~~jenkins~~"/>
        <vers num="2.2.11" edition=":~~~jenkins~~"/>
        <vers num="2.2.12" edition=":~~~jenkins~~"/>
        <vers num="2.3.0" edition=":~~~jenkins~~"/>
        <vers num="2.3.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.3.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.3.0" edition="beta-3:~~~jenkins~~"/>
        <vers num="2.3.0" edition="beta-4:~~~jenkins~~"/>
        <vers num="2.3.1" edition=":~~~jenkins~~"/>
        <vers num="2.3.2" edition=":~~~jenkins~~"/>
        <vers num="2.3.3" edition=":~~~jenkins~~"/>
        <vers num="2.3.4" edition=":~~~jenkins~~"/>
        <vers num="2.3.5" edition=":~~~jenkins~~"/>
        <vers num="2.4.0" edition=":~~~jenkins~~"/>
        <vers num="2.4.1" edition=":~~~jenkins~~"/>
        <vers num="2.4.2" edition=":~~~jenkins~~"/>
        <vers num="2.4.3" edition=":~~~jenkins~~"/>
        <vers num="2.4.4" edition=":~~~jenkins~~"/>
        <vers num="2.5.0" edition=":~~~jenkins~~"/>
        <vers num="2.5.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.5.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.5.0" edition="beta-3:~~~jenkins~~"/>
        <vers num="2.5.0" edition="beta-4:~~~jenkins~~"/>
        <vers num="2.5.0" edition="beta-5:~~~jenkins~~"/>
        <vers num="2.5.1" edition=":~~~jenkins~~"/>
        <vers num="2.5.2" edition=":~~~jenkins~~"/>
        <vers num="2.5.3" edition=":~~~jenkins~~"/>
        <vers num="2.6.0" edition=":~~~jenkins~~"/>
        <vers num="2.6.1" edition=":~~~jenkins~~"/>
        <vers num="2.6.2" edition=":~~~jenkins~~"/>
        <vers num="2.6.2" edition="beta-1:~~~jenkins~~"/>
        <vers num="2.6.2" edition="beta-2:~~~jenkins~~"/>
        <vers num="2.6.4" edition=":~~~jenkins~~"/>
        <vers num="2.6.5" edition=":~~~jenkins~~"/>
        <vers num="3.0.0" edition=":~~~jenkins~~"/>
        <vers num="3.0.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="3.0.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="3.0.1" edition=":~~~jenkins~~"/>
        <vers num="3.0.2" edition=":~~~jenkins~~"/>
        <vers num="3.0.2" edition="beta-1:~~~jenkins~~"/>
        <vers num="3.0.2" edition="beta-2:~~~jenkins~~"/>
        <vers num="3.0.3" edition=":~~~jenkins~~"/>
        <vers num="3.0.4" edition=":~~~jenkins~~"/>
        <vers num="3.0.5" edition=":~~~jenkins~~"/>
        <vers num="3.1.0" edition=":~~~jenkins~~"/>
        <vers num="3.2.0" edition=":~~~jenkins~~"/>
        <vers num="3.3.0" edition=":~~~jenkins~~"/>
        <vers num="3.3.1" edition=":~~~jenkins~~"/>
        <vers num="3.4.0" edition="alpha-1:~~~jenkins~~"/>
        <vers num="3.4.0" edition="alpha-4:~~~jenkins~~"/>
        <vers num="3.4.0" edition="beta-1:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000093" seq="2017-1000093" published="2017-10-04" modified="2017-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not consider polling to be a protection-worthy action as it's similar to cache invalidation, the plugin specifically adds a permission to be able to use this functionality, and this issue undermines that permission.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="poll_scm" vendor="jenkins">
        <vers num="1.3.1" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000094" seq="2017-1000094" published="2017-10-04" modified="2017-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="docker_commons" vendor="jenkins">
        <vers num="1.9" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000095" seq="2017-1000095" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g. currentBuild['rawBuild'] rather than currentBuild.rawBuild. Additionally, the following entries allowed accessing private data that would not be accessible otherwise due to script security: groovy.json.JsonOutput.toJson(Closure); groovy.json.JsonOutput.toJson(Object).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="script_security" vendor="jenkins">
        <vers num="1.34" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000096" seq="2017-1000096" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99571" adv="1">99571</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="pipeline:_groovy" vendor="jenkins">
        <vers num="2.36" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000097" seq="2017-1000097" published="2017-10-04" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/golang/go/issues/18141" adv="1">https://github.com/golang/go/issues/18141</ref>
      <ref source="CONFIRM" url="https://go-review.googlesource.com/c/33721/">https://go-review.googlesource.com/c/33721/</ref>
      <ref source="CONFIRM" url="https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ">https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ</ref>
    </refs>
    <vuln_soft>
      <prod name="go" vendor="golang">
        <vers num="1.6.3"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000098" seq="2017-1000098" published="2017-10-04" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://golang.org/cl/30410" adv="1" patch="1">https://golang.org/cl/30410</ref>
      <ref source="CONFIRM" url="https://golang.org/issue/17965" adv="1" patch="1">https://golang.org/issue/17965</ref>
      <ref source="CONFIRM" url="https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ">https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ</ref>
    </refs>
    <vuln_soft>
      <prod name="go" vendor="golang">
        <vers num="1.6.3"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000099" seq="2017-1000099" published="2017-10-04" modified="2017-11-01" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could lead to other private data from the heap to get inadvertently displayed. The wrong buffer was an uninitialized memory area allocated on the heap and if it turned out to not contain any zero byte, it would continue and display the data following that buffer in memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100281" adv="1">100281</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039119" adv="1">1039119</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/0809C.patch" adv="1" patch="1">https://curl.haxx.se/0809C.patch</ref>
      <ref source="MISC" url="https://curl.haxx.se/docs/adv_20170809C.html" adv="1">https://curl.haxx.se/docs/adv_20170809C.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-14" adv="1" patch="1">GLSA-201709-14</ref>
    </refs>
    <vuln_soft>
      <prod name="libcurl" vendor="haxx">
        <vers num="7.54.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10001" seq="2017-10001" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 1.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony First Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Simphony First Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony First Edition. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="1.7.1" edition=":~~first~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000100" seq="2017-1000100" published="2017-10-04" modified="2018-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length. This too large value is then used in the sendto() call, making curl attempt to send more data than what is actually put into the buffer. The endto() function will then read beyond the end of the heap based buffer. A malicious HTTP(S) server could redirect a vulnerable libcurl-using client to a crafted TFTP URL (if the client hasn't restricted which protocols it allows redirects to) and trick it to send private memory contents to a remote server over UDP. Limit curl's redirect protocols with --proto-redir and libcurl's with CURLOPT_REDIR_PROTOCOLS.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3992">DSA-3992</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100286" adv="1">100286</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039118" adv="1">1039118</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3558">RHSA-2018:3558</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/docs/adv_20170809B.html" adv="1" patch="1">https://curl.haxx.se/docs/adv_20170809B.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-14" adv="1" patch="1">GLSA-201709-14</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208221">https://support.apple.com/HT208221</ref>
    </refs>
    <vuln_soft>
      <prod name="libcurl" vendor="haxx">
        <vers num="7.15.0"/>
        <vers num="7.15.1"/>
        <vers num="7.15.2"/>
        <vers num="7.15.3"/>
        <vers num="7.15.4"/>
        <vers num="7.15.5"/>
        <vers num="7.16.0"/>
        <vers num="7.16.1"/>
        <vers num="7.16.2"/>
        <vers num="7.16.3"/>
        <vers num="7.16.4"/>
        <vers num="7.17.0"/>
        <vers num="7.17.1"/>
        <vers num="7.18.0"/>
        <vers num="7.18.1"/>
        <vers num="7.18.2"/>
        <vers num="7.19.0"/>
        <vers num="7.19.1"/>
        <vers num="7.19.2"/>
        <vers num="7.19.3"/>
        <vers num="7.19.4"/>
        <vers num="7.19.5"/>
        <vers num="7.19.6"/>
        <vers num="7.19.7"/>
        <vers num="7.20.0"/>
        <vers num="7.20.1"/>
        <vers num="7.21.0"/>
        <vers num="7.21.1"/>
        <vers num="7.21.2"/>
        <vers num="7.21.3"/>
        <vers num="7.21.4"/>
        <vers num="7.21.5"/>
        <vers num="7.21.6"/>
        <vers num="7.21.7"/>
        <vers num="7.22.0"/>
        <vers num="7.23.0"/>
        <vers num="7.23.1"/>
        <vers num="7.24.0"/>
        <vers num="7.25.0"/>
        <vers num="7.26.0"/>
        <vers num="7.27.0"/>
        <vers num="7.28.0"/>
        <vers num="7.28.1"/>
        <vers num="7.29.0"/>
        <vers num="7.30.0"/>
        <vers num="7.31.0"/>
        <vers num="7.32.0"/>
        <vers num="7.33.0"/>
        <vers num="7.34.0"/>
        <vers num="7.35.0"/>
        <vers num="7.36.0"/>
        <vers num="7.37.0"/>
        <vers num="7.37.1"/>
        <vers num="7.38.0"/>
        <vers num="7.39"/>
        <vers num="7.40.0"/>
        <vers num="7.41.0"/>
        <vers num="7.42.0"/>
        <vers num="7.42.1"/>
        <vers num="7.43.0"/>
        <vers num="7.44.0"/>
        <vers num="7.45.0"/>
        <vers num="7.46.0"/>
        <vers num="7.47.0"/>
        <vers num="7.47.1"/>
        <vers num="7.48.0"/>
        <vers num="7.49.0"/>
        <vers num="7.49.1"/>
        <vers num="7.50.0"/>
        <vers num="7.50.1"/>
        <vers num="7.50.2"/>
        <vers num="7.50.3"/>
        <vers num="7.51.0"/>
        <vers num="7.52.0"/>
        <vers num="7.52.1"/>
        <vers num="7.53.0"/>
        <vers num="7.53.1"/>
        <vers num="7.54.0"/>
        <vers num="7.54.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000101" seq="2017-1000101" published="2017-10-04" modified="2018-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3992">DSA-3992</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100249" adv="1">100249</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039117" adv="1">1039117</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3558">RHSA-2018:3558</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/docs/adv_20170809A.html" adv="1">https://curl.haxx.se/docs/adv_20170809A.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-14" adv="1">GLSA-201709-14</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208221">https://support.apple.com/HT208221</ref>
    </refs>
    <vuln_soft>
      <prod name="curl" vendor="haxx">
        <vers num="7.4.1"/>
        <vers num="7.35.0"/>
        <vers num="7.36.0"/>
        <vers num="7.37.0"/>
        <vers num="7.37.1"/>
        <vers num="7.38.0"/>
        <vers num="7.39.0"/>
        <vers num="7.40.0"/>
        <vers num="7.41.0"/>
        <vers num="7.42.0"/>
        <vers num="7.42.1"/>
        <vers num="7.43.0"/>
        <vers num="7.44.0"/>
        <vers num="7.45.0"/>
        <vers num="7.46.0"/>
        <vers num="7.47.0"/>
        <vers num="7.47.1"/>
        <vers num="7.48.0"/>
        <vers num="7.49.0"/>
        <vers num="7.49.1"/>
        <vers num="7.50.0"/>
        <vers num="7.50.1"/>
        <vers num="7.50.2"/>
        <vers num="7.50.3"/>
        <vers num="7.51.0"/>
        <vers num="7.52.0"/>
        <vers num="7.52.1"/>
        <vers num="7.53.0"/>
        <vers num="7.53.1"/>
        <vers num="7.54.0"/>
        <vers num="7.54.1"/>
        <vers num="7.55.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000102" seq="2017-1000102" published="2017-10-04" modified="2017-11-01" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101061" adv="1">101061</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="static_analysis_utilities" vendor="jenkins">
        <vers num="1.91" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000103" seq="2017-1000103" published="2017-10-04" modified="2017-11-01" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101061" adv="1">101061</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="dry" vendor="jenkins">
        <vers num="2.48" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000104" seq="2017-1000104" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="config_file_provider" vendor="jenkins">
        <vers num="2.16.1" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000105" seq="2017-1000105" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="blue_ocean" vendor="jenkins">
        <vers num="1.1.5" prev="1" edition=":~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-3:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000106" seq="2017-1000106" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeline creation and editing feature in Blue Ocean. The SCM content REST API did not check the current user's authentication or credentials. If the GitHub organization folder was created via Blue Ocean, it retained a reference to its creator's GitHub credentials. This allowed users with read access to the GitHub organization folder to create arbitrary commits in the repositories inside the GitHub organization corresponding to the GitHub organization folder with the GitHub credentials of the creator of the organization folder. Additionally, users with read access to the GitHub organization folder could read arbitrary file contents from the repositories inside the GitHub organization corresponding to the GitHub organization folder if the branch contained a Jenkinsfile (which could be created using the other part of this vulnerability), and they could provide the organization folder name, repository name, branch name, and file name.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="blue_ocean" vendor="jenkins">
        <vers num="1.1.5" prev="1" edition=":~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta1:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta2:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta3:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000107" seq="2017-1000107" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="script_security" vendor="jenkins">
        <vers num="1.30" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000108" seq="2017-1000108" published="2017-10-04" modified="2017-11-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="pipeline-input-step" vendor="jenkins">
        <vers num="2.0" edition=":~~~jenkins~~"/>
        <vers num="2.1" edition=":~~~jenkins~~"/>
        <vers num="2.2" edition=":~~~jenkins~~"/>
        <vers num="2.3" edition=":~~~jenkins~~"/>
        <vers num="2.4" edition=":~~~jenkins~~"/>
        <vers num="2.5" edition=":~~~jenkins~~"/>
        <vers num="2.6" edition=":~~~jenkins~~"/>
        <vers num="2.7" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000109" seq="2017-1000109" published="2017-10-04" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100227" adv="1">100227</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="owasp_dependency-check" vendor="jenkins">
        <vers num="1.0.1" edition=":~~~jenkins~~"/>
        <vers num="1.0.1.1" edition=":~~~jenkins~~"/>
        <vers num="1.0.2" edition=":~~~jenkins~~"/>
        <vers num="1.0.3" edition=":~~~jenkins~~"/>
        <vers num="1.0.4" edition=":~~~jenkins~~"/>
        <vers num="1.0.4.1" edition=":~~~jenkins~~"/>
        <vers num="1.0.5" edition=":~~~jenkins~~"/>
        <vers num="1.0.7" edition=":~~~jenkins~~"/>
        <vers num="1.0.8" edition=":~~~jenkins~~"/>
        <vers num="1.1.0" edition=":~~~jenkins~~"/>
        <vers num="1.1.1" edition=":~~~jenkins~~"/>
        <vers num="1.1.1.1" edition=":~~~jenkins~~"/>
        <vers num="1.1.1.2" edition=":~~~jenkins~~"/>
        <vers num="1.1.2" edition=":~~~jenkins~~"/>
        <vers num="1.1.3" edition=":~~~jenkins~~"/>
        <vers num="1.1.4" edition=":~~~jenkins~~"/>
        <vers num="1.1.4.1" edition=":~~~jenkins~~"/>
        <vers num="1.2.0" edition=":~~~jenkins~~"/>
        <vers num="1.2.1" edition=":~~~jenkins~~"/>
        <vers num="1.2.2" edition=":~~~jenkins~~"/>
        <vers num="1.2.3" edition=":~~~jenkins~~"/>
        <vers num="1.2.3.1" edition=":~~~jenkins~~"/>
        <vers num="1.2.3.2" edition=":~~~jenkins~~"/>
        <vers num="1.2.4" edition=":~~~jenkins~~"/>
        <vers num="1.2.5" edition=":~~~jenkins~~"/>
        <vers num="1.2.6" edition=":~~~jenkins~~"/>
        <vers num="1.2.7" edition=":~~~jenkins~~"/>
        <vers num="1.2.7.1" edition=":~~~jenkins~~"/>
        <vers num="1.2.8" edition=":~~~jenkins~~"/>
        <vers num="1.2.9" edition=":~~~jenkins~~"/>
        <vers num="1.2.10" edition=":~~~jenkins~~"/>
        <vers num="1.2.11" edition=":~~~jenkins~~"/>
        <vers num="1.2.11.1" edition=":~~~jenkins~~"/>
        <vers num="1.3.0" edition=":~~~jenkins~~"/>
        <vers num="1.3.1" edition=":~~~jenkins~~"/>
        <vers num="1.3.1.1" edition=":~~~jenkins~~"/>
        <vers num="1.3.1.2" edition=":~~~jenkins~~"/>
        <vers num="1.3.2" edition=":~~~jenkins~~"/>
        <vers num="1.3.3" edition=":~~~jenkins~~"/>
        <vers num="1.3.4" edition=":~~~jenkins~~"/>
        <vers num="1.3.5" edition=":~~~jenkins~~"/>
        <vers num="1.3.6" edition=":~~~jenkins~~"/>
        <vers num="1.4.0" edition=":~~~jenkins~~"/>
        <vers num="1.4.1" edition=":~~~jenkins~~"/>
        <vers num="1.4.2" edition=":~~~jenkins~~"/>
        <vers num="1.4.3" edition=":~~~jenkins~~"/>
        <vers num="1.4.4" edition=":~~~jenkins~~"/>
        <vers num="1.4.5" edition=":~~~jenkins~~"/>
        <vers num="2.0.0" edition=":~~~jenkins~~"/>
        <vers num="2.0.1" edition=":~~~jenkins~~"/>
        <vers num="2.0.1.1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000110" seq="2017-1000110" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did not properly check the current user's authentication and authorization when configuring existing GitHub organization folders. This allowed users with read access to the GitHub organization folder to reconfigure it, including changing the GitHub API endpoint for the organization folder to an attacker-controlled server to obtain the GitHub access token, if the organization folder was initially created using Blue Ocean.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="blue_ocean" vendor="jenkins">
        <vers num="1.1.5" prev="1" edition=":~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-1:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-2:~~~jenkins~~"/>
        <vers num="1.2.0" edition="beta-3:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000111" seq="2017-1000111" published="2017-10-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981" adv="1">DSA-3981</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100267" adv="1">100267</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039132" adv="1">1039132</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2918" adv="1">RHSA-2017:2918</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2930" adv="1">RHSA-2017:2930</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2931" adv="1">RHSA-2017:2931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3200" adv="1">RHSA-2017:3200</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/cve-2017-1000111" adv="1">https://access.redhat.com/security/cve/cve-2017-1000111</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.12.3" prev="1"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="virtualization" vendor="redhat">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000112" seq="2017-1000112" published="2017-10-04" modified="2018-08-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q3/277" adv="1" patch="1">[oss-security] 20170810 Linux kernel: CVE-2017-1000112: Exploitable memory corruption due to UFO to non-UFO path switch</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100262" adv="1">100262</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039162" adv="1">1039162</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2918">RHSA-2017:2918</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2930">RHSA-2017:2930</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2931">RHSA-2017:2931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3200">RHSA-2017:3200</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:1931">RHSA-2019:1931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:1932">RHSA-2019:1932</ref>
      <ref source="MISC" url="https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-1000112">https://github.com/xairy/kernel-exploits/tree/master/CVE-2017-1000112</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45147/">45147</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.13.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000113" seq="2017-1000113" published="2017-10-04" modified="2019-06-11" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system access, or users with Extended Read access to the jobs it is used in, to retrieve those passwords. The Deploy to container Plugin now integrates with Credentials Plugin to store passwords securely, and automatically migrates existing passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="deploy" vendor="jenkins">
        <vers num="1.12" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000114" seq="2017-1000114" published="2017-10-04" modified="2017-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the API key for example through browser extensions or cross-site scripting vulnerabilities. The Datadog Plugin now encrypts the API key transmitted to administrators viewing the global configuration form.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100223" adv="1">100223</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-08-07/" adv="1">https://jenkins.io/security/advisory/2017-08-07/</ref>
    </refs>
    <vuln_soft>
      <prod name="datadog" vendor="jenkins">
        <vers num="0.5.6" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000115" seq="2017-1000115" published="2017-10-04" modified="2019-05-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3963" adv="1">DSA-3963</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100290" adv="1">100290</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2489" adv="1">RHSA-2017:2489</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-18" adv="1">GLSA-201709-18</ref>
      <ref source="CONFIRM" url="https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29" adv="1">https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29</ref>
    </refs>
    <vuln_soft>
      <prod name="mercurial" vendor="mercurial">
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.7.0"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.9.0"/>
        <vers num="3.9.1"/>
        <vers num="3.9.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000116" seq="2017-1000116" published="2017-10-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3963" adv="1">DSA-3963</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100290" adv="1">100290</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2489" adv="1">RHSA-2017:2489</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-18" adv="1" patch="1">GLSA-201709-18</ref>
      <ref source="CONFIRM" url="https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29" adv="1">https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.2F_4.3.1_.282017-08-10.29</ref>
    </refs>
    <vuln_soft>
      <prod name="mercurial" vendor="mercurial">
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.7.0"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.9.0"/>
        <vers num="3.9.1"/>
        <vers num="3.9.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000117" seq="2017-1000117" published="2017-10-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3934">DSA-3934</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100283" adv="1">100283</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039131" adv="1">1039131</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2484">RHSA-2017:2484</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2485">RHSA-2017:2485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2491">RHSA-2017:2491</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2674">RHSA-2017:2674</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2675">RHSA-2017:2675</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-10" adv="1">GLSA-201709-10</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208103" adv="1">https://support.apple.com/HT208103</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42599/" adv="1">42599</ref>
      <ref source="MISC" url="https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1466490.html" adv="1" patch="1">https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg1466490.html</ref>
    </refs>
    <vuln_soft>
      <prod name="git" vendor="git-scm">
        <vers num="2.7.5" prev="1"/>
        <vers num="2.8.0" edition="rc0"/>
        <vers num="2.8.0" edition="rc1"/>
        <vers num="2.8.0" edition="rc2"/>
        <vers num="2.8.0" edition="rc3"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.9.0" edition="rc0"/>
        <vers num="2.9.0" edition="rc1"/>
        <vers num="2.9.0" edition="rc2"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.9.4"/>
        <vers num="2.10.0" edition="rc0"/>
        <vers num="2.10.0" edition="rc1"/>
        <vers num="2.10.0" edition="rc2"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.11.0" edition="rc0"/>
        <vers num="2.11.0" edition="rc1"/>
        <vers num="2.11.0" edition="rc2"/>
        <vers num="2.11.0" edition="rc3"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.12.0" edition="rc0"/>
        <vers num="2.12.0" edition="rc1"/>
        <vers num="2.12.0" edition="rc2"/>
        <vers num="2.12.1"/>
        <vers num="2.12.2"/>
        <vers num="2.12.3"/>
        <vers num="2.13.0" edition="rc0"/>
        <vers num="2.13.0" edition="rc1"/>
        <vers num="2.13.0" edition="rc2"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.13.3"/>
        <vers num="2.13.4"/>
        <vers num="2.14.0" edition="rc0"/>
        <vers num="2.14.0" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000118" seq="2017-1000118" published="2017-10-04" modified="2017-10-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Akka HTTP versions &lt;= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://doc.akka.io/docs/akka-http/10.0.6/security/2017-05-03-illegal-media-range-in-accept-header-causes-stackoverflowerror.html" adv="1">https://doc.akka.io/docs/akka-http/10.0.6/security/2017-05-03-illegal-media-range-in-accept-header-causes-stackoverflowerror.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="akka">
        <vers num="10.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000119" seq="2017-1000119" published="2017-10-04" modified="2019-09-06" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://octobercms.com/support/article/rn-8" adv="1">http://octobercms.com/support/article/rn-8</ref>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154390/October-CMS-Upload-Protection-Bypass-Code-Execution.html">http://packetstormsecurity.com/files/154390/October-CMS-Upload-Protection-Bypass-Code-Execution.html</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000120" seq="2017-1000120" published="2017-10-04" modified="2017-10-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">[ERPNext][Frappe Version &lt;= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://tech.mantz-it.com/2016/12/sql-injection-in-frappe-framework.html" adv="1">http://tech.mantz-it.com/2016/12/sql-injection-in-frappe-framework.html</ref>
    </refs>
    <vuln_soft>
      <prod name="frappe" vendor="frappe">
        <vers num="7.1.27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000121" seq="2017-1000121" published="2017-11-01" modified="2017-11-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://trac.webkit.org/changeset/217126/webkit" adv="1">http://trac.webkit.org/changeset/217126/webkit</ref>
      <ref source="MISC" url="https://webkitgtk.org/security/WSA-2017-0007.html" adv="1">https://webkitgtk.org/security/WSA-2017-0007.html</ref>
    </refs>
    <vuln_soft>
      <prod name="webkitgtk+" vendor="webkitgtk">
        <vers num="1.1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.15.1"/>
        <vers num="1.1.15.2"/>
        <vers num="1.1.15.3"/>
        <vers num="1.1.15.4"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
        <vers num="1.1.22"/>
        <vers num="1.1.23"/>
        <vers num="1.1.90"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.90"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.90"/>
        <vers num="1.7.91"/>
        <vers num="1.7.92"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.9.90"/>
        <vers num="1.9.91"/>
        <vers num="1.9.92"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.90"/>
        <vers num="1.11.91"/>
        <vers num="1.11.92"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.90"/>
        <vers num="2.1.90.1"/>
        <vers num="2.1.91"/>
        <vers num="2.1.92"/>
        <vers num="2.1.92a"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.2a"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.4a"/>
        <vers num="2.2.5"/>
        <vers num="2.2.5a"/>
        <vers num="2.2.6"/>
        <vers num="2.2.6a"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1a"/>
        <vers num="2.3.2"/>
        <vers num="2.3.2a"/>
        <vers num="2.3.3"/>
        <vers num="2.3.3a"/>
        <vers num="2.3.4"/>
        <vers num="2.3.4a"/>
        <vers num="2.3.5"/>
        <vers num="2.3.5a"/>
        <vers num="2.3.90"/>
        <vers num="2.3.90a"/>
        <vers num="2.3.91"/>
        <vers num="2.3.91a"/>
        <vers num="2.3.92"/>
        <vers num="2.3.92a"/>
        <vers num="2.4.0"/>
        <vers num="2.4.0a"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1a"/>
        <vers num="2.4.2"/>
        <vers num="2.4.2a"/>
        <vers num="2.4.3"/>
        <vers num="2.4.3a"/>
        <vers num="2.4.4"/>
        <vers num="2.4.4a"/>
        <vers num="2.4.5"/>
        <vers num="2.4.5a"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.5.1"/>
        <vers num="2.5.1a"/>
        <vers num="2.5.2"/>
        <vers num="2.5.2a"/>
        <vers num="2.5.3"/>
        <vers num="2.5.3a"/>
        <vers num="2.5.90"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.90"/>
        <vers num="2.7.91"/>
        <vers num="2.7.92"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.90"/>
        <vers num="2.9.91"/>
        <vers num="2.9.92"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers num="2.10.6"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
        <vers num="2.11.4"/>
        <vers num="2.11.5"/>
        <vers num="2.11.90"/>
        <vers num="2.11.91"/>
        <vers num="2.11.92"/>
        <vers num="2.12.0"/>
        <vers num="2.12.1"/>
        <vers num="2.12.2"/>
        <vers num="2.12.3"/>
        <vers num="2.12.4"/>
        <vers num="2.12.5"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.13.3"/>
        <vers num="2.13.4"/>
        <vers num="2.13.90"/>
        <vers num="2.13.91"/>
        <vers num="2.13.92"/>
        <vers num="2.14.0"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.14.6"/>
        <vers num="2.14.7"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.15.3"/>
        <vers num="2.15.4"/>
        <vers num="2.15.90"/>
        <vers num="2.15.91"/>
        <vers num="2.15.92"/>
        <vers num="2.16.0"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000122" seq="2017-1000122" published="2017-11-01" modified="2017-11-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secondary process to cause a denial of service (release assertion) of the UI process. This vulnerability does not affect Apple products.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://trac.webkit.org/changeset/217206" adv="1">http://trac.webkit.org/changeset/217206</ref>
      <ref source="MISC" url="https://webkitgtk.org/security/WSA-2017-0007.html" adv="1">https://webkitgtk.org/security/WSA-2017-0007.html</ref>
    </refs>
    <vuln_soft>
      <prod name="webkitgtk+" vendor="webkitgtk">
        <vers num="1.1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.15.1"/>
        <vers num="1.1.15.2"/>
        <vers num="1.1.15.3"/>
        <vers num="1.1.15.4"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
        <vers num="1.1.22"/>
        <vers num="1.1.23"/>
        <vers num="1.1.90"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.90"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.90"/>
        <vers num="1.7.91"/>
        <vers num="1.7.92"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.9.90"/>
        <vers num="1.9.91"/>
        <vers num="1.9.92"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.90"/>
        <vers num="1.11.91"/>
        <vers num="1.11.92"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.90"/>
        <vers num="2.1.90.1"/>
        <vers num="2.1.91"/>
        <vers num="2.1.92"/>
        <vers num="2.1.92a"/>
        <vers num="2.2.0"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.2a"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.4a"/>
        <vers num="2.2.5"/>
        <vers num="2.2.5a"/>
        <vers num="2.2.6"/>
        <vers num="2.2.6a"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1a"/>
        <vers num="2.3.2"/>
        <vers num="2.3.2a"/>
        <vers num="2.3.3"/>
        <vers num="2.3.3a"/>
        <vers num="2.3.4"/>
        <vers num="2.3.4a"/>
        <vers num="2.3.5"/>
        <vers num="2.3.5a"/>
        <vers num="2.3.90"/>
        <vers num="2.3.90a"/>
        <vers num="2.3.91"/>
        <vers num="2.3.91a"/>
        <vers num="2.3.92"/>
        <vers num="2.3.92a"/>
        <vers num="2.4.0"/>
        <vers num="2.4.0a"/>
        <vers num="2.4.1"/>
        <vers num="2.4.1a"/>
        <vers num="2.4.2"/>
        <vers num="2.4.2a"/>
        <vers num="2.4.3"/>
        <vers num="2.4.3a"/>
        <vers num="2.4.4"/>
        <vers num="2.4.4a"/>
        <vers num="2.4.5"/>
        <vers num="2.4.5a"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.5.1"/>
        <vers num="2.5.1a"/>
        <vers num="2.5.2"/>
        <vers num="2.5.2a"/>
        <vers num="2.5.3"/>
        <vers num="2.5.3a"/>
        <vers num="2.5.90"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.90"/>
        <vers num="2.7.91"/>
        <vers num="2.7.92"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.90"/>
        <vers num="2.9.91"/>
        <vers num="2.9.92"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers num="2.10.6"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
        <vers num="2.11.4"/>
        <vers num="2.11.5"/>
        <vers num="2.11.90"/>
        <vers num="2.11.91"/>
        <vers num="2.11.92"/>
        <vers num="2.12.0"/>
        <vers num="2.12.1"/>
        <vers num="2.12.2"/>
        <vers num="2.12.3"/>
        <vers num="2.12.4"/>
        <vers num="2.12.5"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.13.3"/>
        <vers num="2.13.4"/>
        <vers num="2.13.90"/>
        <vers num="2.13.91"/>
        <vers num="2.13.92"/>
        <vers num="2.14.0"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.14.6"/>
        <vers num="2.14.7"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.15.3"/>
        <vers num="2.15.4"/>
        <vers num="2.15.90"/>
        <vers num="2.15.91"/>
        <vers num="2.15.92"/>
        <vers num="2.16.0"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000123" seq="2017-1000123" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-12425. Reason: This candidate is a reservation duplicate of CVE-2017-12425. Notes: All CVE users should reference CVE-2017-12425 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000124" seq="2017-1000124" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11366. Reason: This candidate is a reservation duplicate of CVE-2017-11366. Notes: All CVE users should reference CVE-2017-11366 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000125" seq="2017-1000125" published="2017-11-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.jianshu.com/p/b09d20af2374" adv="1">http://www.jianshu.com/p/b09d20af2374</ref>
    </refs>
    <vuln_soft>
      <prod name="codiad" vendor="codiad">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000126" seq="2017-1000126" published="2017-11-17" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">exiv2 0.26 contains a Stack out of bounds read in webp parser</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/06/30/1" adv="1">[oss-security] 20170630 exiv2: multiple memory safety issues</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000127" seq="2017-1000127" published="2017-11-17" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Exiv2 0.26 contains a heap buffer overflow in tiff parser</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/06/30/1" adv="1">[oss-security] 20170630 exiv2: multiple memory safety issues</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000128" seq="2017-1000128" published="2017-11-17" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/06/30/1" adv="1">[oss-security] 20170630 exiv2: multiple memory safety issues</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000129" seq="2017-1000129" published="2017-11-17" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://blog.s9y.org/archives/269-Serendipity-2.0.4-and-2.1-beta2-released.html" adv="1">https://blog.s9y.org/archives/269-Serendipity-2.0.4-and-2.1-beta2-released.html</ref>
    </refs>
    <vuln_soft>
      <prod name="serendipity" vendor="s9y">
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000131" seq="2017-1000131" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1084336" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1084336</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000132" seq="2017-1000132" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1190788" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1190788</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000133" seq="2017-1000133" published="2017-11-03" modified="2017-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1234615" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1234615</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000134" seq="2017-1000134" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1267686" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1267686</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000135" seq="2017-1000135" published="2017-11-03" modified="2017-11-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1348024" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1348024</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000136" seq="2017-1000136" published="2017-11-03" modified="2017-11-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1363873" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1363873</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000137" seq="2017-1000137" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1375092" patch="1">https://bugs.launchpad.net/mahara/+bug/1375092</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.10" edition="rc1"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000138" seq="2017-1000138" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1377736" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1377736</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.10" edition="rc1"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000139" seq="2017-1000139" published="2017-11-03" modified="2017-11-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1397736" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1397736</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000140" seq="2017-1000140" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1404117" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1404117</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000141" seq="2017-1000141" published="2018-01-30" modified="2018-06-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to either prompt them for their password and/or send a warning to their primary email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.launchpad.net/mahara/+bug/1422492" adv="1">https://bugs.launchpad.net/mahara/+bug/1422492</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers num="1.1"/>
        <vers num="1.1.0" edition="alpha1"/>
        <vers num="1.1.0" edition="alpha2"/>
        <vers num="1.1.0" edition="alpha3"/>
        <vers num="1.1.0" edition="beta1"/>
        <vers num="1.1.0" edition="beta2"/>
        <vers num="1.1.0" edition="beta3"/>
        <vers num="1.1.0" edition="beta4"/>
        <vers num="1.1.0" edition="rc1"/>
        <vers num="1.1.0" edition="rc2"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.2.0" edition="alpha1"/>
        <vers num="1.2.0" edition="alpha2"/>
        <vers num="1.2.0" edition="alpha3"/>
        <vers num="1.2.0" edition="beta1"/>
        <vers num="1.2.0" edition="beta2"/>
        <vers num="1.2.0" edition="beta3"/>
        <vers num="1.2.0" edition="beta4"/>
        <vers num="1.2.0" edition="rc1"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3.0" edition="beta1"/>
        <vers num="1.3.0" edition="beta2"/>
        <vers num="1.3.0" edition="beta3"/>
        <vers num="1.3.0" edition="beta4"/>
        <vers num="1.3.0" edition="rc1"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
        <vers num="1.4" edition="rc4"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.5" edition="rc1"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.6.10"/>
        <vers num="1.7." edition="rc1"/>
        <vers num="1.7.0" edition="-"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.6"/>
        <vers num="1.7.7"/>
        <vers num="1.7.8"/>
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.9.7"/>
        <vers num="1.9.8"/>
        <vers num="1.9.9"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="1.10.5"/>
        <vers num="1.10.6"/>
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.10.9"/>
        <vers num="1.10.10"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.04.8"/>
        <vers num="15.04.9"/>
        <vers num="15.04.10"/>
        <vers num="15.04.11"/>
        <vers num="15.04.12"/>
        <vers num="15.04.13"/>
        <vers num="15.04.14"/>
        <vers num="15.04.15"/>
        <vers num="15.10" edition="rc1"/>
        <vers num="15.10" edition="rc2"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="15.10.4"/>
        <vers num="15.10.5"/>
        <vers num="15.10.6"/>
        <vers num="15.10.7"/>
        <vers num="15.10.8"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
        <vers num="16.04.2"/>
        <vers num="16.04.3"/>
        <vers num="16.04.4"/>
        <vers num="16.04.5"/>
        <vers num="16.04.6"/>
        <vers num="16.04.7"/>
        <vers num="16.04.8"/>
        <vers num="16.04.9"/>
        <vers num="16.10" edition="rc1"/>
        <vers num="16.10" edition="rc2"/>
        <vers num="16.10.0"/>
        <vers num="16.10.1"/>
        <vers num="16.10.2"/>
        <vers num="16.10.3"/>
        <vers num="16.10.4"/>
        <vers num="16.10.5"/>
        <vers num="16.10.6"/>
        <vers num="16.10.7"/>
        <vers num="16.10.8"/>
        <vers num="16.10.9"/>
        <vers num="17.04" edition="rc1"/>
        <vers num="17.04" edition="rc2"/>
        <vers num="17.04.0"/>
        <vers num="17.04.1"/>
        <vers num="17.04.2"/>
        <vers num="17.04.3"/>
        <vers num="17.04.4"/>
        <vers num="17.04.5"/>
        <vers num="17.04.6"/>
        <vers num="17.04.7"/>
        <vers num="17.04.8"/>
        <vers num="17.10.0"/>
        <vers num="17.10.1"/>
        <vers num="17.10.2"/>
        <vers num="17.10.3"/>
        <vers num="17.10.4"/>
        <vers num="17.10.5"/>
        <vers num="17.10.8"/>
        <vers num="18.04.0"/>
        <vers num="18.04.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000142" seq="2017-1000142" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1425306" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1425306</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000143" seq="2017-1000143" published="2017-11-03" modified="2017-11-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1429647" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1429647</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.8" edition="rc1"/>
        <vers num="1.8" edition="rc2"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000144" seq="2017-1000144" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1447377" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1447377</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000145" seq="2017-1000145" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1460368" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1460368</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000146" seq="2017-1000146" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1472439" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1472439</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000147" seq="2017-1000147" published="2017-11-03" modified="2017-11-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1480329" patch="1">https://bugs.launchpad.net/mahara/+bug/1480329</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.9" edition="rc1"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.9.7"/>
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="1.10.5"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000148" seq="2017-1000148" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1508684" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1508684</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000149" seq="2017-1000149" published="2017-11-03" modified="2017-11-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1558361" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1558361</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="1.10" edition="rc1"/>
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="1.10.5"/>
        <vers num="1.10.6"/>
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.10" edition="rc1"/>
        <vers num="15.10" edition="rc2"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000150" seq="2017-1000150" published="2017-11-03" modified="2017-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1567784" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1567784</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000151" seq="2017-1000151" published="2017-11-03" modified="2017-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1570221" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1570221</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.04.8"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="15.10.4"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
        <vers num="16.04.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000152" seq="2017-1000152" published="2017-11-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1570744" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1570744</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000153" seq="2017-1000153" published="2017-11-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1577251" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1577251</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.04.8"/>
        <vers num="15.04.9"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="15.10.4"/>
        <vers num="15.10.5"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
        <vers num="16.04.2"/>
        <vers num="16.04.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000154" seq="2017-1000154" published="2017-11-03" modified="2017-11-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1580399" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1580399</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000155" seq="2017-1000155" published="2017-11-03" modified="2017-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1600069" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1600069</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000156" seq="2017-1000156" published="2017-11-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1609200" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1609200</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.04.8"/>
        <vers num="15.10.0"/>
        <vers num="15.10.1"/>
        <vers num="15.10.2"/>
        <vers num="15.10.3"/>
        <vers num="15.10.4"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
        <vers num="16.04.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000157" seq="2017-1000157" published="2017-11-03" modified="2017-11-13" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/mahara/+bug/1692749" adv="1" patch="1">https://bugs.launchpad.net/mahara/+bug/1692749</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara" vendor="mahara">
        <vers num="15.04" edition="rc1"/>
        <vers num="15.04" edition="rc2"/>
        <vers num="15.04.0"/>
        <vers num="15.04.1"/>
        <vers num="15.04.2"/>
        <vers num="15.04.3"/>
        <vers num="15.04.4"/>
        <vers num="15.04.5"/>
        <vers num="15.04.6"/>
        <vers num="15.04.7"/>
        <vers num="15.04.8"/>
        <vers num="15.04.9"/>
        <vers num="15.04.10"/>
        <vers num="15.04.11"/>
        <vers num="15.04.12"/>
        <vers num="16.04" edition="rc1"/>
        <vers num="16.04" edition="rc2"/>
        <vers num="16.04.0"/>
        <vers num="16.04.1"/>
        <vers num="16.04.2"/>
        <vers num="16.04.3"/>
        <vers num="16.04.4"/>
        <vers num="16.04.5"/>
        <vers num="16.04.6"/>
        <vers num="16.10" edition="rc1"/>
        <vers num="16.10" edition="rc2"/>
        <vers num="16.10.0"/>
        <vers num="16.10.1"/>
        <vers num="16.10.2"/>
        <vers num="16.10.3"/>
        <vers num="17.04" edition="rc1"/>
        <vers num="17.04" edition="rc2"/>
        <vers num="17.04.0"/>
        <vers num="17.04.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000158" seq="2017-1000158" published="2017-11-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039890" adv="1">1039890</ref>
      <ref source="MISC" url="https://bugs.python.org/issue30657" adv="1" patch="1">https://bugs.python.org/issue30657</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00035.html" adv="1">[debian-lts-announce] 20171124 [SECURITY] [DLA 1189-1] python2.7 security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00036.html" adv="1">[debian-lts-announce] 20171124 [SECURITY] [DLA 1190-1] python2.6 security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html" adv="1">[debian-lts-announce] 20180925 [SECURITY] [DLA 1519-1] python2.7 security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html" adv="1">[debian-lts-announce] 20180926 [SECURITY] [DLA 1520-1] python3.4 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201805-02" adv="1">GLSA-201805-02</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4307" adv="1">DSA-4307</ref>
    </refs>
    <vuln_soft>
      <prod name="python" vendor="python">
        <vers num="2.7.13" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000159" seq="2017-1000159" published="2017-11-27" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.gnome.org/show_bug.cgi?id=784947" patch="1">https://bugzilla.gnome.org/show_bug.cgi?id=784947</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/12/msg00006.html">[debian-lts-announce] 20171211 [SECURITY] [DLA 1204-1] evince security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/08/msg00013.html">[debian-lts-announce] 20190813 [SECURITY] [DLA 1881-1] evince security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/08/msg00014.html">[debian-lts-announce] 20190813 [SECURITY] [DLA 1882-1] atril security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-15">GLSA-201804-15</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000160" seq="2017-1000160" published="2017-11-17" modified="2017-12-01" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://docs.expressionengine.com/latest/about/changelog.html#version-3-4-3" adv="1">https://docs.expressionengine.com/latest/about/changelog.html#version-3-4-3</ref>
    </refs>
    <vuln_soft>
      <prod name="expressionengine" vendor="ellislab">
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000161" seq="2017-1000161" published="2017-11-17" modified="2017-11-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000162" seq="2017-1000162" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-12474, CVE-2017-12475, CVE-2017-12476.  Reason: This candidate is a reservation duplicate of CVE-2017-12474, CVE-2017-12475, and CVE-2017-12476.  Notes: All CVE users should reference CVE-2017-12474, CVE-2017-12475, and/or CVE-2017-12476 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000163" seq="2017-1000163" published="2017-11-17" modified="2017-12-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://elixirforum.com/t/security-releases-for-phoenix/4143" adv="1">https://elixirforum.com/t/security-releases-for-phoenix/4143</ref>
    </refs>
    <vuln_soft>
      <prod name="phoenix" vendor="phoenixframework">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.2.0"/>
        <vers num="1.2.2"/>
        <vers num="1.3.0-rc.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000164" seq="2017-1000164" published="2017-11-17" modified="2017-11-29" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://forge.tine20.org/view.php?id=13228" adv="1" patch="1">https://forge.tine20.org/view.php?id=13228</ref>
    </refs>
    <vuln_soft>
      <prod name="tine_2.0" vendor="tine20">
        <vers num="2017.02.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000165" seq="2017-1000165" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11366. Reason: This candidate is a reservation duplicate of CVE-2017-11366. Notes: All CVE users should reference CVE-2017-11366 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000166" seq="2017-1000166" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by the Primary CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000167" seq="2017-1000167" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by the Primary CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000168" seq="2017-1000168" published="2017-11-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/dnaq/sodiumoxide/issues/154" adv="1">https://github.com/dnaq/sodiumoxide/issues/154</ref>
    </refs>
    <vuln_soft>
      <prod name="sodiumoxide" vendor="sodiumoxide_project">
        <vers num="0.0.13" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000169" seq="2017-1000169" published="2017-11-17" modified="2017-12-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">QuickerBB version &lt;= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/halojoy/QuickerBB/issues/10" adv="1">https://github.com/halojoy/QuickerBB/issues/10</ref>
    </refs>
    <vuln_soft>
      <prod name="quickerbb" vendor="quickerbb_project">
        <vers num="0.7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000170" seq="2017-1000170" published="2017-11-17" modified="2017-12-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">jqueryFileTree 2.1.5 and older Directory Traversal</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/jqueryfiletree/jqueryfiletree/issues/66" adv="1" patch="1">https://github.com/jqueryfiletree/jqueryfiletree/issues/66</ref>
    </refs>
    <vuln_soft>
      <prod name="jqueryfiletree" vendor="jqueryfiletree_project">
        <vers num="2.1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000171" seq="2017-1000171" published="2017-11-03" modified="2017-11-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/MaharaProject/mahara-mobile/issues/33" adv="1">https://github.com/MaharaProject/mahara-mobile/issues/33</ref>
    </refs>
    <vuln_soft>
      <prod name="mahara_mobile" vendor="mahara">
        <vers num="1.2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000172" seq="2017-1000172" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has already been freed, creating a Heap Use-After-Free condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/marcobambini/gravity/issues/144" adv="1">https://github.com/marcobambini/gravity/issues/144</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000173" seq="2017-1000173" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/marcobambini/gravity/issues/172" adv="1" patch="1">https://github.com/marcobambini/gravity/issues/172</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000174" seq="2017-1000174" published="2017-11-16" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, an address access exception was found in swfdump swf_GetBits().</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/21" adv="1">https://github.com/matthiaskramm/swftools/issues/21</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000175" seq="2017-1000175" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by the Primary CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000176" seq="2017-1000176" published="2017-11-16" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, a memcpy buffer overflow was found in swfc.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/23" adv="1">https://github.com/matthiaskramm/swftools/issues/23</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000177" seq="2017-1000177" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11097. Reason: This candidate is a reservation duplicate of CVE-2017-11097. Notes: All CVE users should reference CVE-2017-11097 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000178" seq="2017-1000178" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11096. Reason: This candidate is a reservation duplicate of CVE-2017-11096. Notes: All CVE users should reference CVE-2017-11096 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000179" seq="2017-1000179" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11101. Reason: This candidate is a reservation duplicate of CVE-2017-11101. Notes: All CVE users should reference CVE-2017-11101 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000180" seq="2017-1000180" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11100. Reason: This candidate is a reservation duplicate of CVE-2017-11100. Notes: All CVE users should reference CVE-2017-11100 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000181" seq="2017-1000181" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-10976. Reason: This candidate is a reservation duplicate of CVE-2017-10976. Notes: All CVE users should reference CVE-2017-10976 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000182" seq="2017-1000182" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, a memory leak was found in wav2swf.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/30" adv="1">https://github.com/matthiaskramm/swftools/issues/30</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000183" seq="2017-1000183" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11099. Reason: This candidate is a reservation duplicate of CVE-2017-11099. Notes: All CVE users should reference CVE-2017-11099 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000184" seq="2017-1000184" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11098. Reason: This candidate is a reservation duplicate of CVE-2017-11098. Notes: All CVE users should reference CVE-2017-11098 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000185" seq="2017-1000185" published="2017-11-16" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, a memcpy buffer overflow was found in gif2swf.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/33" adv="1">https://github.com/matthiaskramm/swftools/issues/33</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000186" seq="2017-1000186" published="2017-11-16" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, a stack overflow was found in pdf2swf.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/34" adv="1">https://github.com/matthiaskramm/swftools/issues/34</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000187" seq="2017-1000187" published="2017-11-16" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In SWFTools, an address access exception was found in pdf2swf. FoFiTrueType::writeTTF()</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/36" adv="1">https://github.com/matthiaskramm/swftools/issues/36</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000188" seq="2017-1000188" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101889" adv="1">101889</ref>
      <ref source="MISC" url="https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f" adv="1" patch="1">https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f</ref>
    </refs>
    <vuln_soft>
      <prod name="ejs" vendor="ejs">
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000189" seq="2017-1000189" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101893" adv="1">101893</ref>
      <ref source="MISC" url="https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f" adv="1" patch="1">https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f</ref>
    </refs>
    <vuln_soft>
      <prod name="ejs" vendor="ejs">
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000190" seq="2017-1000190" published="2017-11-17" modified="2019-07-23" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/ngallagher/simplexml/issues/18" adv="1">https://github.com/ngallagher/simplexml/issues/18</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/8c4ef27e2c0218f29e785990dc919266855aea137c958f10d242cb36@%3Cdev.lucene.apache.org%3E">[lucene-dev] 20190723 [jira] [Updated] (SOLR-13648) vulnerable simple-xml-2.7.1.jar</ref>
    </refs>
    <vuln_soft>
      <prod name="simplexml" vendor="simplexml_project">
        <vers num="2.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000191" seq="2017-1000191" published="2017-11-17" modified="2017-12-04" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/NICMx/Jool/issues/232" adv="1">https://github.com/NICMx/Jool/issues/232</ref>
    </refs>
    <vuln_soft>
      <prod name="jool" vendor="jool">
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000192" seq="2017-1000192" published="2017-11-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901" adv="1">https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901</ref>
    </refs>
    <vuln_soft>
      <prod name="syspass" vendor="cygnux">
        <vers num="2.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000193" seq="2017-1000193" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-66d6dfe5e11488e1afefcb69b8bdaabfR31" patch="1">https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-66d6dfe5e11488e1afefcb69b8bdaabfR31</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000194" seq="2017-1000194" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R224" patch="1">https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R224</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000195" seq="2017-1000195" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R317" patch="1">https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R317</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000196" seq="2017-1000196" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R49" patch="1">https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-c328b7b99eac0d17b3c71eb37038fd61R49</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000197" seq="2017-1000197" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-eef90a4e3585febf6489916dc242d0ceR241" patch="1">https://github.com/octobercms/october/compare/v1.0.412...v1.0.413#diff-eef90a4e3585febf6489916dc242d0ceR241</ref>
    </refs>
    <vuln_soft>
      <prod name="october_cms" vendor="octobercms">
        <vers num="1.0.412" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000198" seq="2017-1000198" published="2017-11-16" modified="2017-12-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3277">RHSA-2017:3277</ref>
      <ref source="MISC" url="https://github.com/open-iscsi/tcmu-runner/commit/61bd03e600d2abf309173e9186f4d465bb1b7157" adv="1" patch="1">https://github.com/open-iscsi/tcmu-runner/commit/61bd03e600d2abf309173e9186f4d465bb1b7157</ref>
    </refs>
    <vuln_soft>
      <prod name="tcmu-runner" vendor="tcmu-runner_project">
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000199" seq="2017-1000199" published="2017-11-16" modified="2017-12-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3277">RHSA-2017:3277</ref>
      <ref source="MISC" url="https://github.com/open-iscsi/tcmu-runner/issues/194" adv="1">https://github.com/open-iscsi/tcmu-runner/issues/194</ref>
    </refs>
    <vuln_soft>
      <prod name="tcmu-runner" vendor="tcmu-runner_project">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10002" seq="2017-10002" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Settings and Config). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Inventory Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Inventory Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Inventory Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99699" adv="1">99699</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_inventory_management" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000200" seq="2017-1000200" published="2017-11-16" modified="2017-12-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3277">RHSA-2017:3277</ref>
      <ref source="MISC" url="https://github.com/open-iscsi/tcmu-runner/pull/200/commits/bb80e9c7a798f035768260ebdadffb6eb0786178" adv="1" patch="1">https://github.com/open-iscsi/tcmu-runner/pull/200/commits/bb80e9c7a798f035768260ebdadffb6eb0786178</ref>
    </refs>
    <vuln_soft>
      <prod name="tcmu-runner" vendor="tcmu-runner_project">
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000201" seq="2017-1000201" published="2017-11-16" modified="2017-12-01" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3277">RHSA-2017:3277</ref>
      <ref source="MISC" url="https://github.com/open-iscsi/tcmu-runner/pull/200/commits/e2d953050766ac538615a811c64b34358614edce" adv="1" patch="1">https://github.com/open-iscsi/tcmu-runner/pull/200/commits/e2d953050766ac538615a811c64b34358614edce</ref>
    </refs>
    <vuln_soft>
      <prod name="tcmu-runner" vendor="tcmu-runner_project">
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000202" seq="2017-1000202" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-12933. Reason: This candidate is a reservation duplicate of CVE-2017-12933. Notes: All CVE users should reference CVE-2017-12933 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000203" seq="2017-1000203" published="2017-11-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/root-project/root/commit/88ccff152604e0f1012653a596d802ff7ede3145#diff-6cd6f6c31bac70116b7ca7abdc8e517e" adv="1" patch="1">https://github.com/root-project/root/commit/88ccff152604e0f1012653a596d802ff7ede3145#diff-6cd6f6c31bac70116b7ca7abdc8e517e</ref>
    </refs>
    <vuln_soft>
      <prod name="root" vendor="cern">
        <vers num="6.9.03" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000204" seq="2017-1000204" published="2017-11-17" modified="2017-11-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2016-9920.  Reason: This candidate is a reservation duplicate of CVE-2016-9920.  Notes: All CVE users should reference CVE-2016-9920 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000205" seq="2017-1000205" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-9091.  Reason: This candidate is a reservation duplicate of CVE-2017-9091.  Notes: All CVE users should reference CVE-2017-9091 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000206" seq="2017-1000206" published="2017-11-17" modified="2017-12-01" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/samtools/htslib/blob/1.4.1/NEWS" adv="1">https://github.com/samtools/htslib/blob/1.4.1/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod name="htslib" vendor="htslib">
        <vers num="1.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000207" seq="2017-1000207" published="2017-11-27" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A vulnerability in Swagger-Parser's version &lt;= 1.0.30 and Swagger codegen version &lt;= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (&lt;= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/swagger-api/swagger-parser/pull/481">https://github.com/swagger-api/swagger-parser/pull/481</ref>
      <ref source="MISC" url="https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208" adv="1">https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208</ref>
    </refs>
    <vuln_soft>
      <prod name="swagger-codegen" vendor="swagger">
        <vers num="2.2.2" prev="1"/>
      </prod>
      <prod name="swagger-parser" vendor="swagger">
        <vers num="1.0.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000208" seq="2017-1000208" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A vulnerability in Swagger-Parser's (version &lt;= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (&lt;= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/swagger-api/swagger-parser/releases/tag/v1.0.31">https://github.com/swagger-api/swagger-parser/releases/tag/v1.0.31</ref>
      <ref source="MISC" url="https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208" adv="1">https://lgtm.com/blog/swagger_snakeyaml_CVE-2017-1000207_CVE-2017-1000208</ref>
    </refs>
    <vuln_soft>
      <prod name="swagger-codegen" vendor="swagger">
        <vers num="2.2.2" prev="1"/>
      </prod>
      <prod name="swagger-parser" vendor="swagger">
        <vers num="1.0.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000209" seq="2017-1000209" published="2017-11-16" modified="2017-12-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107" adv="1">https://github.com/TakahikoKawasaki/nv-websocket-client/pull/107</ref>
    </refs>
    <vuln_soft>
      <prod name="nv-websocket-client" vendor="nv-websocket-client_project">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000210" seq="2017-1000210" published="2017-11-16" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">picoTCP (versions 1.7.0 - 1.5.0) is vulnerable to stack buffer overflow resulting in code execution or denial of service attack</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/tass-belgium/picotcp/pull/473" adv="1" patch="1">https://github.com/tass-belgium/picotcp/pull/473</ref>
    </refs>
    <vuln_soft>
      <prod name="picotcp" vendor="altran">
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000211" seq="2017-1000211" published="2017-11-17" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lynx.invisible-island.net/current/CHANGES.html" adv="1">http://lynx.invisible-island.net/current/CHANGES.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102180">102180</ref>
      <ref source="MISC" url="https://github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9" adv="1">https://github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00021.html">[debian-lts-announce] 20171118 [SECURITY] [DLA 1175-1] lynx-cur security update</ref>
    </refs>
    <vuln_soft>
      <prod name="lynx" vendor="lynx_project">
        <vers num="2.8.9" edition="dev15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000212" seq="2017-1000212" published="2017-11-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/tonini/alchemist-server/issues/14" adv="1">https://github.com/tonini/alchemist-server/issues/14</ref>
    </refs>
    <vuln_soft>
      <prod name="alchemist-server" vendor="alchemist-elixir">
        <vers num="-" edition=":~~~vim~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000213" seq="2017-1000213" published="2017-11-16" modified="2017-11-29" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/WBCE/WBCE_CMS/commit/0da620016aec17ac2d2f3a22c55ab8c2b55e691e#diff-7b380285e285160d0070863099baabe0" adv="1" patch="1">https://github.com/WBCE/WBCE_CMS/commit/0da620016aec17ac2d2f3a22c55ab8c2b55e691e#diff-7b380285e285160d0070863099baabe0</ref>
    </refs>
    <vuln_soft>
      <prod name="wbce_cms" vendor="wbce">
        <vers num="1.1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000214" seq="2017-1000214" published="2017-11-27" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GitPHP by xiphux is vulnerable to OS Command Injections</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Enalean/gitphp/commit/160621785ee812d6d90e20878bd6175e42c13c94" adv="1">https://github.com/Enalean/gitphp/commit/160621785ee812d6d90e20878bd6175e42c13c94</ref>
      <ref source="CONFIRM" url="https://github.com/xiphux/gitphp/pull/37">https://github.com/xiphux/gitphp/pull/37</ref>
    </refs>
    <vuln_soft>
      <prod name="gitphp" vendor="gitphp_project">
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.7"/>
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
        <vers num="0.1.0"/>
        <vers num="0.1.1"/>
        <vers num="0.2.0"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000215" seq="2017-1000215" published="2017-11-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/xrootd/xrootd/blob/befa2e627a5a33a38c92db3e57c07d8246a24acf/src/XrdSecgsi/XrdSecgsiGMAPFunLDAP.cc#L85" adv="1">https://github.com/xrootd/xrootd/blob/befa2e627a5a33a38c92db3e57c07d8246a24acf/src/XrdSecgsi/XrdSecgsiGMAPFunLDAP.cc#L85</ref>
      <ref source="CONFIRM" url="https://github.com/xrootd/xrootd/blob/v4.6.1/docs/ReleaseNotes.txt" adv="1">https://github.com/xrootd/xrootd/blob/v4.6.1/docs/ReleaseNotes.txt</ref>
      <ref source="CONFIRM" url="https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf" adv="1" patch="1">https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201903-11" adv="1">GLSA-201903-11</ref>
    </refs>
    <vuln_soft>
      <prod name="xrootd" vendor="xrootd">
        <vers num="4.6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000216" seq="2017-1000216" published="2017-08-20" modified="2017-08-20" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11104. Reason: This candidate is a reservation duplicate of CVE-2017-11104. Notes: All CVE users should reference CVE-2017-11104 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000217" seq="2017-1000217" published="2017-11-17" modified="2019-04-29" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://groups.google.com/a/opencast.org/forum/#!topic/security-notices/sCpt0pIPEFg" adv="1">https://groups.google.com/a/opencast.org/forum/#!topic/security-notices/sCpt0pIPEFg</ref>
    </refs>
    <vuln_soft>
      <prod name="opencast" vendor="opencast">
        <vers num="2.3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000218" seq="2017-1000218" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/hfiref0x/LightFTP/issues/5" adv="1">https://github.com/hfiref0x/LightFTP/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="lightftp" vendor="lightftp_project">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000219" seq="2017-1000219" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://nodesecurity.io/advisories/336" adv="1">https://nodesecurity.io/advisories/336</ref>
    </refs>
    <vuln_soft>
      <prod name="windows-cpu" vendor="windows-cpu_project">
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000220" seq="2017-1000220" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">soyuka/pidusage &lt;=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://nodesecurity.io/advisories/356" adv="1">https://nodesecurity.io/advisories/356</ref>
    </refs>
    <vuln_soft>
      <prod name="pidusage" vendor="pidusage_project">
        <vers num="1.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000221" seq="2017-1000221" published="2017-11-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have access to recordings published only for ROLE_USER_X.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://opencast.jira.com/browse/MH-11862" adv="1">https://opencast.jira.com/browse/MH-11862</ref>
    </refs>
    <vuln_soft>
      <prod name="opencast" vendor="apereo">
        <vers num="2.2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000222" seq="2017-1000222" published="2017-11-17" modified="2017-11-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000223" seq="2017-1000223" published="2017-11-17" modified="2017-12-01" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://raw.githubusercontent.com/modxcms/revolution/v2.5.7-pl/core/docs/changelog.txt" adv="1">https://raw.githubusercontent.com/modxcms/revolution/v2.5.7-pl/core/docs/changelog.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="modx_revolution" vendor="modx">
        <vers num="2.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000224" seq="2017-1000224" published="2017-11-16" modified="2017-12-03" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://security.dxw.com/advisories/csrf-in-youtube-plugin/" adv="1">https://security.dxw.com/advisories/csrf-in-youtube-plugin/</ref>
    </refs>
    <vuln_soft>
      <prod name="youtube" vendor="embedplus">
        <vers num="11.8.1" prev="1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000225" seq="2017-1000225" published="2017-11-17" modified="2017-12-01" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://security.dxw.com/advisories/reflected-xss-in-relevanssi-premium-when-using-relevanssi_didyoumean-could-allow-unauthenticated-attacker-to-do-almost-anything-an-admin-can/" adv="1">https://security.dxw.com/advisories/reflected-xss-in-relevanssi-premium-when-using-relevanssi_didyoumean-could-allow-unauthenticated-attacker-to-do-almost-anything-an-admin-can/</ref>
    </refs>
    <vuln_soft>
      <prod name="relevanssi" vendor="relevanssi">
        <vers num="1.14.8" edition=":~~premium~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000226" seq="2017-1000226" published="2017-11-17" modified="2017-12-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Stop User Enumeration 1.3.8 allows user enumeration via the REST API</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://security.dxw.com/advisories/stop-user-enumeration-rest-api/" adv="1">https://security.dxw.com/advisories/stop-user-enumeration-rest-api/</ref>
    </refs>
    <vuln_soft>
      <prod name="stop_user_enumeration" vendor="fullworks">
        <vers num="1.3.8" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000227" seq="2017-1000227" published="2017-11-17" modified="2019-08-24" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://security.dxw.com/advisories/stored-xss-salutation-theme/" adv="1">https://security.dxw.com/advisories/stored-xss-salutation-theme/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/9734">https://wpvulndb.com/vulnerabilities/9734</ref>
    </refs>
    <vuln_soft>
      <prod name="salutation" vendor="parallelus">
        <vers num="3.0.15" edition=":~~~buddypress~~"/>
        <vers num="3.0.15" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000228" seq="2017-1000228" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101897" adv="1">101897</ref>
      <ref source="MISC" url="https://snyk.io/vuln/npm:ejs:20161128" adv="1">https://snyk.io/vuln/npm:ejs:20161128</ref>
    </refs>
    <vuln_soft>
      <prod name="ejs" vendor="ejs">
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000229" seq="2017-1000229" published="2017-11-17" modified="2019-05-06" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00030.html" adv="1">[debian-lts-announce] 20171121 [SECURITY] [DLA 1184-1] optipng security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201801-02" adv="1">GLSA-201801-02</ref>
      <ref source="MISC" url="https://sourceforge.net/p/optipng/bugs/65/" adv="1">https://sourceforge.net/p/optipng/bugs/65/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4058" adv="1">DSA-4058</ref>
    </refs>
    <vuln_soft>
      <prod name="optipng" vendor="optipng_project">
        <vers num="0.7.6"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000230" seq="2017-1000230" published="2017-11-17" modified="2017-12-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulting in denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://sourceforge.net/p/snap7/discussion/bugfix/thread/2d2d085c/" adv="1">https://sourceforge.net/p/snap7/discussion/bugfix/thread/2d2d085c/</ref>
    </refs>
    <vuln_soft>
      <prod name="snap7_server" vendor="snap7_project">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000231" seq="2017-1000231" published="2017-11-16" modified="2018-02-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00028.html">[debian-lts-announce] 20171121 [SECURITY] [DLA 1182-1] ldns security update</ref>
      <ref source="MISC" url="https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=1256" adv="1" patch="1">https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=1256</ref>
    </refs>
    <vuln_soft>
      <prod name="ldns" vendor="nlnetlabs">
        <vers num="1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000232" seq="2017-1000232" published="2017-11-16" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=1257" adv="1">https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=1257</ref>
    </refs>
    <vuln_soft>
      <prod name="ldns" vendor="nlnetlabs">
        <vers num="1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000233" seq="2017-1000233" published="2017-11-17" modified="2017-11-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-11667.  Reason: This candidate is a reservation duplicate of CVE-2017-11667.  Notes: All CVE users should reference CVE-2017-11667 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000234" seq="2017-1000234" published="2017-11-16" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">I, Librarian version &lt;=4.6 &amp; 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simply by navigating through the "dir" parameter</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="i_librarian" vendor="i-librarian">
        <vers num="4.6" prev="1"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000235" seq="2017-1000235" published="2017-11-16" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">I, Librarian version &lt;=4.6 &amp; 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="i_librarian" vendor="i-librarian">
        <vers num="4.6" prev="1"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000236" seq="2017-1000236" published="2017-11-16" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">I, Librarian version &lt;=4.6 &amp; 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="i_librarian" vendor="i-librarian">
        <vers num="4.6" prev="1"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000237" seq="2017-1000237" published="2017-11-16" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">I, Librarian version &lt;=4.6 &amp; 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170509-0_I_Librarian_Multiple_vulnerabilities_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="i_librarian" vendor="i-librarian">
        <vers num="4.6" prev="1"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000238" seq="2017-1000238" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170523-0_InvoicePlane_Upload_arbitrary_files_stored_XSS_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170523-0_InvoicePlane_Upload_arbitrary_files_stored_XSS_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="invoiceplane" vendor="invoiceplane">
        <vers num="1.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000239" seq="2017-1000239" published="2017-11-16" modified="2017-11-29" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170523-0_InvoicePlane_Upload_arbitrary_files_stored_XSS_v10.txt" adv="1">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170523-0_InvoicePlane_Upload_arbitrary_files_stored_XSS_v10.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="invoiceplane" vendor="invoiceplane">
        <vers num="1.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000240" seq="2017-1000240" published="2017-11-16" modified="2017-11-30" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The application OpenEMR is affected by multiple reflected &amp; stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2017-001" adv="1">https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2017-001</ref>
    </refs>
    <vuln_soft>
      <prod name="openemr" vendor="open-emr">
        <vers num="5.0.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000241" seq="2017-1000241" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2017-004">https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2017-004</ref>
    </refs>
    <vuln_soft>
      <prod name="openemr" vendor="open-emr">
        <vers num="5.0.1" prev="1" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000242" seq="2017-1000242" published="2017-11-01" modified="2017-11-24" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101940">101940</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-04-27/" adv="1">https://jenkins.io/security/advisory/2017-04-27/</ref>
    </refs>
    <vuln_soft>
      <prod name="git_client" vendor="jenkins">
        <vers num="2.4.2" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000243" seq="2017-1000243" published="2017-11-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101946">101946</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-06-06/" adv="1">https://jenkins.io/security/advisory/2017-06-06/</ref>
    </refs>
    <vuln_soft>
      <prod name="favorite_plugin" vendor="jenkins">
        <vers num="2.1.4" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000244" seq="2017-1000244" published="2017-11-01" modified="2019-05-22" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101943" adv="1">101943</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-06-06/" adv="1">https://jenkins.io/security/advisory/2017-06-06/</ref>
    </refs>
    <vuln_soft>
      <prod name="favorite" vendor="jenkins">
        <vers num="2.2.0" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000245" seq="2017-1000245" published="2017-11-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-07-10/" adv="1">https://jenkins.io/security/advisory/2017-07-10/</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="jenkins">
        <vers num="2.4" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000246" seq="2017-1000246" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/rohe/pysaml2/issues/417" adv="1" patch="1">https://github.com/rohe/pysaml2/issues/417</ref>
    </refs>
    <vuln_soft>
      <prod name="pysaml2" vendor="pysaml2_project">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.3"/>
        <vers num="2.0.0"/>
        <vers num="2.1.0"/>
        <vers num="2.2.0"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.2"/>
        <vers num="4.0.0"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.3.0"/>
        <vers num="4.4.0"/>
        <vers num="4.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000247" seq="2017-1000247" published="2017-11-16" modified="2017-12-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.codeigniter.com/userguide3/changelog.html#version-3-1-4" adv="1">https://www.codeigniter.com/userguide3/changelog.html#version-3-1-4</ref>
    </refs>
    <vuln_soft>
      <prod name="codeigniter" vendor="codeigniter">
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000248" seq="2017-1000248" published="2017-11-16" modified="2017-12-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Redis-store &lt;=v1.3.0 allows unsafe objects to be loaded from redis</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/redis-store/redis-store/commit/e0c1398d54a9661c8c70267c3a925ba6b192142e" adv="1" patch="1">https://github.com/redis-store/redis-store/commit/e0c1398d54a9661c8c70267c3a925ba6b192142e</ref>
    </refs>
    <vuln_soft>
      <prod name="redis-store" vendor="redis-store">
        <vers num="1.3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000249" seq="2017-1000249" published="2017-09-11" modified="2017-11-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3965">DSA-3965</ref>
      <ref source="CONFIRM" url="https://github.com/file/file/commit/35c94dc6acc418f1ad7f6241a6680e5327495793" adv="1" patch="1">https://github.com/file/file/commit/35c94dc6acc418f1ad7f6241a6680e5327495793</ref>
      <ref source="CONFIRM" url="https://github.com/file/file/commit/9611f31313a93aa036389c5f3b15eea53510d4d" adv="1" patch="1">https://github.com/file/file/commit/9611f31313a93aa036389c5f3b15eea53510d4d</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-02">GLSA-201710-02</ref>
    </refs>
    <vuln_soft>
      <prod name="file" vendor="file_project">
        <vers num="5.29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000250" seq="2017-1000250" published="2017-09-12" modified="2018-02-16" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3972">DSA-3972</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100814" adv="1">100814</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2685">RHSA-2017:2685</ref>
      <ref source="MISC" url="https://access.redhat.com/security/cve/CVE-2017-1000250" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000250</ref>
      <ref source="MISC" url="https://www.armis.com/blueborne" adv="1">https://www.armis.com/blueborne</ref>
      <ref source="CERT-VN" url="https://www.kb.cert.org/vuls/id/240311" adv="1">VU#240311</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne">https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne</ref>
    </refs>
    <vuln_soft>
      <prod name="bluez" vendor="bluez">
        <vers num="5.46" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000251" seq="2017-1000251" published="2017-09-12" modified="2018-02-16" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://nvidia.custhelp.com/app/answers/detail/a_id/4561" adv="1">http://nvidia.custhelp.com/app/answers/detail/a_id/4561</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981" adv="1">DSA-3981</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100809" adv="1" patch="1">100809</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039373" adv="1">1039373</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2679" adv="1">RHSA-2017:2679</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2680" adv="1">RHSA-2017:2680</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2681" adv="1">RHSA-2017:2681</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2682" adv="1">RHSA-2017:2682</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2683" adv="1">RHSA-2017:2683</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2704" adv="1">RHSA-2017:2704</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2705" adv="1">RHSA-2017:2705</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2706" adv="1">RHSA-2017:2706</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2707" adv="1">RHSA-2017:2707</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2731" adv="1">RHSA-2017:2731</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2732" adv="1">RHSA-2017:2732</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/vulnerabilities/blueborne" adv="1">https://access.redhat.com/security/vulnerabilities/blueborne</ref>
      <ref source="MISC" url="https://github.com/torvalds/linux/commit/f2fcfcd670257236ebf2088bbdf26f6a8ef459fe" adv="1">https://github.com/torvalds/linux/commit/f2fcfcd670257236ebf2088bbdf26f6a8ef459fe</ref>
      <ref source="MISC" url="https://www.armis.com/blueborne" adv="1">https://www.armis.com/blueborne</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42762/" adv="1">42762</ref>
      <ref source="CERT-VN" url="https://www.kb.cert.org/vuls/id/240311" adv="1">VU#240311</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne">https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.32" edition="rc1"/>
        <vers num="2.6.32" edition="rc3"/>
        <vers num="2.6.32" edition="rc4"/>
        <vers num="2.6.32" edition="rc5"/>
        <vers num="2.6.32" edition="rc6"/>
        <vers num="2.6.32" edition="rc7"/>
        <vers num="2.6.32" edition="rc8"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.19"/>
        <vers num="2.6.32.20"/>
        <vers num="2.6.32.21"/>
        <vers num="2.6.32.22"/>
        <vers num="2.6.32.23"/>
        <vers num="2.6.32.24"/>
        <vers num="2.6.32.25"/>
        <vers num="2.6.32.26"/>
        <vers num="2.6.32.27"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.33" edition="rc1"/>
        <vers num="2.6.33" edition="rc2"/>
        <vers num="2.6.33" edition="rc3"/>
        <vers num="2.6.33" edition="rc4"/>
        <vers num="2.6.33" edition="rc5"/>
        <vers num="2.6.33" edition="rc6"/>
        <vers num="2.6.33" edition="rc7"/>
        <vers num="2.6.33" edition="rc8"/>
        <vers num="2.6.33.1"/>
        <vers num="2.6.33.2"/>
        <vers num="2.6.33.3"/>
        <vers num="2.6.33.4"/>
        <vers num="2.6.33.5"/>
        <vers num="2.6.33.6"/>
        <vers num="2.6.33.7"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.34" edition="rc1"/>
        <vers num="2.6.34" edition="rc2"/>
        <vers num="2.6.34" edition="rc3"/>
        <vers num="2.6.34" edition="rc4"/>
        <vers num="2.6.34" edition="rc5"/>
        <vers num="2.6.34" edition="rc6"/>
        <vers num="2.6.34" edition="rc7"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.4"/>
        <vers num="2.6.34.5"/>
        <vers num="2.6.34.6"/>
        <vers num="2.6.34.7"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.35" edition="rc1"/>
        <vers num="2.6.35" edition="rc2"/>
        <vers num="2.6.35" edition="rc3"/>
        <vers num="2.6.35" edition="rc4"/>
        <vers num="2.6.35" edition="rc5"/>
        <vers num="2.6.35" edition="rc6"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.2"/>
        <vers num="2.6.35.3"/>
        <vers num="2.6.35.4"/>
        <vers num="2.6.35.5"/>
        <vers num="2.6.35.6"/>
        <vers num="2.6.35.7"/>
        <vers num="2.6.35.8"/>
        <vers num="2.6.35.9"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.36" edition="rc1"/>
        <vers num="2.6.36" edition="rc2"/>
        <vers num="2.6.36" edition="rc3"/>
        <vers num="2.6.36" edition="rc4"/>
        <vers num="2.6.36" edition="rc5"/>
        <vers num="2.6.36" edition="rc6"/>
        <vers num="2.6.36" edition="rc7"/>
        <vers num="2.6.36" edition="rc8"/>
        <vers num="2.6.36.1"/>
        <vers num="2.6.36.2"/>
        <vers num="2.6.36.3"/>
        <vers num="2.6.36.4"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.37" edition="rc6"/>
        <vers num="2.6.37" edition="rc7"/>
        <vers num="2.6.37" edition="rc8"/>
        <vers num="2.6.37.1"/>
        <vers num="2.6.37.2"/>
        <vers num="2.6.37.3"/>
        <vers num="2.6.37.4"/>
        <vers num="2.6.37.5"/>
        <vers num="2.6.37.6"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.38.1"/>
        <vers num="2.6.38.2"/>
        <vers num="2.6.38.3"/>
        <vers num="2.6.38.4"/>
        <vers num="2.6.38.5"/>
        <vers num="2.6.38.6"/>
        <vers num="2.6.38.7"/>
        <vers num="2.6.38.8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.39.1"/>
        <vers num="2.6.39.2"/>
        <vers num="2.6.39.3"/>
        <vers num="2.6.39.4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.69"/>
        <vers num="3.0.70"/>
        <vers num="3.0.71"/>
        <vers num="3.0.72"/>
        <vers num="3.0.73"/>
        <vers num="3.0.74"/>
        <vers num="3.0.75"/>
        <vers num="3.0.76"/>
        <vers num="3.0.77"/>
        <vers num="3.0.78"/>
        <vers num="3.0.79"/>
        <vers num="3.0.80"/>
        <vers num="3.0.81"/>
        <vers num="3.0.82"/>
        <vers num="3.0.83"/>
        <vers num="3.0.84"/>
        <vers num="3.0.85"/>
        <vers num="3.0.86"/>
        <vers num="3.0.87"/>
        <vers num="3.0.88"/>
        <vers num="3.0.89"/>
        <vers num="3.0.90"/>
        <vers num="3.0.91"/>
        <vers num="3.0.92"/>
        <vers num="3.0.93"/>
        <vers num="3.0.94"/>
        <vers num="3.0.95"/>
        <vers num="3.0.96"/>
        <vers num="3.0.97"/>
        <vers num="3.0.98"/>
        <vers num="3.0.99"/>
        <vers num="3.0.100"/>
        <vers num="3.0.101"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.1.10"/>
        <vers num="3.2" edition=":~~~~x86~"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.30"/>
        <vers num="3.2.64"/>
        <vers num="3.2.65"/>
        <vers num="3.2.66"/>
        <vers num="3.2.67"/>
        <vers num="3.2.68"/>
        <vers num="3.2.69"/>
        <vers num="3.2.70"/>
        <vers num="3.2.71"/>
        <vers num="3.2.72"/>
        <vers num="3.2.73"/>
        <vers num="3.2.74"/>
        <vers num="3.2.75"/>
        <vers num="3.2.76"/>
        <vers num="3.2.77"/>
        <vers num="3.2.78"/>
        <vers num="3.2.79"/>
        <vers num="3.2.80"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.33"/>
        <vers num="3.4.34"/>
        <vers num="3.4.35"/>
        <vers num="3.4.36"/>
        <vers num="3.4.37"/>
        <vers num="3.4.38"/>
        <vers num="3.4.39"/>
        <vers num="3.4.40"/>
        <vers num="3.4.41"/>
        <vers num="3.4.42"/>
        <vers num="3.4.43"/>
        <vers num="3.4.44"/>
        <vers num="3.4.45"/>
        <vers num="3.4.46"/>
        <vers num="3.4.47"/>
        <vers num="3.4.48"/>
        <vers num="3.4.49"/>
        <vers num="3.4.50"/>
        <vers num="3.4.51"/>
        <vers num="3.4.52"/>
        <vers num="3.4.53"/>
        <vers num="3.4.54"/>
        <vers num="3.4.55"/>
        <vers num="3.4.56"/>
        <vers num="3.4.57"/>
        <vers num="3.4.58"/>
        <vers num="3.4.59"/>
        <vers num="3.4.60"/>
        <vers num="3.4.61"/>
        <vers num="3.4.62"/>
        <vers num="3.4.63"/>
        <vers num="3.4.64"/>
        <vers num="3.4.65"/>
        <vers num="3.4.66"/>
        <vers num="3.4.67"/>
        <vers num="3.4.68"/>
        <vers num="3.4.69"/>
        <vers num="3.4.70"/>
        <vers num="3.4.71"/>
        <vers num="3.4.72"/>
        <vers num="3.4.73"/>
        <vers num="3.4.74"/>
        <vers num="3.4.75"/>
        <vers num="3.4.76"/>
        <vers num="3.4.77"/>
        <vers num="3.4.78"/>
        <vers num="3.4.79"/>
        <vers num="3.4.80"/>
        <vers num="3.4.81"/>
        <vers num="3.4.82"/>
        <vers num="3.4.83"/>
        <vers num="3.4.84"/>
        <vers num="3.4.85"/>
        <vers num="3.4.86"/>
        <vers num="3.4.87"/>
        <vers num="3.4.88"/>
        <vers num="3.4.89"/>
        <vers num="3.4.90"/>
        <vers num="3.4.91"/>
        <vers num="3.4.92"/>
        <vers num="3.4.93"/>
        <vers num="3.4.94"/>
        <vers num="3.4.95"/>
        <vers num="3.4.96"/>
        <vers num="3.4.97"/>
        <vers num="3.4.98"/>
        <vers num="3.4.99"/>
        <vers num="3.4.100"/>
        <vers num="3.4.101"/>
        <vers num="3.4.102"/>
        <vers num="3.4.103"/>
        <vers num="3.4.104"/>
        <vers num="3.4.105"/>
        <vers num="3.4.106"/>
        <vers num="3.4.107"/>
        <vers num="3.4.108"/>
        <vers num="3.4.109"/>
        <vers num="3.4.110"/>
        <vers num="3.4.111"/>
        <vers num="3.4.112"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6" edition="rc5"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9" edition="rc3"/>
        <vers num="3.9" edition="rc4"/>
        <vers num="3.9" edition="rc5"/>
        <vers num="3.9" edition="rc6"/>
        <vers num="3.9" edition="rc7"/>
        <vers num="3.9.0"/>
        <vers num="3.9.1"/>
        <vers num="3.9.2"/>
        <vers num="3.9.3"/>
        <vers num="3.9.4"/>
        <vers num="3.9.5"/>
        <vers num="3.9.6"/>
        <vers num="3.9.7"/>
        <vers num="3.9.8"/>
        <vers num="3.9.9"/>
        <vers num="3.9.10"/>
        <vers num="3.9.11"/>
        <vers num="3.10"/>
        <vers num="3.10.1"/>
        <vers num="3.10.2"/>
        <vers num="3.10.3"/>
        <vers num="3.10.4"/>
        <vers num="3.10.5"/>
        <vers num="3.10.6"/>
        <vers num="3.10.7"/>
        <vers num="3.10.8"/>
        <vers num="3.10.9"/>
        <vers num="3.10.10"/>
        <vers num="3.10.11"/>
        <vers num="3.10.12"/>
        <vers num="3.10.13"/>
        <vers num="3.10.14"/>
        <vers num="3.10.15"/>
        <vers num="3.10.16"/>
        <vers num="3.10.17"/>
        <vers num="3.10.18"/>
        <vers num="3.10.19"/>
        <vers num="3.10.20"/>
        <vers num="3.10.21"/>
        <vers num="3.10.22"/>
        <vers num="3.10.23"/>
        <vers num="3.10.24"/>
        <vers num="3.10.25"/>
        <vers num="3.10.26"/>
        <vers num="3.10.27"/>
        <vers num="3.10.28"/>
        <vers num="3.10.29"/>
        <vers num="3.10.30"/>
        <vers num="3.10.31"/>
        <vers num="3.10.32"/>
        <vers num="3.10.33"/>
        <vers num="3.10.34"/>
        <vers num="3.10.35"/>
        <vers num="3.10.36"/>
        <vers num="3.10.37"/>
        <vers num="3.10.38"/>
        <vers num="3.10.39"/>
        <vers num="3.10.40"/>
        <vers num="3.10.41"/>
        <vers num="3.10.42"/>
        <vers num="3.10.43"/>
        <vers num="3.10.44"/>
        <vers num="3.10.45"/>
        <vers num="3.10.46"/>
        <vers num="3.10.47"/>
        <vers num="3.10.48"/>
        <vers num="3.10.49"/>
        <vers num="3.10.50"/>
        <vers num="3.10.51"/>
        <vers num="3.10.52"/>
        <vers num="3.10.53"/>
        <vers num="3.10.54"/>
        <vers num="3.10.55"/>
        <vers num="3.10.56"/>
        <vers num="3.10.57"/>
        <vers num="3.10.58"/>
        <vers num="3.10.59"/>
        <vers num="3.10.60"/>
        <vers num="3.10.61"/>
        <vers num="3.10.62"/>
        <vers num="3.10.63"/>
        <vers num="3.10.64"/>
        <vers num="3.10.65"/>
        <vers num="3.10.66"/>
        <vers num="3.10.67"/>
        <vers num="3.10.68"/>
        <vers num="3.10.69"/>
        <vers num="3.10.70"/>
        <vers num="3.10.71"/>
        <vers num="3.10.72"/>
        <vers num="3.10.73"/>
        <vers num="3.10.74"/>
        <vers num="3.10.75"/>
        <vers num="3.10.76"/>
        <vers num="3.10.77"/>
        <vers num="3.10.78"/>
        <vers num="3.10.79"/>
        <vers num="3.10.80"/>
        <vers num="3.10.81"/>
        <vers num="3.10.82"/>
        <vers num="3.10.83"/>
        <vers num="3.10.84"/>
        <vers num="3.10.85"/>
        <vers num="3.10.86"/>
        <vers num="3.10.87"/>
        <vers num="3.10.88"/>
        <vers num="3.10.89"/>
        <vers num="3.10.90"/>
        <vers num="3.10.91"/>
        <vers num="3.10.92"/>
        <vers num="3.10.93"/>
        <vers num="3.10.94"/>
        <vers num="3.10.95"/>
        <vers num="3.10.96"/>
        <vers num="3.10.97"/>
        <vers num="3.10.98"/>
        <vers num="3.10.99"/>
        <vers num="3.10.100"/>
        <vers num="3.10.101"/>
        <vers num="3.10.102"/>
        <vers num="3.11"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.8"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.8"/>
        <vers num="3.12.9"/>
        <vers num="3.12.10"/>
        <vers num="3.12.11"/>
        <vers num="3.12.12"/>
        <vers num="3.12.13"/>
        <vers num="3.12.14"/>
        <vers num="3.12.15"/>
        <vers num="3.12.16"/>
        <vers num="3.12.17"/>
        <vers num="3.12.18"/>
        <vers num="3.12.19"/>
        <vers num="3.12.20"/>
        <vers num="3.12.21"/>
        <vers num="3.12.22"/>
        <vers num="3.12.23"/>
        <vers num="3.12.24"/>
        <vers num="3.12.25"/>
        <vers num="3.12.26"/>
        <vers num="3.12.27"/>
        <vers num="3.12.28"/>
        <vers num="3.12.29"/>
        <vers num="3.12.30"/>
        <vers num="3.12.31"/>
        <vers num="3.12.32"/>
        <vers num="3.12.33"/>
        <vers num="3.12.34"/>
        <vers num="3.12.35"/>
        <vers num="3.12.36"/>
        <vers num="3.12.37"/>
        <vers num="3.12.38"/>
        <vers num="3.12.39"/>
        <vers num="3.12.40"/>
        <vers num="3.12.41"/>
        <vers num="3.12.42"/>
        <vers num="3.12.43"/>
        <vers num="3.12.44"/>
        <vers num="3.12.45"/>
        <vers num="3.12.46"/>
        <vers num="3.12.47"/>
        <vers num="3.12.48"/>
        <vers num="3.12.49"/>
        <vers num="3.12.50"/>
        <vers num="3.12.51"/>
        <vers num="3.12.52"/>
        <vers num="3.12.53"/>
        <vers num="3.12.54"/>
        <vers num="3.12.55"/>
        <vers num="3.12.56"/>
        <vers num="3.12.57"/>
        <vers num="3.12.58"/>
        <vers num="3.12.59"/>
        <vers num="3.13"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.4"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.8"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.13.11"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="rc1"/>
        <vers num="3.14" edition="rc2"/>
        <vers num="3.14" edition="rc3"/>
        <vers num="3.14" edition="rc4"/>
        <vers num="3.14" edition="rc5"/>
        <vers num="3.14" edition="rc6"/>
        <vers num="3.14" edition="rc7"/>
        <vers num="3.14" edition="rc8"/>
        <vers num="3.14.1"/>
        <vers num="3.14.2"/>
        <vers num="3.14.3"/>
        <vers num="3.14.4"/>
        <vers num="3.14.5"/>
        <vers num="3.14.10"/>
        <vers num="3.14.11"/>
        <vers num="3.14.12"/>
        <vers num="3.14.13"/>
        <vers num="3.14.14"/>
        <vers num="3.14.15"/>
        <vers num="3.14.16"/>
        <vers num="3.14.17"/>
        <vers num="3.14.18"/>
        <vers num="3.14.19"/>
        <vers num="3.14.20"/>
        <vers num="3.14.21"/>
        <vers num="3.14.22"/>
        <vers num="3.14.23"/>
        <vers num="3.14.24"/>
        <vers num="3.14.25"/>
        <vers num="3.14.26"/>
        <vers num="3.14.27"/>
        <vers num="3.14.28"/>
        <vers num="3.14.29"/>
        <vers num="3.14.30"/>
        <vers num="3.14.31"/>
        <vers num="3.14.32"/>
        <vers num="3.14.33"/>
        <vers num="3.14.34"/>
        <vers num="3.14.35"/>
        <vers num="3.14.36"/>
        <vers num="3.14.37"/>
        <vers num="3.14.38"/>
        <vers num="3.14.39"/>
        <vers num="3.14.40"/>
        <vers num="3.14.41"/>
        <vers num="3.14.42"/>
        <vers num="3.14.43"/>
        <vers num="3.14.44"/>
        <vers num="3.14.45"/>
        <vers num="3.14.46"/>
        <vers num="3.14.47"/>
        <vers num="3.14.48"/>
        <vers num="3.14.49"/>
        <vers num="3.14.50"/>
        <vers num="3.14.51"/>
        <vers num="3.14.52"/>
        <vers num="3.14.53"/>
        <vers num="3.14.54"/>
        <vers num="3.14.55"/>
        <vers num="3.14.56"/>
        <vers num="3.14.57"/>
        <vers num="3.14.58"/>
        <vers num="3.14.59"/>
        <vers num="3.14.60"/>
        <vers num="3.14.61"/>
        <vers num="3.14.62"/>
        <vers num="3.14.63"/>
        <vers num="3.14.64"/>
        <vers num="3.14.65"/>
        <vers num="3.14.66"/>
        <vers num="3.14.67"/>
        <vers num="3.14.68"/>
        <vers num="3.14.79"/>
        <vers num="3.15" edition="rc4"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
        <vers num="3.15.4"/>
        <vers num="3.15.5"/>
        <vers num="3.15.6"/>
        <vers num="3.15.7"/>
        <vers num="3.15.8"/>
        <vers num="3.15.10"/>
        <vers num="3.16.0"/>
        <vers num="3.16.1"/>
        <vers num="3.16.4"/>
        <vers num="3.16.5"/>
        <vers num="3.16.6"/>
        <vers num="3.16.7"/>
        <vers num="3.17.5"/>
        <vers num="3.17.6"/>
        <vers num="3.17.7"/>
        <vers num="3.17.8"/>
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.10"/>
        <vers num="3.18.11"/>
        <vers num="3.18.12"/>
        <vers num="3.18.13"/>
        <vers num="3.18.14"/>
        <vers num="3.18.15"/>
        <vers num="3.18.16"/>
        <vers num="3.18.17"/>
        <vers num="3.18.18"/>
        <vers num="3.18.19"/>
        <vers num="3.18.20"/>
        <vers num="3.18.21"/>
        <vers num="3.18.22"/>
        <vers num="3.18.23"/>
        <vers num="3.18.24"/>
        <vers num="3.18.25"/>
        <vers num="3.18.26"/>
        <vers num="3.18.27"/>
        <vers num="3.18.28"/>
        <vers num="3.18.29"/>
        <vers num="3.18.30"/>
        <vers num="3.18.31"/>
        <vers num="3.18.32"/>
        <vers num="3.18.33"/>
        <vers num="3.18.34"/>
        <vers num="3.18.35"/>
        <vers num="3.18.36"/>
        <vers num="3.18.37"/>
        <vers num="3.18.38"/>
        <vers num="3.18.39"/>
        <vers num="3.18.40"/>
        <vers num="3.18.41"/>
        <vers num="3.18.42"/>
        <vers num="3.18.43"/>
        <vers num="3.18.44"/>
        <vers num="3.18.45"/>
        <vers num="3.18.46"/>
        <vers num="3.18.47"/>
        <vers num="3.18.48"/>
        <vers num="3.18.49"/>
        <vers num="3.18.50"/>
        <vers num="3.18.51"/>
        <vers num="3.18.52"/>
        <vers num="3.18.53"/>
        <vers num="3.18.54"/>
        <vers num="3.18.55"/>
        <vers num="3.18.56"/>
        <vers num="3.18.57"/>
        <vers num="3.18.58"/>
        <vers num="3.18.59"/>
        <vers num="3.18.60"/>
        <vers num="3.18.61"/>
        <vers num="3.18.62"/>
        <vers num="3.18.63"/>
        <vers num="3.18.64"/>
        <vers num="3.18.65"/>
        <vers num="3.18.66"/>
        <vers num="3.19"/>
        <vers num="3.19.1"/>
        <vers num="3.19.2"/>
        <vers num="3.19.3"/>
        <vers num="3.19.4"/>
        <vers num="3.19.5"/>
        <vers num="3.19.6"/>
        <vers num="3.19.7"/>
        <vers num="3.19.8"/>
        <vers num="4.0"/>
        <vers num="4.0.0"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1.0"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.33"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.3" edition="rc7"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4" edition="rc8"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.4.19"/>
        <vers num="4.4.20"/>
        <vers num="4.4.21"/>
        <vers num="4.4.22"/>
        <vers num="4.4.23"/>
        <vers num="4.4.24"/>
        <vers num="4.4.25"/>
        <vers num="4.4.26"/>
        <vers num="4.4.27"/>
        <vers num="4.4.28"/>
        <vers num="4.4.29"/>
        <vers num="4.4.30"/>
        <vers num="4.4.31"/>
        <vers num="4.4.32"/>
        <vers num="4.4.33"/>
        <vers num="4.4.34"/>
        <vers num="4.4.35"/>
        <vers num="4.4.36"/>
        <vers num="4.4.37"/>
        <vers num="4.4.38"/>
        <vers num="4.4.39"/>
        <vers num="4.4.40"/>
        <vers num="4.4.41"/>
        <vers num="4.4.42"/>
        <vers num="4.4.43"/>
        <vers num="4.4.44"/>
        <vers num="4.4.45"/>
        <vers num="4.4.46"/>
        <vers num="4.4.47"/>
        <vers num="4.4.48"/>
        <vers num="4.4.49"/>
        <vers num="4.4.50"/>
        <vers num="4.4.51"/>
        <vers num="4.4.52"/>
        <vers num="4.4.53"/>
        <vers num="4.4.54"/>
        <vers num="4.4.55"/>
        <vers num="4.4.56"/>
        <vers num="4.4.57"/>
        <vers num="4.4.58"/>
        <vers num="4.4.59"/>
        <vers num="4.4.60"/>
        <vers num="4.4.61"/>
        <vers num="4.4.62"/>
        <vers num="4.4.63"/>
        <vers num="4.4.64"/>
        <vers num="4.4.65"/>
        <vers num="4.4.66"/>
        <vers num="4.4.67"/>
        <vers num="4.4.68"/>
        <vers num="4.4.69"/>
        <vers num="4.4.70"/>
        <vers num="4.4.71"/>
        <vers num="4.4.72"/>
        <vers num="4.4.73"/>
        <vers num="4.4.74"/>
        <vers num="4.4.75"/>
        <vers num="4.4.76"/>
        <vers num="4.4.77"/>
        <vers num="4.4.78"/>
        <vers num="4.4.79"/>
        <vers num="4.4.80"/>
        <vers num="4.4.81"/>
        <vers num="4.4.82"/>
        <vers num="4.4.83"/>
        <vers num="4.5.0" edition="rc7"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.7"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.7" edition="rc6"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.6"/>
        <vers num="4.7.9"/>
        <vers num="4.8"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="4.8.10"/>
        <vers num="4.8.11"/>
        <vers num="4.8.12"/>
        <vers num="4.8.13"/>
        <vers num="4.8.14"/>
        <vers num="4.8.15"/>
        <vers num="4.8.16"/>
        <vers num="4.8.17"/>
        <vers num="4.9"/>
        <vers num="4.9.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
        <vers num="4.9.13"/>
        <vers num="4.9.14"/>
        <vers num="4.9.15"/>
        <vers num="4.9.16"/>
        <vers num="4.9.17"/>
        <vers num="4.9.18"/>
        <vers num="4.9.19"/>
        <vers num="4.9.20"/>
        <vers num="4.9.21"/>
        <vers num="4.9.22"/>
        <vers num="4.9.23"/>
        <vers num="4.9.24"/>
        <vers num="4.9.25"/>
        <vers num="4.9.26"/>
        <vers num="4.9.27"/>
        <vers num="4.9.28"/>
        <vers num="4.9.29"/>
        <vers num="4.9.30"/>
        <vers num="4.9.31"/>
        <vers num="4.9.32"/>
        <vers num="4.9.33"/>
        <vers num="4.9.34"/>
        <vers num="4.9.35"/>
        <vers num="4.9.36"/>
        <vers num="4.9.37"/>
        <vers num="4.9.38"/>
        <vers num="4.9.39"/>
        <vers num="4.9.40"/>
        <vers num="4.9.41"/>
        <vers num="4.9.42"/>
        <vers num="4.9.43"/>
        <vers num="4.9.44"/>
        <vers num="4.10"/>
        <vers num="4.10.1"/>
        <vers num="4.10.2"/>
        <vers num="4.10.3"/>
        <vers num="4.10.4"/>
        <vers num="4.10.5"/>
        <vers num="4.10.6"/>
        <vers num="4.10.7"/>
        <vers num="4.10.8"/>
        <vers num="4.10.9"/>
        <vers num="4.10.10"/>
        <vers num="4.10.11"/>
        <vers num="4.10.12"/>
        <vers num="4.10.13"/>
        <vers num="4.10.14"/>
        <vers num="4.10.15"/>
        <vers num="4.11" edition="rc1"/>
        <vers num="4.11" edition="rc2"/>
        <vers num="4.11" edition="rc3"/>
        <vers num="4.11" edition="rc4"/>
        <vers num="4.11" edition="rc5"/>
        <vers num="4.11" edition="rc6"/>
        <vers num="4.11" edition="rc7"/>
        <vers num="4.11.1"/>
        <vers num="4.11.2"/>
        <vers num="4.11.3"/>
        <vers num="4.11.4"/>
        <vers num="4.11.5"/>
        <vers num="4.11.6"/>
        <vers num="4.11.7"/>
        <vers num="4.11.8"/>
        <vers num="4.11.9"/>
        <vers num="4.11.10"/>
        <vers num="4.11.11"/>
        <vers num="4.11.12"/>
        <vers num="4.12"/>
        <vers num="4.12.1"/>
        <vers num="4.12.2"/>
        <vers num="4.12.3"/>
        <vers num="4.12.4"/>
        <vers num="4.12.5"/>
        <vers num="4.12.6"/>
        <vers num="4.12.7"/>
        <vers num="4.12.8"/>
        <vers num="4.12.9"/>
        <vers num="4.12.10"/>
        <vers num="4.12.11"/>
        <vers num="4.12.12"/>
        <vers num="4.12.13"/>
        <vers num="4.12.14"/>
        <vers num="4.13"/>
        <vers num="4.13.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000252" seq="2017-1000252" published="2017-09-26" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=36ae3c0a36b7456432fedce38ae2f7bd3e01a563" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=36ae3c0a36b7456432fedce38ae2f7bd3e01a563</ref>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3a8b0677fc6180a467e26cc32ce6b0c09a32f9bb" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3a8b0677fc6180a467e26cc32ce6b0c09a32f9bb</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="CONFIRM" url="http://www.openwall.com/lists/oss-security/2017/09/15/4" adv="1" patch="1">http://www.openwall.com/lists/oss-security/2017/09/15/4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101022">101022</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0676">RHSA-2018:0676</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1062">RHSA-2018:1062</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1130">RHSA-2018:1130</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1490781" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1490781</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/36ae3c0a36b7456432fedce38ae2f7bd3e01a563" adv="1" patch="1">https://github.com/torvalds/linux/commit/36ae3c0a36b7456432fedce38ae2f7bd3e01a563</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/3a8b0677fc6180a467e26cc32ce6b0c09a32f9bb" adv="1" patch="1">https://github.com/torvalds/linux/commit/3a8b0677fc6180a467e26cc32ce6b0c09a32f9bb</ref>
      <ref source="CONFIRM" url="https://marc.info/?l=kvm&amp;m=150549145711115&amp;w=2" adv="1" patch="1">https://marc.info/?l=kvm&amp;m=150549145711115&amp;w=2</ref>
      <ref source="CONFIRM" url="https://marc.info/?l=kvm&amp;m=150549146311117&amp;w=2" adv="1" patch="1">https://marc.info/?l=kvm&amp;m=150549146311117&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.13.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000253" seq="2017-1000253" published="2017-10-04" modified="2017-12-08" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101010" adv="1">101010</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039434" adv="1">1039434</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2793">RHSA-2017:2793</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2794">RHSA-2017:2794</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2795">RHSA-2017:2795</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2796">RHSA-2017:2796</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2797">RHSA-2017:2797</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2798">RHSA-2017:2798</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2799">RHSA-2017:2799</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2800">RHSA-2017:2800</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2801">RHSA-2017:2801</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2802">RHSA-2017:2802</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt" adv="1" patch="1">https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="centos" vendor="centos">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.8"/>
        <vers num="6.9"/>
        <vers num="7.1406"/>
        <vers num="7.1503"/>
        <vers num="7.1511"/>
        <vers num="7.1611"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.8"/>
        <vers num="6.9"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000254" seq="2017-1000254" published="2017-10-06" modified="2018-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory with the `PWD` command. The server then responds with a 257 response containing the path, inside double quotes. The returned path name is then kept by libcurl for subsequent uses. Due to a flaw in the string parser for this directory name, a directory name passed like this but without a closing double quote would lead to libcurl not adding a trailing NUL byte to the buffer holding the name. When libcurl would then later access the string, it could read beyond the allocated heap buffer and crash or wrongly access data beyond the buffer, thinking it was part of the path. A malicious server could abuse this fact and effectively prevent libcurl-based clients to work with it - the PWD command is always issued on new FTP connections and the mistake has a high chance of causing a segfault. The simple fact that this has issue remained undiscovered for this long could suggest that malformed PWD responses are rare in benign servers. We are not aware of any exploit of this flaw. This bug was introduced in commit [415d2e7cb7](https://github.com/curl/curl/commit/415d2e7cb7), March 2005. In libcurl version 7.56.0, the parser always zero terminates the string but also rejects it if not terminated properly with a final double quote.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3992">DSA-3992</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101115" adv="1">101115</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039509" adv="1">1039509</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2486">RHSA-2018:2486</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3558">RHSA-2018:3558</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/673d0cd8.patch" adv="1" patch="1">https://curl.haxx.se/673d0cd8.patch</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/docs/adv_20171004.html" adv="1" patch="1">https://curl.haxx.se/docs/adv_20171004.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201712-04">GLSA-201712-04</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208331">https://support.apple.com/HT208331</ref>
    </refs>
    <vuln_soft>
      <prod name="libcurl" vendor="haxx">
        <vers num="7.7"/>
        <vers num="7.7.1"/>
        <vers num="7.7.2"/>
        <vers num="7.7.3"/>
        <vers num="7.8"/>
        <vers num="7.8.1"/>
        <vers num="7.9"/>
        <vers num="7.9.1"/>
        <vers num="7.9.2"/>
        <vers num="7.9.3"/>
        <vers num="7.9.4"/>
        <vers num="7.9.5"/>
        <vers num="7.9.6"/>
        <vers num="7.9.7"/>
        <vers num="7.9.8"/>
        <vers num="7.10"/>
        <vers num="7.10.1"/>
        <vers num="7.10.2"/>
        <vers num="7.10.3"/>
        <vers num="7.10.4"/>
        <vers num="7.10.5"/>
        <vers num="7.10.6"/>
        <vers num="7.10.7"/>
        <vers num="7.10.8"/>
        <vers num="7.11.0"/>
        <vers num="7.11.1"/>
        <vers num="7.11.2"/>
        <vers num="7.12.0"/>
        <vers num="7.12.1"/>
        <vers num="7.12.2"/>
        <vers num="7.12.3"/>
        <vers num="7.13.0"/>
        <vers num="7.13.1"/>
        <vers num="7.13.2"/>
        <vers num="7.14.0"/>
        <vers num="7.14.1"/>
        <vers num="7.15.0"/>
        <vers num="7.15.1"/>
        <vers num="7.15.2"/>
        <vers num="7.15.3"/>
        <vers num="7.15.4"/>
        <vers num="7.15.5"/>
        <vers num="7.16.0"/>
        <vers num="7.16.1"/>
        <vers num="7.16.2"/>
        <vers num="7.16.3"/>
        <vers num="7.16.4"/>
        <vers num="7.17.0"/>
        <vers num="7.17.1"/>
        <vers num="7.18.0"/>
        <vers num="7.18.1"/>
        <vers num="7.18.2"/>
        <vers num="7.19.0"/>
        <vers num="7.19.1"/>
        <vers num="7.19.2"/>
        <vers num="7.19.3"/>
        <vers num="7.19.4"/>
        <vers num="7.19.5"/>
        <vers num="7.19.6"/>
        <vers num="7.19.7"/>
        <vers num="7.20.0"/>
        <vers num="7.20.1"/>
        <vers num="7.21.0"/>
        <vers num="7.21.1"/>
        <vers num="7.21.2"/>
        <vers num="7.21.3"/>
        <vers num="7.21.4"/>
        <vers num="7.21.5"/>
        <vers num="7.21.6"/>
        <vers num="7.21.7"/>
        <vers num="7.22.0"/>
        <vers num="7.23.0"/>
        <vers num="7.23.1"/>
        <vers num="7.24.0"/>
        <vers num="7.25.0"/>
        <vers num="7.26.0"/>
        <vers num="7.27.0"/>
        <vers num="7.28.0"/>
        <vers num="7.28.1"/>
        <vers num="7.29.0"/>
        <vers num="7.30.0"/>
        <vers num="7.31.0"/>
        <vers num="7.32.0"/>
        <vers num="7.33.0"/>
        <vers num="7.34.0"/>
        <vers num="7.35.0"/>
        <vers num="7.36.0"/>
        <vers num="7.37.0"/>
        <vers num="7.37.1"/>
        <vers num="7.38.0"/>
        <vers num="7.39"/>
        <vers num="7.40.0"/>
        <vers num="7.41.0"/>
        <vers num="7.42.0"/>
        <vers num="7.42.1"/>
        <vers num="7.43.0"/>
        <vers num="7.44.0"/>
        <vers num="7.45.0"/>
        <vers num="7.46.0"/>
        <vers num="7.47.0"/>
        <vers num="7.47.1"/>
        <vers num="7.48.0"/>
        <vers num="7.49.0"/>
        <vers num="7.49.1"/>
        <vers num="7.50.0"/>
        <vers num="7.50.1"/>
        <vers num="7.50.2"/>
        <vers num="7.50.3"/>
        <vers num="7.51.0"/>
        <vers num="7.52.0"/>
        <vers num="7.52.1"/>
        <vers num="7.53.0"/>
        <vers num="7.53.1"/>
        <vers num="7.54.0"/>
        <vers num="7.54.1"/>
        <vers num="7.55.0"/>
        <vers num="7.55.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000255" seq="2017-1000255" published="2017-10-30" modified="2018-04-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.6" CVSS_base_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)">
    <desc>
      <descript source="cve">On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn so that the kernel will take an exception (interrupt), and use the r1 value *from the signal frame* as the kernel stack pointer. As part of the exception entry the content of the signal frame is written to the kernel stack, allowing an attacker to overwrite arbitrary locations with arbitrary values. The exception handling does produce an oops, and a panic if panic_on_oops=1, but only after kernel memory has been over written. This flaw was introduced in commit: "5d176f751ee3 (powerpc: tm: Enable transactional memory (TM) lazily for userspace)" which was merged upstream into v4.9-rc1. Please note that kernels built with CONFIG_PPC_TRANSACTIONAL_MEM=n are not vulnerable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101264" adv="1">101264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0654">RHSA-2018:0654</ref>
      <ref source="MISC" url="https://access.redhat.com/security/cve/CVE-2017-1000255" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000255</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000256" seq="2017-1000256" published="2017-10-31" modified="2019-09-26" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4003" adv="1">DSA-4003</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000256" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000256</ref>
      <ref source="MISC" url="https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1556251.html" adv="1">https://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg1556251.html</ref>
      <ref source="MLIST" url="https://www.redhat.com/archives/libvirt-announce/2017-October/msg00001.html" adv="1">[libvirt-announce] 20171016 LSN-2017-0002 - TLS certificate verification disabled for clients</ref>
    </refs>
    <vuln_soft>
      <prod name="libvirt" vendor="redhat">
        <vers num="2.3.0" edition="-"/>
        <vers num="2.3.0" edition="rc1"/>
        <vers num="2.3.0" edition="rc2"/>
        <vers num="2.4.0" edition="-"/>
        <vers num="2.4.0" edition="rc1"/>
        <vers num="2.4.0" edition="rc2"/>
        <vers num="2.5.0" edition="-"/>
        <vers num="2.5.0" edition="rc1"/>
        <vers num="2.5.0" edition="rc2"/>
        <vers num="3.0.0" edition="-"/>
        <vers num="3.0.0" edition="rc1"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.1.0" edition="-"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.2.0" edition="-"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers num="3.3.0" edition="-"/>
        <vers num="3.3.0" edition="rc1"/>
        <vers num="3.3.0" edition="rc2"/>
        <vers num="3.4.0" edition="-"/>
        <vers num="3.4.0" edition="rc1"/>
        <vers num="3.4.0" edition="rc2"/>
        <vers num="3.5.0" edition="-"/>
        <vers num="3.5.0" edition="rc1"/>
        <vers num="3.5.0" edition="rc2"/>
        <vers num="3.6.0" edition="-"/>
        <vers num="3.6.0" edition="rc1"/>
        <vers num="3.6.0" edition="rc2"/>
        <vers num="3.7.0" edition="-"/>
        <vers num="3.7.0" edition="rc1"/>
        <vers num="3.7.0" edition="rc2"/>
        <vers num="3.8.0" edition="-"/>
        <vers num="3.8.0" edition="rc1"/>
        <vers num="3.9.0" edition="-"/>
        <vers num="3.9.0" edition="rc1"/>
        <vers num="3.9.0" edition="rc2"/>
        <vers num="3.10.0" edition="-"/>
        <vers num="3.10.0" edition="rc1"/>
        <vers num="3.10.0" edition="rc2"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="rc1"/>
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.1.0" edition="-"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.0" edition="rc2"/>
        <vers num="4.2.0" edition="-"/>
        <vers num="4.2.0" edition="rc1"/>
        <vers num="4.2.0" edition="rc2"/>
        <vers num="4.3.0" edition="-"/>
        <vers num="4.3.0" edition="rc1"/>
        <vers num="4.3.0" edition="rc2"/>
        <vers num="4.4.0" edition="-"/>
        <vers num="4.4.0" edition="rc1"/>
        <vers num="4.4.0" edition="rc2"/>
        <vers num="4.5.0" edition="-"/>
        <vers num="4.5.0" edition="rc1"/>
        <vers num="4.5.0" edition="rc2"/>
        <vers num="4.6.0" edition="-"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.7.0" edition="-"/>
        <vers num="4.7.0" edition="rc1"/>
        <vers num="4.7.0" edition="rc2"/>
        <vers num="4.8.0" edition="rc1"/>
        <vers num="4.8.0" edition="rc2"/>
        <vers num="4.9.0" edition="-"/>
        <vers num="4.9.0" edition="rc1"/>
        <vers num="4.10.0" edition="-"/>
        <vers num="4.10.0" edition="rc1"/>
        <vers num="4.10.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.1.0" edition="-"/>
        <vers num="5.1.0" edition="rc1"/>
        <vers num="5.1.0" edition="rc2"/>
        <vers num="5.2.0" edition="-"/>
        <vers num="5.2.0" edition="rc1"/>
        <vers num="5.2.0" edition="rc2"/>
        <vers num="5.3.0" edition="-"/>
        <vers num="5.3.0" edition="rc1"/>
        <vers num="5.3.0" edition="rc2"/>
        <vers num="5.4.0" edition="-"/>
        <vers num="5.4.0" edition="rc1"/>
        <vers num="5.5.0" edition="-"/>
        <vers num="5.5.0" edition="rc1"/>
        <vers num="5.5.0" edition="rc2"/>
        <vers num="5.6.0"/>
        <vers num="5.7.0"/>
        <vers num="5.8.0"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000257" seq="2017-1000257" published="2017-10-31" modified="2018-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4007" adv="1">DSA-4007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101519" adv="1">101519</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039644" adv="1">1039644</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3263">RHSA-2017:3263</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2486">RHSA-2018:2486</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3558">RHSA-2018:3558</ref>
      <ref source="CONFIRM" url="https://curl.haxx.se/docs/adv_20171023.html" adv="1">https://curl.haxx.se/docs/adv_20171023.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201712-04">GLSA-201712-04</ref>
    </refs>
    <vuln_soft>
      <prod name="libcurl" vendor="haxx">
        <vers num="7.20.0"/>
        <vers num="7.20.1"/>
        <vers num="7.21.0"/>
        <vers num="7.21.1"/>
        <vers num="7.21.2"/>
        <vers num="7.21.3"/>
        <vers num="7.21.4"/>
        <vers num="7.21.5"/>
        <vers num="7.21.6"/>
        <vers num="7.21.7"/>
        <vers num="7.22.0"/>
        <vers num="7.23.0"/>
        <vers num="7.23.1"/>
        <vers num="7.24.0"/>
        <vers num="7.25.0"/>
        <vers num="7.26.0"/>
        <vers num="7.27.0"/>
        <vers num="7.28.0"/>
        <vers num="7.28.1"/>
        <vers num="7.29.0"/>
        <vers num="7.30.0"/>
        <vers num="7.31.0"/>
        <vers num="7.32.0"/>
        <vers num="7.33.0"/>
        <vers num="7.34.0"/>
        <vers num="7.35.0"/>
        <vers num="7.36.0"/>
        <vers num="7.37.0"/>
        <vers num="7.37.1"/>
        <vers num="7.38.0"/>
        <vers num="7.39"/>
        <vers num="7.39.0"/>
        <vers num="7.40.0"/>
        <vers num="7.41.0"/>
        <vers num="7.42"/>
        <vers num="7.42.0"/>
        <vers num="7.42.1"/>
        <vers num="7.43.0"/>
        <vers num="7.44.0"/>
        <vers num="7.45.0"/>
        <vers num="7.46.0"/>
        <vers num="7.47.0"/>
        <vers num="7.47.1"/>
        <vers num="7.48.0"/>
        <vers num="7.49.0"/>
        <vers num="7.49.1"/>
        <vers num="7.50.0"/>
        <vers num="7.50.1"/>
        <vers num="7.50.2"/>
        <vers num="7.50.3"/>
        <vers num="7.51.0"/>
        <vers num="7.52.0"/>
        <vers num="7.52.1"/>
        <vers num="7.53.0"/>
        <vers num="7.53.1"/>
        <vers num="7.54.0"/>
        <vers num="7.54.1"/>
        <vers num="7.55.0"/>
        <vers num="7.55.1"/>
        <vers num="7.56.0"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10003" seq="2017-10003" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network Services Library). The supported version that is affected is 10. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data as well as unauthorized read access to a subset of Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. CVSS 3.0 Base Score 4.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99848" adv="1">99848</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000353" seq="2017-1000353" published="2018-01-29" modified="2018-02-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98056" adv="1">98056</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-04-26/" adv="1">https://jenkins.io/security/advisory/2017-04-26/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41965/" adv="1">41965</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.46.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000354" seq="2017-1000354" published="2018-01-29" modified="2018-02-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. The `login` command available in the remoting-based CLI stored the encrypted user name of the successfully authenticated user in a cache file used to authenticate further commands. Users with sufficient permission to create secrets in Jenkins, and download their encrypted values (e.g. with Job/Configure permission), were able to impersonate any other Jenkins user on the same instance.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98065" adv="1">98065</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-04-26/" adv="1">https://jenkins.io/security/advisory/2017-04-26/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.46.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000355" seq="2017-1000355" published="2018-01-29" modified="2018-02-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98066" adv="1">98066</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-04-26/" adv="1">https://jenkins.io/security/advisory/2017-04-26/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.46.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000356" seq="2017-1000356" published="2018-01-29" modified="2018-02-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98062" adv="1">98062</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-04-26/" adv="1">https://jenkins.io/security/advisory/2017-04-26/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.46.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000357" seq="2017-1000357" published="2017-04-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 (Beryllium), 4.1 (Beryllium-SR1), 4.2 (Beryllium-SR2), and 4.4 (Beryllium-SR4) are affected by this flaw. Java version is openjdk version 1.8.0_91.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf" adv="1">https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000358" seq="2017-1000358" published="2017-04-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf" adv="1">https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000359" seq="2017-1000359" published="2017-04-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf" adv="1">https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000360" seq="2017-1000360" published="2017-04-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf" adv="1">https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000361" seq="2017-1000361" published="2017-04-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf" adv="1">https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000362" seq="2017-1000362" published="2017-07-17" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins now deletes the backup directory, if present. Upgrading from before 1.498 will no longer create a backup directory. Administrators relying on file access permissions in their manually created backups are advised to check them for the directory $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups, and delete it if present.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-02-01/" adv="1">https://jenkins.io/security/advisory/2017-02-01/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="1.498" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000363" seq="2017-1000363" published="2017-07-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array in the following code, by appending many (>LP_NO) 'lp=none' arguments to the command line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3945" adv="1">DSA-3945</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98651" adv="1">98651</ref>
      <ref source="MISC" url="https://alephsecurity.com/vulns/aleph-2017023" adv="1">https://alephsecurity.com/vulns/aleph-2017023</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="-"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.1.16"/>
        <vers num="2.1.17"/>
        <vers num="2.1.18"/>
        <vers num="2.1.19"/>
        <vers num="2.1.20"/>
        <vers num="2.1.21"/>
        <vers num="2.1.22"/>
        <vers num="2.1.23"/>
        <vers num="2.1.24"/>
        <vers num="2.1.25"/>
        <vers num="2.1.26"/>
        <vers num="2.1.27"/>
        <vers num="2.1.28"/>
        <vers num="2.1.29"/>
        <vers num="2.1.30"/>
        <vers num="2.1.31"/>
        <vers num="2.1.32"/>
        <vers num="2.1.33"/>
        <vers num="2.1.34"/>
        <vers num="2.1.35"/>
        <vers num="2.1.36"/>
        <vers num="2.1.37"/>
        <vers num="2.1.38"/>
        <vers num="2.1.39"/>
        <vers num="2.1.40"/>
        <vers num="2.1.41"/>
        <vers num="2.1.42"/>
        <vers num="2.1.43"/>
        <vers num="2.1.44"/>
        <vers num="2.1.45"/>
        <vers num="2.1.46"/>
        <vers num="2.1.47"/>
        <vers num="2.1.48"/>
        <vers num="2.1.49"/>
        <vers num="2.1.50"/>
        <vers num="2.1.51"/>
        <vers num="2.1.52"/>
        <vers num="2.1.53"/>
        <vers num="2.1.54"/>
        <vers num="2.1.55"/>
        <vers num="2.1.56"/>
        <vers num="2.1.57"/>
        <vers num="2.1.58"/>
        <vers num="2.1.59"/>
        <vers num="2.1.60"/>
        <vers num="2.1.61"/>
        <vers num="2.1.62"/>
        <vers num="2.1.63"/>
        <vers num="2.1.64"/>
        <vers num="2.1.65"/>
        <vers num="2.1.66"/>
        <vers num="2.1.67"/>
        <vers num="2.1.68"/>
        <vers num="2.1.69"/>
        <vers num="2.1.70"/>
        <vers num="2.1.71"/>
        <vers num="2.1.72"/>
        <vers num="2.1.73"/>
        <vers num="2.1.74"/>
        <vers num="2.1.75"/>
        <vers num="2.1.76"/>
        <vers num="2.1.77"/>
        <vers num="2.1.78"/>
        <vers num="2.1.79"/>
        <vers num="2.1.80"/>
        <vers num="2.1.81"/>
        <vers num="2.1.82"/>
        <vers num="2.1.83"/>
        <vers num="2.1.84"/>
        <vers num="2.1.85"/>
        <vers num="2.1.86"/>
        <vers num="2.1.87"/>
        <vers num="2.1.88"/>
        <vers num="2.1.89"/>
        <vers num="2.1.90"/>
        <vers num="2.1.91"/>
        <vers num="2.1.92"/>
        <vers num="2.1.93"/>
        <vers num="2.1.94"/>
        <vers num="2.1.95"/>
        <vers num="2.1.96"/>
        <vers num="2.1.97"/>
        <vers num="2.1.98"/>
        <vers num="2.1.99"/>
        <vers num="2.1.100"/>
        <vers num="2.1.101"/>
        <vers num="2.1.102"/>
        <vers num="2.1.103"/>
        <vers num="2.1.104"/>
        <vers num="2.1.105"/>
        <vers num="2.1.106"/>
        <vers num="2.1.107"/>
        <vers num="2.1.108"/>
        <vers num="2.1.109"/>
        <vers num="2.1.110"/>
        <vers num="2.1.111"/>
        <vers num="2.1.112"/>
        <vers num="2.1.113"/>
        <vers num="2.1.114"/>
        <vers num="2.1.115"/>
        <vers num="2.1.116"/>
        <vers num="2.1.117"/>
        <vers num="2.1.118"/>
        <vers num="2.1.119"/>
        <vers num="2.1.120"/>
        <vers num="2.1.121"/>
        <vers num="2.1.122"/>
        <vers num="2.1.123"/>
        <vers num="2.1.124"/>
        <vers num="2.1.125"/>
        <vers num="2.1.126"/>
        <vers num="2.1.127"/>
        <vers num="2.1.128"/>
        <vers num="2.1.129"/>
        <vers num="2.1.130"/>
        <vers num="2.1.131"/>
        <vers num="2.1.132"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21" edition="pre1"/>
        <vers num="2.2.21" edition="pre2"/>
        <vers num="2.2.21" edition="pre3"/>
        <vers num="2.2.21" edition="pre4"/>
        <vers num="2.2.21" edition="rc1"/>
        <vers num="2.2.21" edition="rc2"/>
        <vers num="2.2.21" edition="rc3"/>
        <vers num="2.2.21" edition="rc4"/>
        <vers num="2.2.22" edition="rc1"/>
        <vers num="2.2.22" edition="rc2"/>
        <vers num="2.2.22" edition="rc3"/>
        <vers num="2.2.23" edition="rc1"/>
        <vers num="2.2.23" edition="rc2"/>
        <vers num="2.2.24" edition="rc2"/>
        <vers num="2.2.24" edition="rc3"/>
        <vers num="2.2.24" edition="rc4"/>
        <vers num="2.2.24" edition="rc5"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.27" edition="pre1"/>
        <vers num="2.2.27" edition="pre2"/>
        <vers num="2.2.27" edition="rc1"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
        <vers num="2.3.30"/>
        <vers num="2.3.31"/>
        <vers num="2.3.32"/>
        <vers num="2.3.33"/>
        <vers num="2.3.34"/>
        <vers num="2.3.35"/>
        <vers num="2.3.36"/>
        <vers num="2.3.37"/>
        <vers num="2.3.38"/>
        <vers num="2.3.39"/>
        <vers num="2.3.40"/>
        <vers num="2.3.41"/>
        <vers num="2.3.42"/>
        <vers num="2.3.43"/>
        <vers num="2.3.44"/>
        <vers num="2.3.45"/>
        <vers num="2.3.46"/>
        <vers num="2.3.47"/>
        <vers num="2.3.48"/>
        <vers num="2.3.49"/>
        <vers num="2.3.50"/>
        <vers num="2.3.51"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.3.99" edition="pre8"/>
        <vers num="2.3.99" edition="pre9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11" edition="pre3"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.18" edition="pre9"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.32" edition="pre1"/>
        <vers num="2.4.32" edition="pre2"/>
        <vers num="2.4.33" edition="pre1"/>
        <vers num="2.4.33.1"/>
        <vers num="2.4.33.2"/>
        <vers num="2.4.33.3"/>
        <vers num="2.4.33.4"/>
        <vers num="2.4.33.5"/>
        <vers num="2.4.34" edition="rc3"/>
        <vers num="2.4.34.1"/>
        <vers num="2.4.34.2"/>
        <vers num="2.4.35"/>
        <vers num="2.4.35.2"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.75"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.1" edition="rc3"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.3" edition="rc4"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="final"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.15.8"/>
        <vers num="2.6.15.9"/>
        <vers num="2.6.15.10"/>
        <vers num="2.6.15.11"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16" edition="rc2"/>
        <vers num="2.6.16" edition="rc3"/>
        <vers num="2.6.16" edition="rc4"/>
        <vers num="2.6.16" edition="rc5"/>
        <vers num="2.6.16" edition="rc6"/>
        <vers num="2.6.16" edition="rc7"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19" edition="rc1"/>
        <vers num="2.6.19" edition="rc2"/>
        <vers num="2.6.19" edition="rc3"/>
        <vers num="2.6.19" edition="rc4"/>
        <vers num="2.6.19" edition="rc5"/>
        <vers num="2.6.19" edition="rc6"/>
        <vers num="2.6.19.0"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.20" edition="rc1"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20" edition="rc3"/>
        <vers num="2.6.20" edition="rc4"/>
        <vers num="2.6.20" edition="rc5"/>
        <vers num="2.6.20" edition="rc6"/>
        <vers num="2.6.20" edition="rc7"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21" edition="rc1"/>
        <vers num="2.6.21" edition="rc2"/>
        <vers num="2.6.21" edition="rc3"/>
        <vers num="2.6.21" edition="rc4"/>
        <vers num="2.6.21" edition="rc5"/>
        <vers num="2.6.21" edition="rc6"/>
        <vers num="2.6.21" edition="rc7"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22" edition="rc1"/>
        <vers num="2.6.22" edition="rc2"/>
        <vers num="2.6.22" edition="rc3"/>
        <vers num="2.6.22" edition="rc4"/>
        <vers num="2.6.22" edition="rc5"/>
        <vers num="2.6.22" edition="rc6"/>
        <vers num="2.6.22" edition="rc7"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23" edition="rc3"/>
        <vers num="2.6.23" edition="rc4"/>
        <vers num="2.6.23" edition="rc5"/>
        <vers num="2.6.23" edition="rc6"/>
        <vers num="2.6.23" edition="rc7"/>
        <vers num="2.6.23" edition="rc8"/>
        <vers num="2.6.23" edition="rc9"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.24" edition="rc1"/>
        <vers num="2.6.24" edition="rc2"/>
        <vers num="2.6.24" edition="rc3"/>
        <vers num="2.6.24" edition="rc4"/>
        <vers num="2.6.24" edition="rc5"/>
        <vers num="2.6.24" edition="rc6"/>
        <vers num="2.6.24" edition="rc7"/>
        <vers num="2.6.24" edition="rc8"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.25" edition="rc1"/>
        <vers num="2.6.25" edition="rc2"/>
        <vers num="2.6.25" edition="rc3"/>
        <vers num="2.6.25" edition="rc4"/>
        <vers num="2.6.25" edition="rc5"/>
        <vers num="2.6.25" edition="rc6"/>
        <vers num="2.6.25" edition="rc7"/>
        <vers num="2.6.25" edition="rc8"/>
        <vers num="2.6.25" edition="rc9"/>
        <vers num="2.6.25.1"/>
        <vers num="2.6.25.2"/>
        <vers num="2.6.25.3"/>
        <vers num="2.6.25.4"/>
        <vers num="2.6.25.5"/>
        <vers num="2.6.25.6"/>
        <vers num="2.6.25.7"/>
        <vers num="2.6.25.8"/>
        <vers num="2.6.25.9"/>
        <vers num="2.6.25.10"/>
        <vers num="2.6.25.11"/>
        <vers num="2.6.25.12"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.18"/>
        <vers num="2.6.25.19"/>
        <vers num="2.6.25.20"/>
        <vers num="2.6.26" edition="rc1"/>
        <vers num="2.6.26" edition="rc2"/>
        <vers num="2.6.26" edition="rc3"/>
        <vers num="2.6.26" edition="rc4"/>
        <vers num="2.6.26" edition="rc5"/>
        <vers num="2.6.26" edition="rc6"/>
        <vers num="2.6.26" edition="rc7"/>
        <vers num="2.6.26" edition="rc8"/>
        <vers num="2.6.26" edition="rc9"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.26.6"/>
        <vers num="2.6.26.7"/>
        <vers num="2.6.26.8"/>
        <vers num="2.6.27" edition="rc1"/>
        <vers num="2.6.27" edition="rc2"/>
        <vers num="2.6.27" edition="rc3"/>
        <vers num="2.6.27" edition="rc4"/>
        <vers num="2.6.27" edition="rc5"/>
        <vers num="2.6.27" edition="rc6"/>
        <vers num="2.6.27" edition="rc7"/>
        <vers num="2.6.27" edition="rc8"/>
        <vers num="2.6.27" edition="rc9"/>
        <vers num="2.6.27.1"/>
        <vers num="2.6.27.2"/>
        <vers num="2.6.27.3"/>
        <vers num="2.6.27.4"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.27.10"/>
        <vers num="2.6.27.11"/>
        <vers num="2.6.27.12"/>
        <vers num="2.6.27.13"/>
        <vers num="2.6.27.14"/>
        <vers num="2.6.27.15"/>
        <vers num="2.6.27.16"/>
        <vers num="2.6.27.17"/>
        <vers num="2.6.27.18"/>
        <vers num="2.6.27.19"/>
        <vers num="2.6.27.20"/>
        <vers num="2.6.27.21"/>
        <vers num="2.6.27.22"/>
        <vers num="2.6.27.23"/>
        <vers num="2.6.27.24"/>
        <vers num="2.6.27.25"/>
        <vers num="2.6.27.26"/>
        <vers num="2.6.27.27"/>
        <vers num="2.6.27.28"/>
        <vers num="2.6.27.29"/>
        <vers num="2.6.27.30"/>
        <vers num="2.6.27.31"/>
        <vers num="2.6.27.32"/>
        <vers num="2.6.27.33"/>
        <vers num="2.6.27.34"/>
        <vers num="2.6.27.35"/>
        <vers num="2.6.27.36"/>
        <vers num="2.6.27.37"/>
        <vers num="2.6.27.38"/>
        <vers num="2.6.27.39"/>
        <vers num="2.6.27.40"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers num="2.6.27.62"/>
        <vers num="2.6.28" edition="rc1"/>
        <vers num="2.6.28" edition="rc2"/>
        <vers num="2.6.28" edition="rc3"/>
        <vers num="2.6.28" edition="rc4"/>
        <vers num="2.6.28" edition="rc5"/>
        <vers num="2.6.28" edition="rc6"/>
        <vers num="2.6.28" edition="rc7"/>
        <vers num="2.6.28" edition="rc8"/>
        <vers num="2.6.28" edition="rc9"/>
        <vers num="2.6.28.1"/>
        <vers num="2.6.28.2"/>
        <vers num="2.6.28.3"/>
        <vers num="2.6.28.4"/>
        <vers num="2.6.28.5"/>
        <vers num="2.6.28.6"/>
        <vers num="2.6.28.7"/>
        <vers num="2.6.28.8"/>
        <vers num="2.6.28.9"/>
        <vers num="2.6.28.10"/>
        <vers num="2.6.29" edition="rc1"/>
        <vers num="2.6.29" edition="rc2"/>
        <vers num="2.6.29" edition="rc3"/>
        <vers num="2.6.29" edition="rc4"/>
        <vers num="2.6.29" edition="rc5"/>
        <vers num="2.6.29" edition="rc6"/>
        <vers num="2.6.29" edition="rc7"/>
        <vers num="2.6.29" edition="rc8"/>
        <vers num="2.6.29.1"/>
        <vers num="2.6.29.2"/>
        <vers num="2.6.29.3"/>
        <vers num="2.6.29.4"/>
        <vers num="2.6.29.5"/>
        <vers num="2.6.29.6"/>
        <vers num="2.6.30" edition="rc1"/>
        <vers num="2.6.30" edition="rc2"/>
        <vers num="2.6.30" edition="rc3"/>
        <vers num="2.6.30" edition="rc4"/>
        <vers num="2.6.30" edition="rc5"/>
        <vers num="2.6.30" edition="rc6"/>
        <vers num="2.6.30" edition="rc7"/>
        <vers num="2.6.30" edition="rc8"/>
        <vers num="2.6.30.1"/>
        <vers num="2.6.30.2"/>
        <vers num="2.6.30.3"/>
        <vers num="2.6.30.4"/>
        <vers num="2.6.30.5"/>
        <vers num="2.6.30.6"/>
        <vers num="2.6.30.7"/>
        <vers num="2.6.30.8"/>
        <vers num="2.6.30.9"/>
        <vers num="2.6.30.10"/>
        <vers num="2.6.31" edition="rc1"/>
        <vers num="2.6.31" edition="rc2"/>
        <vers num="2.6.31" edition="rc3"/>
        <vers num="2.6.31" edition="rc4"/>
        <vers num="2.6.31" edition="rc5"/>
        <vers num="2.6.31" edition="rc6"/>
        <vers num="2.6.31" edition="rc7"/>
        <vers num="2.6.31" edition="rc8"/>
        <vers num="2.6.31" edition="rc9"/>
        <vers num="2.6.31.1"/>
        <vers num="2.6.31.2"/>
        <vers num="2.6.31.3"/>
        <vers num="2.6.31.4"/>
        <vers num="2.6.31.5"/>
        <vers num="2.6.31.6"/>
        <vers num="2.6.31.7"/>
        <vers num="2.6.31.8"/>
        <vers num="2.6.31.9"/>
        <vers num="2.6.31.10"/>
        <vers num="2.6.31.11"/>
        <vers num="2.6.31.12"/>
        <vers num="2.6.31.13"/>
        <vers num="2.6.31.14"/>
        <vers num="2.6.32" edition="rc1"/>
        <vers num="2.6.32" edition="rc2"/>
        <vers num="2.6.32" edition="rc3"/>
        <vers num="2.6.32" edition="rc4"/>
        <vers num="2.6.32" edition="rc5"/>
        <vers num="2.6.32" edition="rc6"/>
        <vers num="2.6.32" edition="rc7"/>
        <vers num="2.6.32" edition="rc8"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.19"/>
        <vers num="2.6.32.20"/>
        <vers num="2.6.32.21"/>
        <vers num="2.6.32.22"/>
        <vers num="2.6.32.23"/>
        <vers num="2.6.32.24"/>
        <vers num="2.6.32.25"/>
        <vers num="2.6.32.26"/>
        <vers num="2.6.32.27"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.33" edition="rc1"/>
        <vers num="2.6.33" edition="rc2"/>
        <vers num="2.6.33" edition="rc3"/>
        <vers num="2.6.33" edition="rc4"/>
        <vers num="2.6.33" edition="rc5"/>
        <vers num="2.6.33" edition="rc6"/>
        <vers num="2.6.33" edition="rc7"/>
        <vers num="2.6.33" edition="rc8"/>
        <vers num="2.6.33.1"/>
        <vers num="2.6.33.2"/>
        <vers num="2.6.33.3"/>
        <vers num="2.6.33.4"/>
        <vers num="2.6.33.5"/>
        <vers num="2.6.33.6"/>
        <vers num="2.6.33.7"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.34" edition="rc1"/>
        <vers num="2.6.34" edition="rc2"/>
        <vers num="2.6.34" edition="rc3"/>
        <vers num="2.6.34" edition="rc4"/>
        <vers num="2.6.34" edition="rc5"/>
        <vers num="2.6.34" edition="rc6"/>
        <vers num="2.6.34" edition="rc7"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.4"/>
        <vers num="2.6.34.5"/>
        <vers num="2.6.34.6"/>
        <vers num="2.6.34.7"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.35" edition="rc1"/>
        <vers num="2.6.35" edition="rc2"/>
        <vers num="2.6.35" edition="rc3"/>
        <vers num="2.6.35" edition="rc4"/>
        <vers num="2.6.35" edition="rc5"/>
        <vers num="2.6.35" edition="rc6"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.2"/>
        <vers num="2.6.35.3"/>
        <vers num="2.6.35.4"/>
        <vers num="2.6.35.5"/>
        <vers num="2.6.35.6"/>
        <vers num="2.6.35.7"/>
        <vers num="2.6.35.8"/>
        <vers num="2.6.35.9"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.36" edition="rc1"/>
        <vers num="2.6.36" edition="rc2"/>
        <vers num="2.6.36" edition="rc3"/>
        <vers num="2.6.36" edition="rc4"/>
        <vers num="2.6.36" edition="rc5"/>
        <vers num="2.6.36" edition="rc6"/>
        <vers num="2.6.36" edition="rc7"/>
        <vers num="2.6.36" edition="rc8"/>
        <vers num="2.6.36.1"/>
        <vers num="2.6.36.2"/>
        <vers num="2.6.36.3"/>
        <vers num="2.6.36.4"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.37" edition="rc6"/>
        <vers num="2.6.37" edition="rc7"/>
        <vers num="2.6.37" edition="rc8"/>
        <vers num="2.6.37.1"/>
        <vers num="2.6.37.2"/>
        <vers num="2.6.37.3"/>
        <vers num="2.6.37.4"/>
        <vers num="2.6.37.5"/>
        <vers num="2.6.37.6"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.38.1"/>
        <vers num="2.6.38.2"/>
        <vers num="2.6.38.3"/>
        <vers num="2.6.38.4"/>
        <vers num="2.6.38.5"/>
        <vers num="2.6.38.6"/>
        <vers num="2.6.38.7"/>
        <vers num="2.6.38.8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.39.1"/>
        <vers num="2.6.39.2"/>
        <vers num="2.6.39.3"/>
        <vers num="2.6.39.4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.69"/>
        <vers num="3.0.70"/>
        <vers num="3.0.71"/>
        <vers num="3.0.72"/>
        <vers num="3.0.73"/>
        <vers num="3.0.74"/>
        <vers num="3.0.75"/>
        <vers num="3.0.76"/>
        <vers num="3.0.77"/>
        <vers num="3.0.78"/>
        <vers num="3.0.79"/>
        <vers num="3.0.80"/>
        <vers num="3.0.81"/>
        <vers num="3.0.82"/>
        <vers num="3.0.83"/>
        <vers num="3.0.84"/>
        <vers num="3.0.85"/>
        <vers num="3.0.86"/>
        <vers num="3.0.87"/>
        <vers num="3.0.88"/>
        <vers num="3.0.89"/>
        <vers num="3.0.90"/>
        <vers num="3.0.91"/>
        <vers num="3.0.92"/>
        <vers num="3.0.93"/>
        <vers num="3.0.94"/>
        <vers num="3.0.95"/>
        <vers num="3.0.96"/>
        <vers num="3.0.97"/>
        <vers num="3.0.98"/>
        <vers num="3.0.99"/>
        <vers num="3.0.100"/>
        <vers num="3.0.101"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.1.10"/>
        <vers num="3.2" edition=":~~~~x86~"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.30"/>
        <vers num="3.2.64"/>
        <vers num="3.2.65"/>
        <vers num="3.2.66"/>
        <vers num="3.2.67"/>
        <vers num="3.2.68"/>
        <vers num="3.2.69"/>
        <vers num="3.2.70"/>
        <vers num="3.2.71"/>
        <vers num="3.2.72"/>
        <vers num="3.2.73"/>
        <vers num="3.2.74"/>
        <vers num="3.2.75"/>
        <vers num="3.2.76"/>
        <vers num="3.2.77"/>
        <vers num="3.2.78"/>
        <vers num="3.2.79"/>
        <vers num="3.2.80"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition=":~~~~x86~"/>
        <vers num="3.4" edition="rc1:~~~~x86~"/>
        <vers num="3.4" edition="rc2:~~~~x86~"/>
        <vers num="3.4" edition="rc3:~~~~x86~"/>
        <vers num="3.4" edition="rc4:~~~~x86~"/>
        <vers num="3.4" edition="rc5:~~~~x86~"/>
        <vers num="3.4" edition="rc6:~~~~x86~"/>
        <vers num="3.4" edition="rc7:~~~~x86~"/>
        <vers num="3.4.1" edition=":~~~~x86~"/>
        <vers num="3.4.2" edition=":~~~~x86~"/>
        <vers num="3.4.3" edition=":~~~~x86~"/>
        <vers num="3.4.4" edition=":~~~~x86~"/>
        <vers num="3.4.5" edition=":~~~~x86~"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.33"/>
        <vers num="3.4.34"/>
        <vers num="3.4.35"/>
        <vers num="3.4.36"/>
        <vers num="3.4.37"/>
        <vers num="3.4.38"/>
        <vers num="3.4.39"/>
        <vers num="3.4.40"/>
        <vers num="3.4.41"/>
        <vers num="3.4.42"/>
        <vers num="3.4.43"/>
        <vers num="3.4.44"/>
        <vers num="3.4.45"/>
        <vers num="3.4.46"/>
        <vers num="3.4.47"/>
        <vers num="3.4.48"/>
        <vers num="3.4.49"/>
        <vers num="3.4.50"/>
        <vers num="3.4.51"/>
        <vers num="3.4.52"/>
        <vers num="3.4.53"/>
        <vers num="3.4.54"/>
        <vers num="3.4.55"/>
        <vers num="3.4.56"/>
        <vers num="3.4.57"/>
        <vers num="3.4.58"/>
        <vers num="3.4.59"/>
        <vers num="3.4.60"/>
        <vers num="3.4.61"/>
        <vers num="3.4.62"/>
        <vers num="3.4.63"/>
        <vers num="3.4.64"/>
        <vers num="3.4.65"/>
        <vers num="3.4.66"/>
        <vers num="3.4.67"/>
        <vers num="3.4.68"/>
        <vers num="3.4.69"/>
        <vers num="3.4.70"/>
        <vers num="3.4.71"/>
        <vers num="3.4.72"/>
        <vers num="3.4.73"/>
        <vers num="3.4.74"/>
        <vers num="3.4.75"/>
        <vers num="3.4.76"/>
        <vers num="3.4.77"/>
        <vers num="3.4.78"/>
        <vers num="3.4.79"/>
        <vers num="3.4.80"/>
        <vers num="3.4.81"/>
        <vers num="3.4.82"/>
        <vers num="3.4.83"/>
        <vers num="3.4.84"/>
        <vers num="3.4.85"/>
        <vers num="3.4.86"/>
        <vers num="3.4.87"/>
        <vers num="3.4.88"/>
        <vers num="3.4.89"/>
        <vers num="3.4.90"/>
        <vers num="3.4.91"/>
        <vers num="3.4.92"/>
        <vers num="3.4.93"/>
        <vers num="3.4.94"/>
        <vers num="3.4.95"/>
        <vers num="3.4.96"/>
        <vers num="3.4.97"/>
        <vers num="3.4.98"/>
        <vers num="3.4.99"/>
        <vers num="3.4.100"/>
        <vers num="3.4.101"/>
        <vers num="3.4.102"/>
        <vers num="3.4.103"/>
        <vers num="3.4.104"/>
        <vers num="3.4.105"/>
        <vers num="3.4.106"/>
        <vers num="3.4.107"/>
        <vers num="3.4.108"/>
        <vers num="3.4.109"/>
        <vers num="3.4.110"/>
        <vers num="3.4.111"/>
        <vers num="3.4.112"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6" edition="rc5"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.8"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9" edition="rc3"/>
        <vers num="3.9" edition="rc4"/>
        <vers num="3.9" edition="rc5"/>
        <vers num="3.9" edition="rc6"/>
        <vers num="3.9" edition="rc7"/>
        <vers num="3.9.0" edition=":~~~~arm64~"/>
        <vers num="3.9.1" edition=":~~~~arm64~"/>
        <vers num="3.9.2" edition=":~~~~arm64~"/>
        <vers num="3.9.3" edition=":~~~~arm64~"/>
        <vers num="3.9.4" edition=":~~~~arm64~"/>
        <vers num="3.9.5" edition=":~~~~arm64~"/>
        <vers num="3.9.6" edition=":~~~~arm64~"/>
        <vers num="3.9.7" edition=":~~~~arm64~"/>
        <vers num="3.9.8" edition=":~~~~arm64~"/>
        <vers num="3.9.9" edition=":~~~~arm64~"/>
        <vers num="3.9.10" edition=":~~~~arm64~"/>
        <vers num="3.9.11" edition=":~~~~arm64~"/>
        <vers num="3.10"/>
        <vers num="3.10.0" edition=":~~~~arm64~"/>
        <vers num="3.10.1" edition=":~~~~arm64~"/>
        <vers num="3.10.2" edition=":~~~~arm64~"/>
        <vers num="3.10.3" edition=":~~~~arm64~"/>
        <vers num="3.10.4" edition=":~~~~arm64~"/>
        <vers num="3.10.5" edition=":~~~~arm64~"/>
        <vers num="3.10.6" edition=":~~~~arm64~"/>
        <vers num="3.10.7" edition=":~~~~arm64~"/>
        <vers num="3.10.8" edition=":~~~~arm64~"/>
        <vers num="3.10.9" edition=":~~~~arm64~"/>
        <vers num="3.10.10"/>
        <vers num="3.10.11"/>
        <vers num="3.10.12"/>
        <vers num="3.10.13"/>
        <vers num="3.10.14"/>
        <vers num="3.10.15"/>
        <vers num="3.10.16"/>
        <vers num="3.10.17"/>
        <vers num="3.10.18"/>
        <vers num="3.10.19"/>
        <vers num="3.10.20"/>
        <vers num="3.10.21"/>
        <vers num="3.10.22"/>
        <vers num="3.10.23"/>
        <vers num="3.10.24"/>
        <vers num="3.10.25"/>
        <vers num="3.10.26"/>
        <vers num="3.10.27"/>
        <vers num="3.10.28"/>
        <vers num="3.10.29"/>
        <vers num="3.10.30"/>
        <vers num="3.10.31"/>
        <vers num="3.10.32"/>
        <vers num="3.10.33"/>
        <vers num="3.10.34"/>
        <vers num="3.10.35"/>
        <vers num="3.10.36"/>
        <vers num="3.10.37"/>
        <vers num="3.10.38"/>
        <vers num="3.10.39"/>
        <vers num="3.10.40"/>
        <vers num="3.10.41"/>
        <vers num="3.10.42"/>
        <vers num="3.10.43"/>
        <vers num="3.10.44"/>
        <vers num="3.10.45"/>
        <vers num="3.10.46"/>
        <vers num="3.10.47"/>
        <vers num="3.10.48"/>
        <vers num="3.10.49"/>
        <vers num="3.10.50"/>
        <vers num="3.10.51"/>
        <vers num="3.10.52"/>
        <vers num="3.10.53"/>
        <vers num="3.10.54"/>
        <vers num="3.10.55"/>
        <vers num="3.10.56"/>
        <vers num="3.10.57"/>
        <vers num="3.10.58"/>
        <vers num="3.10.59"/>
        <vers num="3.10.60"/>
        <vers num="3.10.61"/>
        <vers num="3.10.62"/>
        <vers num="3.10.63"/>
        <vers num="3.10.64"/>
        <vers num="3.10.65"/>
        <vers num="3.10.66"/>
        <vers num="3.10.67"/>
        <vers num="3.10.68"/>
        <vers num="3.10.69"/>
        <vers num="3.10.70"/>
        <vers num="3.10.71"/>
        <vers num="3.10.72"/>
        <vers num="3.10.73"/>
        <vers num="3.10.74"/>
        <vers num="3.10.75"/>
        <vers num="3.10.76"/>
        <vers num="3.10.77"/>
        <vers num="3.10.78"/>
        <vers num="3.10.79"/>
        <vers num="3.10.80"/>
        <vers num="3.10.81"/>
        <vers num="3.10.82"/>
        <vers num="3.10.83"/>
        <vers num="3.10.84"/>
        <vers num="3.10.85"/>
        <vers num="3.10.86"/>
        <vers num="3.10.87"/>
        <vers num="3.10.88"/>
        <vers num="3.10.89"/>
        <vers num="3.10.90"/>
        <vers num="3.10.91"/>
        <vers num="3.10.92"/>
        <vers num="3.10.93"/>
        <vers num="3.10.94"/>
        <vers num="3.10.95"/>
        <vers num="3.10.96"/>
        <vers num="3.10.97"/>
        <vers num="3.10.98"/>
        <vers num="3.10.99"/>
        <vers num="3.10.100"/>
        <vers num="3.10.101"/>
        <vers num="3.10.102"/>
        <vers num="3.11"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.8"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.8"/>
        <vers num="3.12.9"/>
        <vers num="3.12.10"/>
        <vers num="3.12.11"/>
        <vers num="3.12.12"/>
        <vers num="3.12.13"/>
        <vers num="3.12.14"/>
        <vers num="3.12.15"/>
        <vers num="3.12.16"/>
        <vers num="3.12.17"/>
        <vers num="3.12.18"/>
        <vers num="3.12.19"/>
        <vers num="3.12.20"/>
        <vers num="3.12.21"/>
        <vers num="3.12.22"/>
        <vers num="3.12.23"/>
        <vers num="3.12.24"/>
        <vers num="3.12.25"/>
        <vers num="3.12.26"/>
        <vers num="3.12.27"/>
        <vers num="3.12.28"/>
        <vers num="3.12.29"/>
        <vers num="3.12.30"/>
        <vers num="3.12.31"/>
        <vers num="3.12.32"/>
        <vers num="3.12.33"/>
        <vers num="3.12.34"/>
        <vers num="3.12.35"/>
        <vers num="3.12.36"/>
        <vers num="3.12.37"/>
        <vers num="3.12.38"/>
        <vers num="3.12.39"/>
        <vers num="3.12.40"/>
        <vers num="3.12.41"/>
        <vers num="3.12.42"/>
        <vers num="3.12.43"/>
        <vers num="3.12.44"/>
        <vers num="3.12.45"/>
        <vers num="3.12.46"/>
        <vers num="3.12.47"/>
        <vers num="3.12.48"/>
        <vers num="3.12.49"/>
        <vers num="3.12.50"/>
        <vers num="3.12.51"/>
        <vers num="3.12.52"/>
        <vers num="3.12.53"/>
        <vers num="3.12.54"/>
        <vers num="3.12.55"/>
        <vers num="3.12.56"/>
        <vers num="3.12.57"/>
        <vers num="3.12.58"/>
        <vers num="3.12.59"/>
        <vers num="3.13"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.4"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.8"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.13.11"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="rc1"/>
        <vers num="3.14" edition="rc2"/>
        <vers num="3.14" edition="rc3"/>
        <vers num="3.14" edition="rc4"/>
        <vers num="3.14" edition="rc5"/>
        <vers num="3.14" edition="rc6"/>
        <vers num="3.14" edition="rc7"/>
        <vers num="3.14" edition="rc8"/>
        <vers num="3.14.1"/>
        <vers num="3.14.2"/>
        <vers num="3.14.3"/>
        <vers num="3.14.4"/>
        <vers num="3.14.5"/>
        <vers num="3.14.8"/>
        <vers num="3.14.10"/>
        <vers num="3.14.11"/>
        <vers num="3.14.12"/>
        <vers num="3.14.13"/>
        <vers num="3.14.14"/>
        <vers num="3.14.15"/>
        <vers num="3.14.16"/>
        <vers num="3.14.17"/>
        <vers num="3.14.18"/>
        <vers num="3.14.19"/>
        <vers num="3.14.20"/>
        <vers num="3.14.21"/>
        <vers num="3.14.22"/>
        <vers num="3.14.23"/>
        <vers num="3.14.24"/>
        <vers num="3.14.25"/>
        <vers num="3.14.26"/>
        <vers num="3.14.27"/>
        <vers num="3.14.28"/>
        <vers num="3.14.29"/>
        <vers num="3.14.30"/>
        <vers num="3.14.31"/>
        <vers num="3.14.32"/>
        <vers num="3.14.33"/>
        <vers num="3.14.34"/>
        <vers num="3.14.35"/>
        <vers num="3.14.36"/>
        <vers num="3.14.37"/>
        <vers num="3.14.38"/>
        <vers num="3.14.39"/>
        <vers num="3.14.40"/>
        <vers num="3.14.41"/>
        <vers num="3.14.42"/>
        <vers num="3.14.43"/>
        <vers num="3.14.44"/>
        <vers num="3.14.45"/>
        <vers num="3.14.46"/>
        <vers num="3.14.47"/>
        <vers num="3.14.48"/>
        <vers num="3.14.49"/>
        <vers num="3.14.50"/>
        <vers num="3.14.51"/>
        <vers num="3.14.52"/>
        <vers num="3.14.53"/>
        <vers num="3.14.54"/>
        <vers num="3.14.55"/>
        <vers num="3.14.56"/>
        <vers num="3.14.57"/>
        <vers num="3.14.58"/>
        <vers num="3.14.59"/>
        <vers num="3.14.60"/>
        <vers num="3.14.61"/>
        <vers num="3.14.62"/>
        <vers num="3.14.63"/>
        <vers num="3.14.64"/>
        <vers num="3.14.65"/>
        <vers num="3.14.66"/>
        <vers num="3.14.67"/>
        <vers num="3.14.68"/>
        <vers num="3.14.79"/>
        <vers num="3.15" edition="rc4"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
        <vers num="3.15.4"/>
        <vers num="3.15.5"/>
        <vers num="3.15.6"/>
        <vers num="3.15.7"/>
        <vers num="3.15.8"/>
        <vers num="3.15.10"/>
        <vers num="3.16"/>
        <vers num="3.16.0"/>
        <vers num="3.16.1"/>
        <vers num="3.16.4"/>
        <vers num="3.16.5"/>
        <vers num="3.16.6"/>
        <vers num="3.16.7"/>
        <vers num="3.17"/>
        <vers num="3.17.3" edition=":~~~~arm64~"/>
        <vers num="3.17.5"/>
        <vers num="3.17.6"/>
        <vers num="3.17.7"/>
        <vers num="3.17.8"/>
        <vers num="3.18"/>
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.10"/>
        <vers num="3.18.11"/>
        <vers num="3.18.12"/>
        <vers num="3.18.13"/>
        <vers num="3.18.14"/>
        <vers num="3.18.15"/>
        <vers num="3.18.16"/>
        <vers num="3.18.17"/>
        <vers num="3.18.18"/>
        <vers num="3.18.19"/>
        <vers num="3.18.20"/>
        <vers num="3.18.21"/>
        <vers num="3.18.22"/>
        <vers num="3.18.23"/>
        <vers num="3.18.24"/>
        <vers num="3.18.25"/>
        <vers num="3.18.26"/>
        <vers num="3.18.27"/>
        <vers num="3.18.28"/>
        <vers num="3.18.29"/>
        <vers num="3.18.30"/>
        <vers num="3.18.31"/>
        <vers num="3.18.32"/>
        <vers num="3.18.33"/>
        <vers num="3.18.34"/>
        <vers num="3.18.35"/>
        <vers num="3.18.36"/>
        <vers num="3.18.37"/>
        <vers num="3.18.38"/>
        <vers num="3.18.39"/>
        <vers num="3.18.40"/>
        <vers num="3.18.41"/>
        <vers num="3.18.42"/>
        <vers num="3.18.43"/>
        <vers num="3.18.44"/>
        <vers num="3.18.45"/>
        <vers num="3.18.46"/>
        <vers num="3.18.47"/>
        <vers num="3.18.48"/>
        <vers num="3.18.49"/>
        <vers num="3.18.50"/>
        <vers num="3.18.51"/>
        <vers num="3.18.52"/>
        <vers num="3.18.53"/>
        <vers num="3.18.54"/>
        <vers num="3.18.55"/>
        <vers num="3.18.56"/>
        <vers num="3.18.57"/>
        <vers num="3.18.58"/>
        <vers num="3.18.59"/>
        <vers num="3.18.60"/>
        <vers num="3.18.61"/>
        <vers num="3.18.62"/>
        <vers num="3.18.63"/>
        <vers num="3.18.64"/>
        <vers num="3.18.65"/>
        <vers num="3.18.66"/>
        <vers num="3.19"/>
        <vers num="3.19.1"/>
        <vers num="3.19.2"/>
        <vers num="3.19.3"/>
        <vers num="3.19.4"/>
        <vers num="3.19.5"/>
        <vers num="3.19.6"/>
        <vers num="3.19.7"/>
        <vers num="3.19.8"/>
        <vers num="4"/>
        <vers num="4.0" edition="rc5"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.1" edition="rc2"/>
        <vers num="4.1" edition="rc3"/>
        <vers num="4.1" edition="rc4"/>
        <vers num="4.1" edition="rc5"/>
        <vers num="4.1" edition="rc6"/>
        <vers num="4.1" edition="rc7"/>
        <vers num="4.1" edition="rc8"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.1.27"/>
        <vers num="4.1.28"/>
        <vers num="4.1.29"/>
        <vers num="4.1.30"/>
        <vers num="4.1.31"/>
        <vers num="4.1.32"/>
        <vers num="4.1.33"/>
        <vers num="4.1.34"/>
        <vers num="4.1.35"/>
        <vers num="4.1.36"/>
        <vers num="4.1.37"/>
        <vers num="4.1.38"/>
        <vers num="4.1.39"/>
        <vers num="4.1.40"/>
        <vers num="4.1.41"/>
        <vers num="4.1.42"/>
        <vers num="4.1.43"/>
        <vers num="4.1.44"/>
        <vers num="4.1.45"/>
        <vers num="4.1.46"/>
        <vers num="4.1.47"/>
        <vers num="4.1.48"/>
        <vers num="4.1.49"/>
        <vers num="4.1.50"/>
        <vers num="4.1.51"/>
        <vers num="4.1.52"/>
        <vers num="4.2" edition="rc1"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc3"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.2" edition="rc6"/>
        <vers num="4.2" edition="rc7"/>
        <vers num="4.2" edition="rc8"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.3" edition="rc1"/>
        <vers num="4.3" edition="rc2"/>
        <vers num="4.3" edition="rc3"/>
        <vers num="4.3" edition="rc4"/>
        <vers num="4.3" edition="rc5"/>
        <vers num="4.3" edition="rc6"/>
        <vers num="4.3" edition="rc7"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4" edition="rc8"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.4.19"/>
        <vers num="4.4.20"/>
        <vers num="4.4.21"/>
        <vers num="4.4.22"/>
        <vers num="4.4.23"/>
        <vers num="4.4.24"/>
        <vers num="4.4.25"/>
        <vers num="4.4.26"/>
        <vers num="4.4.27"/>
        <vers num="4.4.28"/>
        <vers num="4.4.29"/>
        <vers num="4.4.30"/>
        <vers num="4.4.31"/>
        <vers num="4.4.32"/>
        <vers num="4.4.33"/>
        <vers num="4.4.34"/>
        <vers num="4.4.35"/>
        <vers num="4.4.36"/>
        <vers num="4.4.37"/>
        <vers num="4.4.38"/>
        <vers num="4.4.39"/>
        <vers num="4.4.40"/>
        <vers num="4.4.41"/>
        <vers num="4.4.42"/>
        <vers num="4.4.43"/>
        <vers num="4.4.44"/>
        <vers num="4.4.45"/>
        <vers num="4.4.46"/>
        <vers num="4.4.47"/>
        <vers num="4.4.48"/>
        <vers num="4.4.49"/>
        <vers num="4.4.50"/>
        <vers num="4.4.51"/>
        <vers num="4.4.52"/>
        <vers num="4.4.53"/>
        <vers num="4.4.54"/>
        <vers num="4.4.55"/>
        <vers num="4.4.56"/>
        <vers num="4.4.57"/>
        <vers num="4.4.58"/>
        <vers num="4.4.59"/>
        <vers num="4.4.60"/>
        <vers num="4.4.61"/>
        <vers num="4.4.62"/>
        <vers num="4.4.63"/>
        <vers num="4.4.64"/>
        <vers num="4.4.65"/>
        <vers num="4.4.66"/>
        <vers num="4.4.67"/>
        <vers num="4.4.68"/>
        <vers num="4.4.69"/>
        <vers num="4.4.70"/>
        <vers num="4.4.71"/>
        <vers num="4.4.72"/>
        <vers num="4.4.73"/>
        <vers num="4.4.74"/>
        <vers num="4.4.75"/>
        <vers num="4.4.76"/>
        <vers num="4.4.77"/>
        <vers num="4.4.78"/>
        <vers num="4.4.79"/>
        <vers num="4.4.80"/>
        <vers num="4.4.81"/>
        <vers num="4.4.82"/>
        <vers num="4.4.83"/>
        <vers num="4.4.84"/>
        <vers num="4.4.85"/>
        <vers num="4.4.86"/>
        <vers num="4.4.87"/>
        <vers num="4.4.88"/>
        <vers num="4.4.89"/>
        <vers num="4.4.90"/>
        <vers num="4.4.91"/>
        <vers num="4.4.92"/>
        <vers num="4.4.93"/>
        <vers num="4.4.94"/>
        <vers num="4.4.95"/>
        <vers num="4.4.96"/>
        <vers num="4.4.97"/>
        <vers num="4.4.98"/>
        <vers num="4.4.99"/>
        <vers num="4.4.100"/>
        <vers num="4.4.101"/>
        <vers num="4.4.102"/>
        <vers num="4.4.103"/>
        <vers num="4.4.104"/>
        <vers num="4.4.105"/>
        <vers num="4.4.106"/>
        <vers num="4.4.107"/>
        <vers num="4.4.108"/>
        <vers num="4.4.109"/>
        <vers num="4.4.110"/>
        <vers num="4.4.111"/>
        <vers num="4.4.112"/>
        <vers num="4.4.113"/>
        <vers num="4.4.114"/>
        <vers num="4.4.115"/>
        <vers num="4.4.116"/>
        <vers num="4.4.117"/>
        <vers num="4.4.118"/>
        <vers num="4.4.119"/>
        <vers num="4.4.120"/>
        <vers num="4.4.121"/>
        <vers num="4.4.122"/>
        <vers num="4.4.123"/>
        <vers num="4.4.124"/>
        <vers num="4.4.125"/>
        <vers num="4.4.126"/>
        <vers num="4.4.127"/>
        <vers num="4.4.128"/>
        <vers num="4.4.129"/>
        <vers num="4.4.130"/>
        <vers num="4.4.131"/>
        <vers num="4.4.132"/>
        <vers num="4.4.133"/>
        <vers num="4.4.134"/>
        <vers num="4.4.135"/>
        <vers num="4.4.136"/>
        <vers num="4.4.137"/>
        <vers num="4.4.138"/>
        <vers num="4.4.139"/>
        <vers num="4.4.140"/>
        <vers num="4.4.141"/>
        <vers num="4.4.142"/>
        <vers num="4.4.143"/>
        <vers num="4.4.144"/>
        <vers num="4.4.145"/>
        <vers num="4.4.146"/>
        <vers num="4.4.147"/>
        <vers num="4.4.148"/>
        <vers num="4.4.149"/>
        <vers num="4.4.150"/>
        <vers num="4.4.151"/>
        <vers num="4.4.152"/>
        <vers num="4.4.153"/>
        <vers num="4.4.154"/>
        <vers num="4.4.155"/>
        <vers num="4.4.156"/>
        <vers num="4.4.157"/>
        <vers num="4.4.158"/>
        <vers num="4.4.159"/>
        <vers num="4.4.160"/>
        <vers num="4.4.161"/>
        <vers num="4.4.162"/>
        <vers num="4.4.163"/>
        <vers num="4.4.164"/>
        <vers num="4.4.165"/>
        <vers num="4.4.166"/>
        <vers num="4.4.167"/>
        <vers num="4.4.168"/>
        <vers num="4.4.169"/>
        <vers num="4.4.170"/>
        <vers num="4.4.171"/>
        <vers num="4.4.172"/>
        <vers num="4.4.173"/>
        <vers num="4.4.174"/>
        <vers num="4.4.175"/>
        <vers num="4.4.176"/>
        <vers num="4.4.177"/>
        <vers num="4.4.178"/>
        <vers num="4.4.179"/>
        <vers num="4.4.180"/>
        <vers num="4.4.181"/>
        <vers num="4.4.182"/>
        <vers num="4.4.183"/>
        <vers num="4.4.184"/>
        <vers num="4.4.185"/>
        <vers num="4.4.186"/>
        <vers num="4.4.187"/>
        <vers num="4.4.188"/>
        <vers num="4.4.189"/>
        <vers num="4.4.190"/>
        <vers num="4.5" edition="rc3"/>
        <vers num="4.5" edition="rc4"/>
        <vers num="4.5.0" edition="rc7"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.7" edition="rc1"/>
        <vers num="4.7" edition="rc2"/>
        <vers num="4.7" edition="rc3"/>
        <vers num="4.7" edition="rc4"/>
        <vers num="4.7" edition="rc5"/>
        <vers num="4.7" edition="rc6"/>
        <vers num="4.7" edition="rc7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7.10"/>
        <vers num="4.8" edition="rc5"/>
        <vers num="4.8" edition="rc6"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="4.8.10"/>
        <vers num="4.8.11"/>
        <vers num="4.8.12"/>
        <vers num="4.8.13"/>
        <vers num="4.8.14"/>
        <vers num="4.8.15"/>
        <vers num="4.8.16"/>
        <vers num="4.8.17"/>
        <vers num="4.9" edition="rc1"/>
        <vers num="4.9" edition="rc2"/>
        <vers num="4.9" edition="rc3"/>
        <vers num="4.9" edition="rc4"/>
        <vers num="4.9" edition="rc5"/>
        <vers num="4.9" edition="rc6"/>
        <vers num="4.9" edition="rc7"/>
        <vers num="4.9" edition="rc8"/>
        <vers num="4.9.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
        <vers num="4.9.13"/>
        <vers num="4.9.14"/>
        <vers num="4.9.15"/>
        <vers num="4.9.16"/>
        <vers num="4.9.17"/>
        <vers num="4.9.18"/>
        <vers num="4.9.19"/>
        <vers num="4.9.20"/>
        <vers num="4.9.21"/>
        <vers num="4.9.22"/>
        <vers num="4.9.23"/>
        <vers num="4.9.24"/>
        <vers num="4.9.25"/>
        <vers num="4.9.26"/>
        <vers num="4.9.27"/>
        <vers num="4.9.28"/>
        <vers num="4.9.29"/>
        <vers num="4.9.30"/>
        <vers num="4.9.31"/>
        <vers num="4.9.32"/>
        <vers num="4.9.33"/>
        <vers num="4.9.34"/>
        <vers num="4.9.35"/>
        <vers num="4.9.36"/>
        <vers num="4.9.37"/>
        <vers num="4.9.38"/>
        <vers num="4.9.39"/>
        <vers num="4.9.40"/>
        <vers num="4.9.41"/>
        <vers num="4.9.42"/>
        <vers num="4.9.43"/>
        <vers num="4.9.44"/>
        <vers num="4.9.45"/>
        <vers num="4.9.46"/>
        <vers num="4.9.47"/>
        <vers num="4.9.48"/>
        <vers num="4.9.49"/>
        <vers num="4.9.50"/>
        <vers num="4.9.51"/>
        <vers num="4.9.52"/>
        <vers num="4.9.53"/>
        <vers num="4.9.54"/>
        <vers num="4.9.55"/>
        <vers num="4.9.56"/>
        <vers num="4.9.57"/>
        <vers num="4.9.58"/>
        <vers num="4.9.59"/>
        <vers num="4.9.60"/>
        <vers num="4.9.61"/>
        <vers num="4.9.62"/>
        <vers num="4.9.63"/>
        <vers num="4.9.64"/>
        <vers num="4.9.65"/>
        <vers num="4.9.66"/>
        <vers num="4.9.67"/>
        <vers num="4.9.68"/>
        <vers num="4.9.69"/>
        <vers num="4.9.70"/>
        <vers num="4.9.71"/>
        <vers num="4.9.72"/>
        <vers num="4.9.73"/>
        <vers num="4.9.74"/>
        <vers num="4.9.75"/>
        <vers num="4.9.76"/>
        <vers num="4.9.77"/>
        <vers num="4.9.78"/>
        <vers num="4.9.79"/>
        <vers num="4.9.80"/>
        <vers num="4.9.81"/>
        <vers num="4.9.82"/>
        <vers num="4.9.83"/>
        <vers num="4.9.84"/>
        <vers num="4.9.85"/>
        <vers num="4.9.86"/>
        <vers num="4.9.87"/>
        <vers num="4.9.88"/>
        <vers num="4.9.89"/>
        <vers num="4.9.90"/>
        <vers num="4.9.91"/>
        <vers num="4.9.92"/>
        <vers num="4.9.93"/>
        <vers num="4.9.94"/>
        <vers num="4.9.95"/>
        <vers num="4.9.96"/>
        <vers num="4.9.97"/>
        <vers num="4.9.98"/>
        <vers num="4.9.99"/>
        <vers num="4.9.100"/>
        <vers num="4.9.101"/>
        <vers num="4.9.102"/>
        <vers num="4.9.103"/>
        <vers num="4.9.104"/>
        <vers num="4.9.105"/>
        <vers num="4.9.106"/>
        <vers num="4.9.107"/>
        <vers num="4.9.108"/>
        <vers num="4.9.109"/>
        <vers num="4.9.110"/>
        <vers num="4.9.111"/>
        <vers num="4.9.112"/>
        <vers num="4.9.113"/>
        <vers num="4.9.114"/>
        <vers num="4.9.115"/>
        <vers num="4.9.116"/>
        <vers num="4.9.117"/>
        <vers num="4.9.118"/>
        <vers num="4.9.119"/>
        <vers num="4.9.120"/>
        <vers num="4.9.121"/>
        <vers num="4.9.122"/>
        <vers num="4.9.123"/>
        <vers num="4.9.124"/>
        <vers num="4.9.125"/>
        <vers num="4.9.126"/>
        <vers num="4.9.127"/>
        <vers num="4.9.128"/>
        <vers num="4.9.129"/>
        <vers num="4.9.130"/>
        <vers num="4.9.131"/>
        <vers num="4.9.132"/>
        <vers num="4.9.133"/>
        <vers num="4.9.134"/>
        <vers num="4.9.135"/>
        <vers num="4.9.136"/>
        <vers num="4.9.137"/>
        <vers num="4.9.138"/>
        <vers num="4.9.139"/>
        <vers num="4.9.140"/>
        <vers num="4.9.141"/>
        <vers num="4.9.142"/>
        <vers num="4.9.143"/>
        <vers num="4.9.144"/>
        <vers num="4.9.145"/>
        <vers num="4.9.146"/>
        <vers num="4.9.147"/>
        <vers num="4.9.148"/>
        <vers num="4.9.149"/>
        <vers num="4.9.150"/>
        <vers num="4.9.151"/>
        <vers num="4.9.152"/>
        <vers num="4.9.153"/>
        <vers num="4.9.154"/>
        <vers num="4.9.155"/>
        <vers num="4.9.156"/>
        <vers num="4.9.157"/>
        <vers num="4.9.158"/>
        <vers num="4.9.159"/>
        <vers num="4.9.160"/>
        <vers num="4.9.161"/>
        <vers num="4.9.162"/>
        <vers num="4.9.163"/>
        <vers num="4.9.164"/>
        <vers num="4.9.165"/>
        <vers num="4.9.166"/>
        <vers num="4.9.167"/>
        <vers num="4.9.168"/>
        <vers num="4.9.169"/>
        <vers num="4.9.170"/>
        <vers num="4.9.171"/>
        <vers num="4.9.172"/>
        <vers num="4.9.173"/>
        <vers num="4.9.174"/>
        <vers num="4.9.175"/>
        <vers num="4.9.176"/>
        <vers num="4.9.177"/>
        <vers num="4.9.178"/>
        <vers num="4.9.179"/>
        <vers num="4.9.180"/>
        <vers num="4.9.181"/>
        <vers num="4.9.182"/>
        <vers num="4.9.183"/>
        <vers num="4.9.184"/>
        <vers num="4.9.185"/>
        <vers num="4.9.186"/>
        <vers num="4.9.187"/>
        <vers num="4.9.188"/>
        <vers num="4.9.189"/>
        <vers num="4.9.190"/>
        <vers num="4.10" edition="rc3"/>
        <vers num="4.10" edition="rc4"/>
        <vers num="4.10.1"/>
        <vers num="4.10.2"/>
        <vers num="4.10.3"/>
        <vers num="4.10.4"/>
        <vers num="4.10.5"/>
        <vers num="4.10.6"/>
        <vers num="4.10.7"/>
        <vers num="4.10.8"/>
        <vers num="4.10.9"/>
        <vers num="4.10.10"/>
        <vers num="4.10.11"/>
        <vers num="4.10.12"/>
        <vers num="4.10.13"/>
        <vers num="4.10.14"/>
        <vers num="4.10.15"/>
        <vers num="4.10.16"/>
        <vers num="4.10.17"/>
        <vers num="4.11" edition="rc1"/>
        <vers num="4.11" edition="rc2"/>
        <vers num="4.11" edition="rc3"/>
        <vers num="4.11" edition="rc4"/>
        <vers num="4.11" edition="rc5"/>
        <vers num="4.11" edition="rc6"/>
        <vers num="4.11" edition="rc7"/>
        <vers num="4.11.1"/>
        <vers num="4.11.2"/>
        <vers num="4.11.3"/>
        <vers num="4.11.4"/>
        <vers num="4.11.5"/>
        <vers num="4.11.6"/>
        <vers num="4.11.7"/>
        <vers num="4.11.8"/>
        <vers num="4.11.9"/>
        <vers num="4.11.10"/>
        <vers num="4.11.11"/>
        <vers num="4.11.12"/>
        <vers num="4.12" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000364" seq="2017-1000364" published="2017-06-19" modified="2018-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3886">DSA-3886</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99130">99130</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038724">1038724</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1482">RHSA-2017:1482</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1483">RHSA-2017:1483</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1484">RHSA-2017:1484</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1485">RHSA-2017:1485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1486">RHSA-2017:1486</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1487">RHSA-2017:1487</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1488">RHSA-2017:1488</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1489">RHSA-2017:1489</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1490">RHSA-2017:1490</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1491">RHSA-2017:1491</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1567">RHSA-2017:1567</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1616">RHSA-2017:1616</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1647">RHSA-2017:1647</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1712">RHSA-2017:1712</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000364" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000364</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10207">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10207</ref>
      <ref source="CONFIRM" url="https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&amp;docId=emr_na-hpesbhf03800en_us">https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&amp;docId=emr_na-hpesbhf03800en_us</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45625/">45625</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
      <ref source="CONFIRM" url="https://www.suse.com/security/cve/CVE-2017-1000364/" adv="1">https://www.suse.com/security/cve/CVE-2017-1000364/</ref>
      <ref source="CONFIRM" url="https://www.suse.com/support/kb/doc/?id=7020973" adv="1">https://www.suse.com/support/kb/doc/?id=7020973</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000365" seq="2017-1000365" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3927">DSA-3927</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3945">DSA-3945</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99156" adv="1">99156</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000365" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000365</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000366" seq="2017-1000366" published="2017-06-19" modified="2019-09-04" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html">http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html</ref>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2019/Sep/7">20190904 SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3887" adv="1">DSA-3887</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99127" adv="1">99127</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038712" adv="1">1038712</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1479" adv="1">RHSA-2017:1479</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1480" adv="1">RHSA-2017:1480</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1481" adv="1">RHSA-2017:1481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1567" adv="1">RHSA-2017:1567</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1712" adv="1">RHSA-2017:1712</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000366" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000366</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205" adv="1" patch="1">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Sep/7">20190904 SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201706-19" adv="1">GLSA-201706-19</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42274/" adv="1">42274</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42275/" adv="1">42275</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42276/" adv="1">42276</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
      <ref source="CONFIRM" url="https://www.suse.com/security/cve/CVE-2017-1000366/" adv="1">https://www.suse.com/security/cve/CVE-2017-1000366/</ref>
      <ref source="CONFIRM" url="https://www.suse.com/support/kb/doc/?id=7020973" adv="1">https://www.suse.com/support/kb/doc/?id=7020973</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.25" prev="1"/>
      </prod>
      <prod name="web_gateway" vendor="mcafee">
        <vers num="7.6.2.14" prev="1"/>
        <vers num="7.7.0.1"/>
        <vers num="7.7.0.2"/>
        <vers num="7.7.0.3"/>
        <vers num="7.7.1"/>
        <vers num="7.7.1.1"/>
        <vers num="7.7.1.2"/>
        <vers num="7.7.1.3"/>
        <vers num="7.7.1.4"/>
        <vers num="7.7.1.5"/>
        <vers num="7.7.2"/>
        <vers num="7.7.2.0"/>
        <vers num="7.7.2.1"/>
        <vers num="7.7.2.2"/>
      </prod>
      <prod name="cloud_magnum_orchestration" vendor="openstack">
        <vers num="7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="suse_linux_enterprise_desktop" vendor="novell">
        <vers num="12.0" edition="sp2"/>
      </prod>
      <prod name="suse_linux_enterprise_point_of_sale" vendor="novell">
        <vers num="11.0" edition="sp3"/>
      </prod>
      <prod name="suse_linux_enterprise_server" vendor="novell">
        <vers num="11.0" edition="sp3:~~ltss~~~"/>
      </prod>
      <prod name="leap" vendor="opensuse">
        <vers num="42.2"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="5" edition=":server"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.6"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="5.9"/>
        <vers num="6.2"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="6.2"/>
        <vers num="6.5"/>
        <vers num="6.7"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_long_life" vendor="redhat">
        <vers num="5.9"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="6.5"/>
        <vers num="6.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="virtualization" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="linux_enterprise_for_sap" vendor="suse">
        <vers num="12" edition="sp1"/>
      </prod>
      <prod name="linux_enterprise_server" vendor="suse">
        <vers num="10" edition="sp4:~~ltss~~~"/>
        <vers num="11" edition="sp4"/>
        <vers num="12" edition="sp1:~~ltss~~~"/>
        <vers num="12" edition="sp2:~~ltss~~~"/>
      </prod>
      <prod name="linux_enterprise_server_for_raspberry_pi" vendor="suse">
        <vers num="12" edition="sp2"/>
      </prod>
      <prod name="linux_enterprise_software_development_kit" vendor="suse">
        <vers num="11.0" edition="sp4"/>
        <vers num="12.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000367" seq="2017-1000367" published="2017-06-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00077.html" adv="1">SUSE-SU-2017:1446</ref>
      <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00078.html" adv="1">SUSE-SU-2017:1450</ref>
      <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00079.html" adv="1">openSUSE-SU-2017:1455</ref>
      <ref source="MISC" url="http://packetstormsecurity.com/files/142783/Sudo-get_process_ttyname-Race-Condition.html" adv="1">http://packetstormsecurity.com/files/142783/Sudo-get_process_ttyname-Race-Condition.html</ref>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2017/Jun/3" adv="1">20170602 Qualys Security Advisory - CVE-2017-1000367 in Sudo's get_process_ttyname() for Linux</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3867" adv="1">DSA-3867</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/05/30/16" adv="1">[oss-security] 20170530 Qualys Security Advisory - CVE-2017-1000367 in Sudo's get_process_ttyname() for Linux</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98745" adv="1">98745</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038582" adv="1">1038582</ref>
      <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-3304-1" adv="1">USN-3304-1</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1381" adv="1">RHSA-2017:1381</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1382" adv="1">RHSA-2017:1382</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXEXC4NNIG2QOZY6N2YUK246KI3D3UQO/" adv="1">FEDORA-2017-54580efa82</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201705-15" adv="1">GLSA-201705-15</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42183/" adv="1">42183</ref>
      <ref source="CONFIRM" url="https://www.sudo.ws/alerts/linux_tty.html" adv="1">https://www.sudo.ws/alerts/linux_tty.html</ref>
    </refs>
    <vuln_soft>
      <prod name="sudo" vendor="sudo_project">
        <vers num="1.8.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000368" seq="2017-1000368" published="2017-06-05" modified="2019-05-29" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98838" adv="1">98838</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1574" adv="1">RHSA-2017:1574</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205" adv="1">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10205</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-04" adv="1">GLSA-201710-04</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3968-1/">USN-3968-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3968-2/">USN-3968-2</ref>
      <ref source="CONFIRM" url="https://www.sudo.ws/alerts/linux_tty.html" adv="1">https://www.sudo.ws/alerts/linux_tty.html</ref>
    </refs>
    <vuln_soft>
      <prod name="sudo" vendor="sudo_project">
        <vers num="1.8.20" prev="1" edition="p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000369" seq="2017-1000369" published="2017-06-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3888">DSA-3888</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99252" adv="1">99252</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038779">1038779</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000369" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000369</ref>
      <ref source="MISC" url="https://github.com/Exim/exim/commit/65e061b76867a9ea7aeeb535341b790b90ae6c21" adv="1">https://github.com/Exim/exim/commit/65e061b76867a9ea7aeeb535341b790b90ae6c21</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-19">GLSA-201709-19</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="exim" vendor="exim">
        <vers num="4.89" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000370" seq="2017-1000370" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99149" adv="1">99149</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000370" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000370</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42273/">42273</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42274/">42274</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000371" seq="2017-1000371" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99131" adv="1">99131</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000371" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000371</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42273/">42273</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42276/">42276</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000372" seq="2017-1000372" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99172" adv="1">99172</ref>
      <ref source="MISC" url="https://ftp.openbsd.org/pub/OpenBSD/patches/6.1/common/008_exec_subr.patch.sig" adv="1">https://ftp.openbsd.org/pub/OpenBSD/patches/6.1/common/008_exec_subr.patch.sig</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000373" seq="2017-1000373" published="2017-06-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99177" adv="1">99177</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039427">1039427</ref>
      <ref source="MISC" url="https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&amp;content-type=text/x-cvsweb-markup" adv="1">https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&amp;content-type=text/x-cvsweb-markup</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113">https://support.apple.com/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208115">https://support.apple.com/HT208115</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208144">https://support.apple.com/HT208144</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42271/">42271</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000374" seq="2017-1000374" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99176" adv="1">99176</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000375" seq="2017-1000375" published="2017-06-19" modified="2017-08-11" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99257" adv="1">99257</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42272/">42272</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000376" seq="2017-1000376" published="2017-06-19" modified="2019-04-26" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3889" adv="1">DSA-3889</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000376" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000376</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_virtualization_server" vendor="redhat">
        <vers num="-"/>
      </prod>
      <prod name="openshift" vendor="redhat">
        <vers num="2.0" edition=":enterprise"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000377" seq="2017-1000377" published="2017-06-19" modified="2017-07-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99129" adv="1">99129</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000377">https://access.redhat.com/security/cve/CVE-2017-1000377</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000378" seq="2017-1000378" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/stdlib/qsort.c?rev=1.23&amp;content-type=text/x-cvsweb-markup" adv="1">http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/stdlib/qsort.c?rev=1.23&amp;content-type=text/x-cvsweb-markup</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99255" adv="1">99255</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000379" seq="2017-1000379" published="2017-06-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99284">99284</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1482">RHSA-2017:1482</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1484">RHSA-2017:1484</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1485">RHSA-2017:1485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1486">RHSA-2017:1486</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1487">RHSA-2017:1487</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1488">RHSA-2017:1488</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1489">RHSA-2017:1489</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1490">RHSA-2017:1490</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1491">RHSA-2017:1491</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1616">RHSA-2017:1616</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1647">RHSA-2017:1647</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1712">RHSA-2017:1712</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1842">RHSA-2017:1842</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/CVE-2017-1000379" adv="1">https://access.redhat.com/security/cve/CVE-2017-1000379</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42275/">42275</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000380" seq="2017-1000380" published="2017-06-17" modified="2017-12-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ba3021b2c79b2fa9114f92790a99deb27a65b728" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ba3021b2c79b2fa9114f92790a99deb27a65b728</ref>
      <ref source="MISC" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d11662f4f798b50d8c8743f433842c3e40fe3378" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d11662f4f798b50d8c8743f433842c3e40fe3378</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="MISC" url="http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.5" adv="1">http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.5</ref>
      <ref source="MISC" url="http://www.openwall.com/lists/oss-security/2017/06/12/2" adv="1" patch="1">http://www.openwall.com/lists/oss-security/2017/06/12/2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99121" adv="1">99121</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3295">RHSA-2017:3295</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3315">RHSA-2017:3315</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3322">RHSA-2017:3322</ref>
      <ref source="MISC" url="https://github.com/torvalds/linux/commit/ba3021b2c79b2fa9114f92790a99deb27a65b728" adv="1" patch="1">https://github.com/torvalds/linux/commit/ba3021b2c79b2fa9114f92790a99deb27a65b728</ref>
      <ref source="MISC" url="https://github.com/torvalds/linux/commit/d11662f4f798b50d8c8743f433842c3e40fe3378" adv="1" patch="1">https://github.com/torvalds/linux/commit/d11662f4f798b50d8c8743f433842c3e40fe3378</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000381" seq="2017-1000381" published="2017-07-07" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99148" adv="1">99148</ref>
      <ref source="CONFIRM" url="https://c-ares.haxx.se/0616.patch" adv="1">https://c-ares.haxx.se/0616.patch</ref>
      <ref source="CONFIRM" url="https://c-ares.haxx.se/adv_20170620.html" adv="1">https://c-ares.haxx.se/adv_20170620.html</ref>
    </refs>
    <vuln_soft>
      <prod name="c-ares" vendor="c-ares_project">
        <vers num="1.8.0"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.10.0"/>
        <vers num="1.11.0" edition="rc1"/>
        <vers num="1.12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000382" seq="2017-1000382" published="2017-10-31" modified="2017-11-27" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://security.cucumberlinux.com/security/details.php?id=120" adv="1">http://security.cucumberlinux.com/security/details.php?id=120</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/10/31/1" adv="1">[oss-security] 20171031 Fw: Security risk of vim swap files</ref>
    </refs>
    <vuln_soft>
      <prod name="vim" vendor="vim">
        <vers num="8.0.1187" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000383" seq="2017-1000383" published="2017-10-31" modified="2017-11-27" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/10/31/1" adv="1">[oss-security] 20171031 Fw: Security risk of vim swap files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101671" adv="1">101671</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="25.3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000384" seq="2017-1000384" published="2017-12-15" modified="2017-12-15" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-16355. Reason: This candidate is a reservation duplicate of CVE-2017-16355. Notes: All CVE users should reference CVE-2017-16355 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000385" seq="2017-1000385" published="2017-12-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of the Bleichenbacher attack).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://erlang.org/pipermail/erlang-questions/2017-November/094255.html" adv="1">[erlang-questions] 20171123 Patch Package: OTP 20.1.7</ref>
      <ref source="MLIST" url="http://erlang.org/pipermail/erlang-questions/2017-November/094256.html" adv="1">[erlang-questions] 20171123 Patch Package: OTP 19.3.6.4</ref>
      <ref source="MLIST" url="http://erlang.org/pipermail/erlang-questions/2017-November/094257.html" adv="1">[erlang-questions] 20171123 Patch Package: OTP 18.3.4.7</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102197" adv="1">102197</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0242">RHSA-2018:0242</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0303">RHSA-2018:0303</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0368">RHSA-2018:0368</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0528">RHSA-2018:0528</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/12/msg00010.html">[debian-lts-announce] 20171215 [SECURITY] [DLA 1207-1] erlang security update</ref>
      <ref source="MISC" url="https://robotattack.org/" adv="1">https://robotattack.org/</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3571-1/">USN-3571-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4057" adv="1">DSA-4057</ref>
      <ref source="CERT-VN" url="https://www.kb.cert.org/vuls/id/144389" adv="1">VU#144389</ref>
    </refs>
    <vuln_soft>
      <prod name="erlang/otp" vendor="erlang">
        <vers num="18.3.4.7"/>
        <vers num="19.3.6.4"/>
        <vers num="20.1.7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000386" seq="2017-1000386" published="2018-01-25" modified="2019-06-11" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference Parameter' type. This could include, for example, arbitrary JavaScript. Active Choices now sanitizes the HTML inserted on the 'Build With Parameters' page if and only if the script is executed in a sandbox. As unsandboxed scripts are subject to administrator approval, it is up to the administrator to allow or disallow problematic script output.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101538" adv="1">101538</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-23/" adv="1">https://jenkins.io/security/advisory/2017-10-23/</ref>
    </refs>
    <vuln_soft>
      <prod name="active_choices" vendor="jenkins">
        <vers num="1.5.2" prev="1" edition=":~~~jenkins~~"/>
        <vers num="1.5.3" edition="-"/>
        <vers num="1.5.3" edition="alpha:~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000387" seq="2017-1000387" published="2018-01-25" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them. Additionally, the credentials were also transmitted in plain text as part of the configuration form. This could result in exposure of the credentials through browser extensions, cross-site scripting vulnerabilities, and similar situations.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101544" adv="1">101544</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-23/" adv="1">https://jenkins.io/security/advisory/2017-10-23/</ref>
    </refs>
    <vuln_soft>
      <prod name="build-publisher" vendor="jenkins">
        <vers num="1.21" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000388" seq="2017-1000388" published="2018-01-25" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-23/" adv="1">https://jenkins.io/security/advisory/2017-10-23/</ref>
    </refs>
    <vuln_soft>
      <prod name="dependency_graph_viewer" vendor="jenkins">
        <vers num="0.12" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000389" seq="2017-1000389" published="2018-01-25" modified="2018-02-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability. Additionally, some URLs provided by global-build-stats plugin that modify data did not require POST requests to be sent, resulting in a potential cross-site request forgery vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-23/" adv="1">https://jenkins.io/security/advisory/2017-10-23/</ref>
    </refs>
    <vuln_soft>
      <prod name="global-build-stats" vendor="jenkins">
        <vers num="1.4" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000390" seq="2017-1000390" published="2018-01-25" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102824" adv="1">102824</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-23/" adv="1">https://jenkins.io/security/advisory/2017-10-23/</ref>
    </refs>
    <vuln_soft>
      <prod name="multijob" vendor="jenkins">
        <vers num="1.25" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000391" seq="2017-1000391" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101773" adv="1">101773</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-11-08/" adv="1">https://jenkins.io/security/advisory/2017-11-08/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.2" prev="1" edition=":~~lts~~~"/>
        <vers num="2.88" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000392" seq="2017-1000392" published="2018-01-25" modified="2019-05-08" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101773" adv="1">101773</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102826" adv="1">102826</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-11-08/" adv="1">https://jenkins.io/security/advisory/2017-11-08/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.2" prev="1" edition=":~~lts~~~"/>
        <vers num="2.88" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000393" seq="2017-1000393" published="2018-01-25" modified="2019-05-08" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'. This allowed them to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of this launch method now requires the Run Scripts permission typically only granted to administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000394" seq="2017-1000394" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000395" seq="2017-1000395" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses if the Mailer Plugin is installed. The remote API now no longer includes information beyond the most basic (user ID and name) unless the user requesting it is a Jenkins administrator.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000396" seq="2017-1000396" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive dependency in Jenkins plugins. The fix for CVE-2012-6153 was backported to the version of commons-httpclient that is bundled in core and made available to plugins.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000397" seq="2017-1000397" published="2018-01-25" modified="2018-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="maven" vendor="jenkins">
        <vers num="2.17" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000398" seq="2017-1000398" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only shows information about accessible tasks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000399" seq="2017-1000399" published="2018-01-25" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10004" seq="2017-10004" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99843" adv="1">99843</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000400" seq="2017-1000400" published="2018-01-25" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000401" seq="2017-1000401" published="2018-01-25" modified="2019-05-08" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, &lt;f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for &lt;f:password/> is now always sent via POST, which is typically not logged.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.73.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.83" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000402" seq="2017-1000402" published="2018-01-25" modified="2018-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="swarm" vendor="jenkins">
        <vers num="3.4" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000403" seq="2017-1000403" published="2018-01-25" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-10-11/" adv="1">https://jenkins.io/security/advisory/2017-10-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="speaks!" vendor="jenkins">
        <vers num="0.1.1" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000404" seq="2017-1000404" published="2018-01-25" modified="2018-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101927" adv="1">101927</ref>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-11-16/" adv="1">https://jenkins.io/security/advisory/2017-11-16/</ref>
    </refs>
    <vuln_soft>
      <prod name="delivery_pipeline" vendor="jenkins">
        <vers num="1.0.7" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000405" seq="2017-1000405" published="2017-11-30" modified="2018-02-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102032" adv="1">102032</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040020">1040020</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0180">RHSA-2018:0180</ref>
      <ref source="MISC" url="https://medium.com/bindecy/huge-dirty-cow-cve-2017-1000405-110eca132de0" adv="1">https://medium.com/bindecy/huge-dirty-cow-cve-2017-1000405-110eca132de0</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-02-01">https://source.android.com/security/bulletin/pixel/2018-02-01</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43199/" adv="1">43199</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.38.1"/>
        <vers num="2.6.38.2"/>
        <vers num="2.6.38.3"/>
        <vers num="2.6.38.4"/>
        <vers num="2.6.38.5"/>
        <vers num="2.6.38.6"/>
        <vers num="2.6.38.7"/>
        <vers num="2.6.38.8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.39.1"/>
        <vers num="2.6.39.2"/>
        <vers num="2.6.39.3"/>
        <vers num="2.6.39.4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.69"/>
        <vers num="3.0.70"/>
        <vers num="3.0.71"/>
        <vers num="3.0.72"/>
        <vers num="3.0.73"/>
        <vers num="3.0.74"/>
        <vers num="3.0.75"/>
        <vers num="3.0.76"/>
        <vers num="3.0.77"/>
        <vers num="3.0.78"/>
        <vers num="3.0.79"/>
        <vers num="3.0.80"/>
        <vers num="3.0.81"/>
        <vers num="3.0.82"/>
        <vers num="3.0.83"/>
        <vers num="3.0.84"/>
        <vers num="3.0.85"/>
        <vers num="3.0.86"/>
        <vers num="3.0.87"/>
        <vers num="3.0.88"/>
        <vers num="3.0.89"/>
        <vers num="3.0.90"/>
        <vers num="3.0.91"/>
        <vers num="3.0.92"/>
        <vers num="3.0.93"/>
        <vers num="3.0.94"/>
        <vers num="3.0.95"/>
        <vers num="3.0.96"/>
        <vers num="3.0.97"/>
        <vers num="3.0.98"/>
        <vers num="3.0.99"/>
        <vers num="3.0.100"/>
        <vers num="3.0.101"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.1.10"/>
        <vers num="3.2" edition=":~~~~x86~"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.30"/>
        <vers num="3.2.64"/>
        <vers num="3.2.65"/>
        <vers num="3.2.66"/>
        <vers num="3.2.67"/>
        <vers num="3.2.68"/>
        <vers num="3.2.69"/>
        <vers num="3.2.70"/>
        <vers num="3.2.71"/>
        <vers num="3.2.72"/>
        <vers num="3.2.73"/>
        <vers num="3.2.74"/>
        <vers num="3.2.75"/>
        <vers num="3.2.76"/>
        <vers num="3.2.77"/>
        <vers num="3.2.78"/>
        <vers num="3.2.79"/>
        <vers num="3.2.80"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition=":~~~~x86~"/>
        <vers num="3.4" edition="rc1:~~~~x86~"/>
        <vers num="3.4" edition="rc2:~~~~x86~"/>
        <vers num="3.4" edition="rc3:~~~~x86~"/>
        <vers num="3.4" edition="rc4:~~~~x86~"/>
        <vers num="3.4" edition="rc5:~~~~x86~"/>
        <vers num="3.4" edition="rc6:~~~~x86~"/>
        <vers num="3.4" edition="rc7:~~~~x86~"/>
        <vers num="3.4.1" edition=":~~~~x86~"/>
        <vers num="3.4.2" edition=":~~~~x86~"/>
        <vers num="3.4.3" edition=":~~~~x86~"/>
        <vers num="3.4.4" edition=":~~~~x86~"/>
        <vers num="3.4.5" edition=":~~~~x86~"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.33"/>
        <vers num="3.4.34"/>
        <vers num="3.4.35"/>
        <vers num="3.4.36"/>
        <vers num="3.4.37"/>
        <vers num="3.4.38"/>
        <vers num="3.4.39"/>
        <vers num="3.4.40"/>
        <vers num="3.4.41"/>
        <vers num="3.4.42"/>
        <vers num="3.4.43"/>
        <vers num="3.4.44"/>
        <vers num="3.4.45"/>
        <vers num="3.4.46"/>
        <vers num="3.4.47"/>
        <vers num="3.4.48"/>
        <vers num="3.4.49"/>
        <vers num="3.4.50"/>
        <vers num="3.4.51"/>
        <vers num="3.4.52"/>
        <vers num="3.4.53"/>
        <vers num="3.4.54"/>
        <vers num="3.4.55"/>
        <vers num="3.4.56"/>
        <vers num="3.4.57"/>
        <vers num="3.4.58"/>
        <vers num="3.4.59"/>
        <vers num="3.4.60"/>
        <vers num="3.4.61"/>
        <vers num="3.4.62"/>
        <vers num="3.4.63"/>
        <vers num="3.4.64"/>
        <vers num="3.4.65"/>
        <vers num="3.4.66"/>
        <vers num="3.4.67"/>
        <vers num="3.4.68"/>
        <vers num="3.4.69"/>
        <vers num="3.4.70"/>
        <vers num="3.4.71"/>
        <vers num="3.4.72"/>
        <vers num="3.4.73"/>
        <vers num="3.4.74"/>
        <vers num="3.4.75"/>
        <vers num="3.4.76"/>
        <vers num="3.4.77"/>
        <vers num="3.4.78"/>
        <vers num="3.4.79"/>
        <vers num="3.4.80"/>
        <vers num="3.4.81"/>
        <vers num="3.4.82"/>
        <vers num="3.4.83"/>
        <vers num="3.4.84"/>
        <vers num="3.4.85"/>
        <vers num="3.4.86"/>
        <vers num="3.4.87"/>
        <vers num="3.4.88"/>
        <vers num="3.4.89"/>
        <vers num="3.4.90"/>
        <vers num="3.4.91"/>
        <vers num="3.4.92"/>
        <vers num="3.4.93"/>
        <vers num="3.4.94"/>
        <vers num="3.4.95"/>
        <vers num="3.4.96"/>
        <vers num="3.4.97"/>
        <vers num="3.4.98"/>
        <vers num="3.4.99"/>
        <vers num="3.4.100"/>
        <vers num="3.4.101"/>
        <vers num="3.4.102"/>
        <vers num="3.4.103"/>
        <vers num="3.4.104"/>
        <vers num="3.4.105"/>
        <vers num="3.4.106"/>
        <vers num="3.4.107"/>
        <vers num="3.4.108"/>
        <vers num="3.4.109"/>
        <vers num="3.4.110"/>
        <vers num="3.4.111"/>
        <vers num="3.4.112"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6" edition="rc5"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.8"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9" edition="rc3"/>
        <vers num="3.9" edition="rc4"/>
        <vers num="3.9" edition="rc5"/>
        <vers num="3.9" edition="rc6"/>
        <vers num="3.9" edition="rc7"/>
        <vers num="3.9.0" edition=":~~~~arm64~"/>
        <vers num="3.9.1" edition=":~~~~arm64~"/>
        <vers num="3.9.2" edition=":~~~~arm64~"/>
        <vers num="3.9.3" edition=":~~~~arm64~"/>
        <vers num="3.9.4" edition=":~~~~arm64~"/>
        <vers num="3.9.5" edition=":~~~~arm64~"/>
        <vers num="3.9.6" edition=":~~~~arm64~"/>
        <vers num="3.9.7" edition=":~~~~arm64~"/>
        <vers num="3.9.8" edition=":~~~~arm64~"/>
        <vers num="3.9.9" edition=":~~~~arm64~"/>
        <vers num="3.9.10" edition=":~~~~arm64~"/>
        <vers num="3.9.11" edition=":~~~~arm64~"/>
        <vers num="3.10"/>
        <vers num="3.10.0" edition=":~~~~arm64~"/>
        <vers num="3.10.1" edition=":~~~~arm64~"/>
        <vers num="3.10.2" edition=":~~~~arm64~"/>
        <vers num="3.10.3" edition=":~~~~arm64~"/>
        <vers num="3.10.4" edition=":~~~~arm64~"/>
        <vers num="3.10.5" edition=":~~~~arm64~"/>
        <vers num="3.10.6" edition=":~~~~arm64~"/>
        <vers num="3.10.7" edition=":~~~~arm64~"/>
        <vers num="3.10.8" edition=":~~~~arm64~"/>
        <vers num="3.10.9" edition=":~~~~arm64~"/>
        <vers num="3.10.10"/>
        <vers num="3.10.11"/>
        <vers num="3.10.12"/>
        <vers num="3.10.13"/>
        <vers num="3.10.14"/>
        <vers num="3.10.15"/>
        <vers num="3.10.16"/>
        <vers num="3.10.17"/>
        <vers num="3.10.18"/>
        <vers num="3.10.19"/>
        <vers num="3.10.20"/>
        <vers num="3.10.21"/>
        <vers num="3.10.22"/>
        <vers num="3.10.23"/>
        <vers num="3.10.24"/>
        <vers num="3.10.25"/>
        <vers num="3.10.26"/>
        <vers num="3.10.27"/>
        <vers num="3.10.28"/>
        <vers num="3.10.29"/>
        <vers num="3.10.30"/>
        <vers num="3.10.31"/>
        <vers num="3.10.32"/>
        <vers num="3.10.33"/>
        <vers num="3.10.34"/>
        <vers num="3.10.35"/>
        <vers num="3.10.36"/>
        <vers num="3.10.37"/>
        <vers num="3.10.38"/>
        <vers num="3.10.39"/>
        <vers num="3.10.40"/>
        <vers num="3.10.41"/>
        <vers num="3.10.42"/>
        <vers num="3.10.43"/>
        <vers num="3.10.44"/>
        <vers num="3.10.45"/>
        <vers num="3.10.46"/>
        <vers num="3.10.47"/>
        <vers num="3.10.48"/>
        <vers num="3.10.49"/>
        <vers num="3.10.50"/>
        <vers num="3.10.51"/>
        <vers num="3.10.52"/>
        <vers num="3.10.53"/>
        <vers num="3.10.54"/>
        <vers num="3.10.55"/>
        <vers num="3.10.56"/>
        <vers num="3.10.57"/>
        <vers num="3.10.58"/>
        <vers num="3.10.59"/>
        <vers num="3.10.60"/>
        <vers num="3.10.61"/>
        <vers num="3.10.62"/>
        <vers num="3.10.63"/>
        <vers num="3.10.64"/>
        <vers num="3.10.65"/>
        <vers num="3.10.66"/>
        <vers num="3.10.67"/>
        <vers num="3.10.68"/>
        <vers num="3.10.69"/>
        <vers num="3.10.70"/>
        <vers num="3.10.71"/>
        <vers num="3.10.72"/>
        <vers num="3.10.73"/>
        <vers num="3.10.74"/>
        <vers num="3.10.75"/>
        <vers num="3.10.76"/>
        <vers num="3.10.77"/>
        <vers num="3.10.78"/>
        <vers num="3.10.79"/>
        <vers num="3.10.80"/>
        <vers num="3.10.81"/>
        <vers num="3.10.82"/>
        <vers num="3.10.83"/>
        <vers num="3.10.84"/>
        <vers num="3.10.85"/>
        <vers num="3.10.86"/>
        <vers num="3.10.87"/>
        <vers num="3.10.88"/>
        <vers num="3.10.89"/>
        <vers num="3.10.90"/>
        <vers num="3.10.91"/>
        <vers num="3.10.92"/>
        <vers num="3.10.93"/>
        <vers num="3.10.94"/>
        <vers num="3.10.95"/>
        <vers num="3.10.96"/>
        <vers num="3.10.97"/>
        <vers num="3.10.98"/>
        <vers num="3.10.99"/>
        <vers num="3.10.100"/>
        <vers num="3.10.101"/>
        <vers num="3.10.102"/>
        <vers num="3.11"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.8"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.8"/>
        <vers num="3.12.9"/>
        <vers num="3.12.10"/>
        <vers num="3.12.11"/>
        <vers num="3.12.12"/>
        <vers num="3.12.13"/>
        <vers num="3.12.14"/>
        <vers num="3.12.15"/>
        <vers num="3.12.16"/>
        <vers num="3.12.17"/>
        <vers num="3.12.18"/>
        <vers num="3.12.19"/>
        <vers num="3.12.20"/>
        <vers num="3.12.21"/>
        <vers num="3.12.22"/>
        <vers num="3.12.23"/>
        <vers num="3.12.24"/>
        <vers num="3.12.25"/>
        <vers num="3.12.26"/>
        <vers num="3.12.27"/>
        <vers num="3.12.28"/>
        <vers num="3.12.29"/>
        <vers num="3.12.30"/>
        <vers num="3.12.31"/>
        <vers num="3.12.32"/>
        <vers num="3.12.33"/>
        <vers num="3.12.34"/>
        <vers num="3.12.35"/>
        <vers num="3.12.36"/>
        <vers num="3.12.37"/>
        <vers num="3.12.38"/>
        <vers num="3.12.39"/>
        <vers num="3.12.40"/>
        <vers num="3.12.41"/>
        <vers num="3.12.42"/>
        <vers num="3.12.43"/>
        <vers num="3.12.44"/>
        <vers num="3.12.45"/>
        <vers num="3.12.46"/>
        <vers num="3.12.47"/>
        <vers num="3.12.48"/>
        <vers num="3.12.49"/>
        <vers num="3.12.50"/>
        <vers num="3.12.51"/>
        <vers num="3.12.52"/>
        <vers num="3.12.53"/>
        <vers num="3.12.54"/>
        <vers num="3.12.55"/>
        <vers num="3.12.56"/>
        <vers num="3.12.57"/>
        <vers num="3.12.58"/>
        <vers num="3.12.59"/>
        <vers num="3.13"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.4"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.8"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.13.11"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="rc1"/>
        <vers num="3.14" edition="rc2"/>
        <vers num="3.14" edition="rc3"/>
        <vers num="3.14" edition="rc4"/>
        <vers num="3.14" edition="rc5"/>
        <vers num="3.14" edition="rc6"/>
        <vers num="3.14" edition="rc7"/>
        <vers num="3.14" edition="rc8"/>
        <vers num="3.14.1"/>
        <vers num="3.14.2"/>
        <vers num="3.14.3"/>
        <vers num="3.14.4"/>
        <vers num="3.14.5"/>
        <vers num="3.14.8"/>
        <vers num="3.14.10"/>
        <vers num="3.14.11"/>
        <vers num="3.14.12"/>
        <vers num="3.14.13"/>
        <vers num="3.14.14"/>
        <vers num="3.14.15"/>
        <vers num="3.14.16"/>
        <vers num="3.14.17"/>
        <vers num="3.14.18"/>
        <vers num="3.14.19"/>
        <vers num="3.14.20"/>
        <vers num="3.14.21"/>
        <vers num="3.14.22"/>
        <vers num="3.14.23"/>
        <vers num="3.14.24"/>
        <vers num="3.14.25"/>
        <vers num="3.14.26"/>
        <vers num="3.14.27"/>
        <vers num="3.14.28"/>
        <vers num="3.14.29"/>
        <vers num="3.14.30"/>
        <vers num="3.14.31"/>
        <vers num="3.14.32"/>
        <vers num="3.14.33"/>
        <vers num="3.14.34"/>
        <vers num="3.14.35"/>
        <vers num="3.14.36"/>
        <vers num="3.14.37"/>
        <vers num="3.14.38"/>
        <vers num="3.14.39"/>
        <vers num="3.14.40"/>
        <vers num="3.14.41"/>
        <vers num="3.14.42"/>
        <vers num="3.14.43"/>
        <vers num="3.14.44"/>
        <vers num="3.14.45"/>
        <vers num="3.14.46"/>
        <vers num="3.14.47"/>
        <vers num="3.14.48"/>
        <vers num="3.14.49"/>
        <vers num="3.14.50"/>
        <vers num="3.14.51"/>
        <vers num="3.14.52"/>
        <vers num="3.14.53"/>
        <vers num="3.14.54"/>
        <vers num="3.14.55"/>
        <vers num="3.14.56"/>
        <vers num="3.14.57"/>
        <vers num="3.14.58"/>
        <vers num="3.14.59"/>
        <vers num="3.14.60"/>
        <vers num="3.14.61"/>
        <vers num="3.14.62"/>
        <vers num="3.14.63"/>
        <vers num="3.14.64"/>
        <vers num="3.14.65"/>
        <vers num="3.14.66"/>
        <vers num="3.14.67"/>
        <vers num="3.14.68"/>
        <vers num="3.14.79"/>
        <vers num="3.15" edition="rc4"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
        <vers num="3.15.4"/>
        <vers num="3.15.5"/>
        <vers num="3.15.6"/>
        <vers num="3.15.7"/>
        <vers num="3.15.8"/>
        <vers num="3.15.10"/>
        <vers num="3.16"/>
        <vers num="3.16.0"/>
        <vers num="3.16.1"/>
        <vers num="3.16.4"/>
        <vers num="3.16.5"/>
        <vers num="3.16.6"/>
        <vers num="3.16.7"/>
        <vers num="3.17"/>
        <vers num="3.17.3" edition=":~~~~arm64~"/>
        <vers num="3.17.5"/>
        <vers num="3.17.6"/>
        <vers num="3.17.7"/>
        <vers num="3.17.8"/>
        <vers num="3.18"/>
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.10"/>
        <vers num="3.18.11"/>
        <vers num="3.18.12"/>
        <vers num="3.18.13"/>
        <vers num="3.18.14"/>
        <vers num="3.18.15"/>
        <vers num="3.18.16"/>
        <vers num="3.18.17"/>
        <vers num="3.18.18"/>
        <vers num="3.18.19"/>
        <vers num="3.18.20"/>
        <vers num="3.18.21"/>
        <vers num="3.18.22"/>
        <vers num="3.18.23"/>
        <vers num="3.18.24"/>
        <vers num="3.18.25"/>
        <vers num="3.18.26"/>
        <vers num="3.18.27"/>
        <vers num="3.18.28"/>
        <vers num="3.18.29"/>
        <vers num="3.18.30"/>
        <vers num="3.18.31"/>
        <vers num="3.18.32"/>
        <vers num="3.18.33"/>
        <vers num="3.18.34"/>
        <vers num="3.18.35"/>
        <vers num="3.18.36"/>
        <vers num="3.18.37"/>
        <vers num="3.18.38"/>
        <vers num="3.18.39"/>
        <vers num="3.18.40"/>
        <vers num="3.18.41"/>
        <vers num="3.18.42"/>
        <vers num="3.18.43"/>
        <vers num="3.18.44"/>
        <vers num="3.18.45"/>
        <vers num="3.18.46"/>
        <vers num="3.18.47"/>
        <vers num="3.18.48"/>
        <vers num="3.18.49"/>
        <vers num="3.18.50"/>
        <vers num="3.18.51"/>
        <vers num="3.18.52"/>
        <vers num="3.18.53"/>
        <vers num="3.18.54"/>
        <vers num="3.18.55"/>
        <vers num="3.18.56"/>
        <vers num="3.18.57"/>
        <vers num="3.18.58"/>
        <vers num="3.18.59"/>
        <vers num="3.18.60"/>
        <vers num="3.18.61"/>
        <vers num="3.18.62"/>
        <vers num="3.18.63"/>
        <vers num="3.18.64"/>
        <vers num="3.18.65"/>
        <vers num="3.18.66"/>
        <vers num="3.19"/>
        <vers num="3.19.1"/>
        <vers num="3.19.2"/>
        <vers num="3.19.3"/>
        <vers num="3.19.4"/>
        <vers num="3.19.5"/>
        <vers num="3.19.6"/>
        <vers num="3.19.7"/>
        <vers num="3.19.8"/>
        <vers num="4"/>
        <vers num="4.0" edition="rc5"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.1" edition="rc2"/>
        <vers num="4.1" edition="rc3"/>
        <vers num="4.1" edition="rc4"/>
        <vers num="4.1" edition="rc5"/>
        <vers num="4.1" edition="rc6"/>
        <vers num="4.1" edition="rc7"/>
        <vers num="4.1" edition="rc8"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.1.27"/>
        <vers num="4.1.28"/>
        <vers num="4.1.29"/>
        <vers num="4.1.30"/>
        <vers num="4.1.31"/>
        <vers num="4.1.32"/>
        <vers num="4.1.33"/>
        <vers num="4.1.34"/>
        <vers num="4.1.35"/>
        <vers num="4.1.36"/>
        <vers num="4.1.37"/>
        <vers num="4.1.38"/>
        <vers num="4.1.39"/>
        <vers num="4.1.40"/>
        <vers num="4.1.41"/>
        <vers num="4.1.42"/>
        <vers num="4.1.43"/>
        <vers num="4.1.44"/>
        <vers num="4.1.45"/>
        <vers num="4.1.46"/>
        <vers num="4.1.47"/>
        <vers num="4.1.48"/>
        <vers num="4.1.49"/>
        <vers num="4.1.50"/>
        <vers num="4.1.51"/>
        <vers num="4.1.52"/>
        <vers num="4.2" edition="rc1"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc3"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.2" edition="rc6"/>
        <vers num="4.2" edition="rc7"/>
        <vers num="4.2" edition="rc8"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.3" edition="rc1"/>
        <vers num="4.3" edition="rc2"/>
        <vers num="4.3" edition="rc3"/>
        <vers num="4.3" edition="rc4"/>
        <vers num="4.3" edition="rc5"/>
        <vers num="4.3" edition="rc6"/>
        <vers num="4.3" edition="rc7"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4" edition="rc8"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.4.19"/>
        <vers num="4.4.20"/>
        <vers num="4.4.21"/>
        <vers num="4.4.22"/>
        <vers num="4.4.23"/>
        <vers num="4.4.24"/>
        <vers num="4.4.25"/>
        <vers num="4.4.26"/>
        <vers num="4.4.27"/>
        <vers num="4.4.28"/>
        <vers num="4.4.29"/>
        <vers num="4.4.30"/>
        <vers num="4.4.31"/>
        <vers num="4.4.32"/>
        <vers num="4.4.33"/>
        <vers num="4.4.34"/>
        <vers num="4.4.35"/>
        <vers num="4.4.36"/>
        <vers num="4.4.37"/>
        <vers num="4.4.38"/>
        <vers num="4.4.39"/>
        <vers num="4.4.40"/>
        <vers num="4.4.41"/>
        <vers num="4.4.42"/>
        <vers num="4.4.43"/>
        <vers num="4.4.44"/>
        <vers num="4.4.45"/>
        <vers num="4.4.46"/>
        <vers num="4.4.47"/>
        <vers num="4.4.48"/>
        <vers num="4.4.49"/>
        <vers num="4.4.50"/>
        <vers num="4.4.51"/>
        <vers num="4.4.52"/>
        <vers num="4.4.53"/>
        <vers num="4.4.54"/>
        <vers num="4.4.55"/>
        <vers num="4.4.56"/>
        <vers num="4.4.57"/>
        <vers num="4.4.58"/>
        <vers num="4.4.59"/>
        <vers num="4.4.60"/>
        <vers num="4.4.61"/>
        <vers num="4.4.62"/>
        <vers num="4.4.63"/>
        <vers num="4.4.64"/>
        <vers num="4.4.65"/>
        <vers num="4.4.66"/>
        <vers num="4.4.67"/>
        <vers num="4.4.68"/>
        <vers num="4.4.69"/>
        <vers num="4.4.70"/>
        <vers num="4.4.71"/>
        <vers num="4.4.72"/>
        <vers num="4.4.73"/>
        <vers num="4.4.74"/>
        <vers num="4.4.75"/>
        <vers num="4.4.76"/>
        <vers num="4.4.77"/>
        <vers num="4.4.78"/>
        <vers num="4.4.79"/>
        <vers num="4.4.80"/>
        <vers num="4.4.81"/>
        <vers num="4.4.82"/>
        <vers num="4.4.83"/>
        <vers num="4.4.84"/>
        <vers num="4.4.85"/>
        <vers num="4.4.86"/>
        <vers num="4.4.87"/>
        <vers num="4.4.88"/>
        <vers num="4.4.89"/>
        <vers num="4.4.90"/>
        <vers num="4.4.91"/>
        <vers num="4.4.92"/>
        <vers num="4.4.93"/>
        <vers num="4.4.94"/>
        <vers num="4.4.95"/>
        <vers num="4.4.96"/>
        <vers num="4.4.97"/>
        <vers num="4.4.98"/>
        <vers num="4.4.99"/>
        <vers num="4.4.100"/>
        <vers num="4.4.101"/>
        <vers num="4.4.102"/>
        <vers num="4.4.103"/>
        <vers num="4.4.104"/>
        <vers num="4.4.105"/>
        <vers num="4.4.106"/>
        <vers num="4.4.107"/>
        <vers num="4.4.108"/>
        <vers num="4.4.109"/>
        <vers num="4.4.110"/>
        <vers num="4.4.111"/>
        <vers num="4.4.112"/>
        <vers num="4.4.113"/>
        <vers num="4.4.114"/>
        <vers num="4.4.115"/>
        <vers num="4.4.116"/>
        <vers num="4.4.117"/>
        <vers num="4.4.118"/>
        <vers num="4.4.119"/>
        <vers num="4.4.120"/>
        <vers num="4.4.121"/>
        <vers num="4.4.122"/>
        <vers num="4.4.123"/>
        <vers num="4.4.124"/>
        <vers num="4.4.125"/>
        <vers num="4.4.126"/>
        <vers num="4.4.127"/>
        <vers num="4.4.128"/>
        <vers num="4.4.129"/>
        <vers num="4.4.130"/>
        <vers num="4.4.131"/>
        <vers num="4.4.132"/>
        <vers num="4.4.133"/>
        <vers num="4.4.134"/>
        <vers num="4.4.135"/>
        <vers num="4.4.136"/>
        <vers num="4.4.137"/>
        <vers num="4.4.138"/>
        <vers num="4.4.139"/>
        <vers num="4.4.140"/>
        <vers num="4.4.141"/>
        <vers num="4.4.142"/>
        <vers num="4.4.143"/>
        <vers num="4.4.144"/>
        <vers num="4.4.145"/>
        <vers num="4.4.146"/>
        <vers num="4.4.147"/>
        <vers num="4.4.148"/>
        <vers num="4.4.149"/>
        <vers num="4.4.150"/>
        <vers num="4.4.151"/>
        <vers num="4.4.152"/>
        <vers num="4.4.153"/>
        <vers num="4.4.154"/>
        <vers num="4.4.155"/>
        <vers num="4.4.156"/>
        <vers num="4.4.157"/>
        <vers num="4.4.158"/>
        <vers num="4.4.159"/>
        <vers num="4.4.160"/>
        <vers num="4.4.161"/>
        <vers num="4.4.162"/>
        <vers num="4.4.163"/>
        <vers num="4.4.164"/>
        <vers num="4.4.165"/>
        <vers num="4.4.166"/>
        <vers num="4.4.167"/>
        <vers num="4.4.168"/>
        <vers num="4.4.169"/>
        <vers num="4.4.170"/>
        <vers num="4.4.171"/>
        <vers num="4.4.172"/>
        <vers num="4.4.173"/>
        <vers num="4.4.174"/>
        <vers num="4.4.175"/>
        <vers num="4.4.176"/>
        <vers num="4.4.177"/>
        <vers num="4.4.178"/>
        <vers num="4.4.179"/>
        <vers num="4.4.180"/>
        <vers num="4.4.181"/>
        <vers num="4.4.182"/>
        <vers num="4.4.183"/>
        <vers num="4.4.184"/>
        <vers num="4.4.185"/>
        <vers num="4.4.186"/>
        <vers num="4.4.187"/>
        <vers num="4.4.188"/>
        <vers num="4.4.189"/>
        <vers num="4.4.190"/>
        <vers num="4.5" edition="rc3"/>
        <vers num="4.5" edition="rc4"/>
        <vers num="4.5.0" edition="rc7"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.7" edition="rc1"/>
        <vers num="4.7" edition="rc2"/>
        <vers num="4.7" edition="rc3"/>
        <vers num="4.7" edition="rc4"/>
        <vers num="4.7" edition="rc5"/>
        <vers num="4.7" edition="rc6"/>
        <vers num="4.7" edition="rc7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7.10"/>
        <vers num="4.8" edition="rc5"/>
        <vers num="4.8" edition="rc6"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="4.8.10"/>
        <vers num="4.8.11"/>
        <vers num="4.8.12"/>
        <vers num="4.8.13"/>
        <vers num="4.8.14"/>
        <vers num="4.8.15"/>
        <vers num="4.8.16"/>
        <vers num="4.8.17"/>
        <vers num="4.9" edition="rc1"/>
        <vers num="4.9" edition="rc2"/>
        <vers num="4.9" edition="rc3"/>
        <vers num="4.9" edition="rc4"/>
        <vers num="4.9" edition="rc5"/>
        <vers num="4.9" edition="rc6"/>
        <vers num="4.9" edition="rc7"/>
        <vers num="4.9" edition="rc8"/>
        <vers num="4.9.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
        <vers num="4.9.13"/>
        <vers num="4.9.14"/>
        <vers num="4.9.15"/>
        <vers num="4.9.16"/>
        <vers num="4.9.17"/>
        <vers num="4.9.18"/>
        <vers num="4.9.19"/>
        <vers num="4.9.20"/>
        <vers num="4.9.21"/>
        <vers num="4.9.22"/>
        <vers num="4.9.23"/>
        <vers num="4.9.24"/>
        <vers num="4.9.25"/>
        <vers num="4.9.26"/>
        <vers num="4.9.27"/>
        <vers num="4.9.28"/>
        <vers num="4.9.29"/>
        <vers num="4.9.30"/>
        <vers num="4.9.31"/>
        <vers num="4.9.32"/>
        <vers num="4.9.33"/>
        <vers num="4.9.34"/>
        <vers num="4.9.35"/>
        <vers num="4.9.36"/>
        <vers num="4.9.37"/>
        <vers num="4.9.38"/>
        <vers num="4.9.39"/>
        <vers num="4.9.40"/>
        <vers num="4.9.41"/>
        <vers num="4.9.42"/>
        <vers num="4.9.43"/>
        <vers num="4.9.44"/>
        <vers num="4.9.45"/>
        <vers num="4.9.46"/>
        <vers num="4.9.47"/>
        <vers num="4.9.48"/>
        <vers num="4.9.49"/>
        <vers num="4.9.50"/>
        <vers num="4.9.51"/>
        <vers num="4.9.52"/>
        <vers num="4.9.53"/>
        <vers num="4.9.54"/>
        <vers num="4.9.55"/>
        <vers num="4.9.56"/>
        <vers num="4.9.57"/>
        <vers num="4.9.58"/>
        <vers num="4.9.59"/>
        <vers num="4.9.60"/>
        <vers num="4.9.61"/>
        <vers num="4.9.62"/>
        <vers num="4.9.63"/>
        <vers num="4.9.64"/>
        <vers num="4.9.65"/>
        <vers num="4.9.66"/>
        <vers num="4.9.67"/>
        <vers num="4.9.68"/>
        <vers num="4.9.69"/>
        <vers num="4.9.70"/>
        <vers num="4.9.71"/>
        <vers num="4.9.72"/>
        <vers num="4.9.73"/>
        <vers num="4.9.74"/>
        <vers num="4.9.75"/>
        <vers num="4.9.76"/>
        <vers num="4.9.77"/>
        <vers num="4.9.78"/>
        <vers num="4.9.79"/>
        <vers num="4.9.80"/>
        <vers num="4.9.81"/>
        <vers num="4.9.82"/>
        <vers num="4.9.83"/>
        <vers num="4.9.84"/>
        <vers num="4.9.85"/>
        <vers num="4.9.86"/>
        <vers num="4.9.87"/>
        <vers num="4.9.88"/>
        <vers num="4.9.89"/>
        <vers num="4.9.90"/>
        <vers num="4.9.91"/>
        <vers num="4.9.92"/>
        <vers num="4.9.93"/>
        <vers num="4.9.94"/>
        <vers num="4.9.95"/>
        <vers num="4.9.96"/>
        <vers num="4.9.97"/>
        <vers num="4.9.98"/>
        <vers num="4.9.99"/>
        <vers num="4.9.100"/>
        <vers num="4.9.101"/>
        <vers num="4.9.102"/>
        <vers num="4.9.103"/>
        <vers num="4.9.104"/>
        <vers num="4.9.105"/>
        <vers num="4.9.106"/>
        <vers num="4.9.107"/>
        <vers num="4.9.108"/>
        <vers num="4.9.109"/>
        <vers num="4.9.110"/>
        <vers num="4.9.111"/>
        <vers num="4.9.112"/>
        <vers num="4.9.113"/>
        <vers num="4.9.114"/>
        <vers num="4.9.115"/>
        <vers num="4.9.116"/>
        <vers num="4.9.117"/>
        <vers num="4.9.118"/>
        <vers num="4.9.119"/>
        <vers num="4.9.120"/>
        <vers num="4.9.121"/>
        <vers num="4.9.122"/>
        <vers num="4.9.123"/>
        <vers num="4.9.124"/>
        <vers num="4.9.125"/>
        <vers num="4.9.126"/>
        <vers num="4.9.127"/>
        <vers num="4.9.128"/>
        <vers num="4.9.129"/>
        <vers num="4.9.130"/>
        <vers num="4.9.131"/>
        <vers num="4.9.132"/>
        <vers num="4.9.133"/>
        <vers num="4.9.134"/>
        <vers num="4.9.135"/>
        <vers num="4.9.136"/>
        <vers num="4.9.137"/>
        <vers num="4.9.138"/>
        <vers num="4.9.139"/>
        <vers num="4.9.140"/>
        <vers num="4.9.141"/>
        <vers num="4.9.142"/>
        <vers num="4.9.143"/>
        <vers num="4.9.144"/>
        <vers num="4.9.145"/>
        <vers num="4.9.146"/>
        <vers num="4.9.147"/>
        <vers num="4.9.148"/>
        <vers num="4.9.149"/>
        <vers num="4.9.150"/>
        <vers num="4.9.151"/>
        <vers num="4.9.152"/>
        <vers num="4.9.153"/>
        <vers num="4.9.154"/>
        <vers num="4.9.155"/>
        <vers num="4.9.156"/>
        <vers num="4.9.157"/>
        <vers num="4.9.158"/>
        <vers num="4.9.159"/>
        <vers num="4.9.160"/>
        <vers num="4.9.161"/>
        <vers num="4.9.162"/>
        <vers num="4.9.163"/>
        <vers num="4.9.164"/>
        <vers num="4.9.165"/>
        <vers num="4.9.166"/>
        <vers num="4.9.167"/>
        <vers num="4.9.168"/>
        <vers num="4.9.169"/>
        <vers num="4.9.170"/>
        <vers num="4.9.171"/>
        <vers num="4.9.172"/>
        <vers num="4.9.173"/>
        <vers num="4.9.174"/>
        <vers num="4.9.175"/>
        <vers num="4.9.176"/>
        <vers num="4.9.177"/>
        <vers num="4.9.178"/>
        <vers num="4.9.179"/>
        <vers num="4.9.180"/>
        <vers num="4.9.181"/>
        <vers num="4.9.182"/>
        <vers num="4.9.183"/>
        <vers num="4.9.184"/>
        <vers num="4.9.185"/>
        <vers num="4.9.186"/>
        <vers num="4.9.187"/>
        <vers num="4.9.188"/>
        <vers num="4.9.189"/>
        <vers num="4.9.190"/>
        <vers num="4.10" edition="rc3"/>
        <vers num="4.10" edition="rc4"/>
        <vers num="4.10.1"/>
        <vers num="4.10.2"/>
        <vers num="4.10.3"/>
        <vers num="4.10.4"/>
        <vers num="4.10.5"/>
        <vers num="4.10.6"/>
        <vers num="4.10.7"/>
        <vers num="4.10.8"/>
        <vers num="4.10.9"/>
        <vers num="4.10.10"/>
        <vers num="4.10.11"/>
        <vers num="4.10.12"/>
        <vers num="4.10.13"/>
        <vers num="4.10.14"/>
        <vers num="4.10.15"/>
        <vers num="4.10.16"/>
        <vers num="4.10.17"/>
        <vers num="4.11" edition="rc1"/>
        <vers num="4.11" edition="rc2"/>
        <vers num="4.11" edition="rc3"/>
        <vers num="4.11" edition="rc4"/>
        <vers num="4.11" edition="rc5"/>
        <vers num="4.11" edition="rc6"/>
        <vers num="4.11" edition="rc7"/>
        <vers num="4.11.1"/>
        <vers num="4.11.2"/>
        <vers num="4.11.3"/>
        <vers num="4.11.4"/>
        <vers num="4.11.5"/>
        <vers num="4.11.6"/>
        <vers num="4.11.7"/>
        <vers num="4.11.8"/>
        <vers num="4.11.9"/>
        <vers num="4.11.10"/>
        <vers num="4.11.11"/>
        <vers num="4.11.12"/>
        <vers num="4.12" edition="rc1"/>
        <vers num="4.12" edition="rc2"/>
        <vers num="4.12" edition="rc3"/>
        <vers num="4.12" edition="rc4"/>
        <vers num="4.12" edition="rc5"/>
        <vers num="4.12" edition="rc6"/>
        <vers num="4.12.1"/>
        <vers num="4.12.2"/>
        <vers num="4.12.3"/>
        <vers num="4.12.4"/>
        <vers num="4.12.5"/>
        <vers num="4.12.6"/>
        <vers num="4.12.7"/>
        <vers num="4.12.8"/>
        <vers num="4.12.9"/>
        <vers num="4.12.10"/>
        <vers num="4.12.11"/>
        <vers num="4.12.12"/>
        <vers num="4.12.13"/>
        <vers num="4.12.14"/>
        <vers num="4.13" edition="rc1"/>
        <vers num="4.13" edition="rc2"/>
        <vers num="4.13" edition="rc3"/>
        <vers num="4.13" edition="rc4"/>
        <vers num="4.13" edition="rc5"/>
        <vers num="4.13" edition="rc6"/>
        <vers num="4.13.1"/>
        <vers num="4.13.2"/>
        <vers num="4.13.3"/>
        <vers num="4.13.4"/>
        <vers num="4.13.5"/>
        <vers num="4.13.6"/>
        <vers num="4.13.7"/>
        <vers num="4.13.8"/>
        <vers num="4.13.9"/>
        <vers num="4.13.10"/>
        <vers num="4.13.11"/>
        <vers num="4.13.12"/>
        <vers num="4.13.13"/>
        <vers num="4.13.14"/>
        <vers num="4.13.15"/>
        <vers num="4.13.16"/>
        <vers num="4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000406" seq="2017-1000406" published="2017-11-30" modified="2017-12-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q4/320" adv="1">[oss-security] 20171123 OpenDayLight: Password change doesn't result in Karaf clearing cache, allowing old password to still be used (CVE-2017-1000406)</ref>
      <ref source="CONFIRM" url="https://git.opendaylight.org/gerrit/#/q/topic:AAA-151" adv="1">https://git.opendaylight.org/gerrit/#/q/topic:AAA-151</ref>
      <ref source="CONFIRM" url="https://jira.opendaylight.org/browse/AAA-151" adv="1">https://jira.opendaylight.org/browse/AAA-151</ref>
    </refs>
    <vuln_soft>
      <prod name="karaf" vendor="opendaylight">
        <vers num="0.6.1-carbon"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000407" seq="2017-1000407" published="2017-12-11" modified="2019-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.1" CVSS_base_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/12/04/2" adv="1" patch="1">[oss-security] 20171204 CVE-2017-1000407 Kernel: KVM: DoS via write flood to I/O port 0x80</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102038" adv="1">102038</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0676" adv="1">RHSA-2018:0676</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1062" adv="1">RHSA-2018:1062</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:1170">RHSA-2019:1170</ref>
      <ref source="CONFIRM" url="https://access.redhat.com/security/cve/cve-2017-1000407" adv="1">https://access.redhat.com/security/cve/cve-2017-1000407</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/12/msg00004.html" adv="1">[debian-lts-announce] 20171210 [SECURITY] [DLA 1200-1] linux security update</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-1/" adv="1">USN-3583-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3583-2/" adv="1">USN-3583-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3617-1/" adv="1">USN-3617-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3617-2/" adv="1">USN-3617-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3619-1/" adv="1">USN-3619-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3619-2/" adv="1">USN-3619-2</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3632-1/" adv="1">USN-3632-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4073" adv="1">DSA-4073</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4082" adv="1">DSA-4082</ref>
      <ref source="MLIST" url="https://www.spinics.net/lists/kvm/msg159809.html" patch="1">[kvm] 20171201 [PATCH 1/2] KVM: VMX: remove I/O port 0x80 bypass on Intel hosts</ref>
    </refs>
    <vuln_soft>
      <prod name="virtualization_host" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="12.04" edition=":~~esm~~~"/>
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.32" edition="rc1"/>
        <vers num="2.6.32" edition="rc2"/>
        <vers num="2.6.32" edition="rc3"/>
        <vers num="2.6.32" edition="rc4"/>
        <vers num="2.6.32" edition="rc5"/>
        <vers num="2.6.32" edition="rc6"/>
        <vers num="2.6.32" edition="rc7"/>
        <vers num="2.6.32" edition="rc8"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.19"/>
        <vers num="2.6.32.20"/>
        <vers num="2.6.32.21"/>
        <vers num="2.6.32.22"/>
        <vers num="2.6.32.23"/>
        <vers num="2.6.32.24"/>
        <vers num="2.6.32.25"/>
        <vers num="2.6.32.26"/>
        <vers num="2.6.32.27"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.33" edition="rc1"/>
        <vers num="2.6.33" edition="rc2"/>
        <vers num="2.6.33" edition="rc3"/>
        <vers num="2.6.33" edition="rc4"/>
        <vers num="2.6.33" edition="rc5"/>
        <vers num="2.6.33" edition="rc6"/>
        <vers num="2.6.33" edition="rc7"/>
        <vers num="2.6.33" edition="rc8"/>
        <vers num="2.6.33.1"/>
        <vers num="2.6.33.2"/>
        <vers num="2.6.33.3"/>
        <vers num="2.6.33.4"/>
        <vers num="2.6.33.5"/>
        <vers num="2.6.33.6"/>
        <vers num="2.6.33.7"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.34" edition="rc1"/>
        <vers num="2.6.34" edition="rc2"/>
        <vers num="2.6.34" edition="rc3"/>
        <vers num="2.6.34" edition="rc4"/>
        <vers num="2.6.34" edition="rc5"/>
        <vers num="2.6.34" edition="rc6"/>
        <vers num="2.6.34" edition="rc7"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.4"/>
        <vers num="2.6.34.5"/>
        <vers num="2.6.34.6"/>
        <vers num="2.6.34.7"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.35" edition="rc1"/>
        <vers num="2.6.35" edition="rc2"/>
        <vers num="2.6.35" edition="rc3"/>
        <vers num="2.6.35" edition="rc4"/>
        <vers num="2.6.35" edition="rc5"/>
        <vers num="2.6.35" edition="rc6"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.2"/>
        <vers num="2.6.35.3"/>
        <vers num="2.6.35.4"/>
        <vers num="2.6.35.5"/>
        <vers num="2.6.35.6"/>
        <vers num="2.6.35.7"/>
        <vers num="2.6.35.8"/>
        <vers num="2.6.35.9"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.36" edition="rc1"/>
        <vers num="2.6.36" edition="rc2"/>
        <vers num="2.6.36" edition="rc3"/>
        <vers num="2.6.36" edition="rc4"/>
        <vers num="2.6.36" edition="rc5"/>
        <vers num="2.6.36" edition="rc6"/>
        <vers num="2.6.36" edition="rc7"/>
        <vers num="2.6.36" edition="rc8"/>
        <vers num="2.6.36.1"/>
        <vers num="2.6.36.2"/>
        <vers num="2.6.36.3"/>
        <vers num="2.6.36.4"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.37" edition="rc6"/>
        <vers num="2.6.37" edition="rc7"/>
        <vers num="2.6.37" edition="rc8"/>
        <vers num="2.6.37.1"/>
        <vers num="2.6.37.2"/>
        <vers num="2.6.37.3"/>
        <vers num="2.6.37.4"/>
        <vers num="2.6.37.5"/>
        <vers num="2.6.37.6"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.38.1"/>
        <vers num="2.6.38.2"/>
        <vers num="2.6.38.3"/>
        <vers num="2.6.38.4"/>
        <vers num="2.6.38.5"/>
        <vers num="2.6.38.6"/>
        <vers num="2.6.38.7"/>
        <vers num="2.6.38.8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.39.1"/>
        <vers num="2.6.39.2"/>
        <vers num="2.6.39.3"/>
        <vers num="2.6.39.4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.69"/>
        <vers num="3.0.70"/>
        <vers num="3.0.71"/>
        <vers num="3.0.72"/>
        <vers num="3.0.73"/>
        <vers num="3.0.74"/>
        <vers num="3.0.75"/>
        <vers num="3.0.76"/>
        <vers num="3.0.77"/>
        <vers num="3.0.78"/>
        <vers num="3.0.79"/>
        <vers num="3.0.80"/>
        <vers num="3.0.81"/>
        <vers num="3.0.82"/>
        <vers num="3.0.83"/>
        <vers num="3.0.84"/>
        <vers num="3.0.85"/>
        <vers num="3.0.86"/>
        <vers num="3.0.87"/>
        <vers num="3.0.88"/>
        <vers num="3.0.89"/>
        <vers num="3.0.90"/>
        <vers num="3.0.91"/>
        <vers num="3.0.92"/>
        <vers num="3.0.93"/>
        <vers num="3.0.94"/>
        <vers num="3.0.95"/>
        <vers num="3.0.96"/>
        <vers num="3.0.97"/>
        <vers num="3.0.98"/>
        <vers num="3.0.99"/>
        <vers num="3.0.100"/>
        <vers num="3.0.101"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.1.10"/>
        <vers num="3.2" edition=":~~~~x86~"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.30"/>
        <vers num="3.2.64"/>
        <vers num="3.2.65"/>
        <vers num="3.2.66"/>
        <vers num="3.2.67"/>
        <vers num="3.2.68"/>
        <vers num="3.2.69"/>
        <vers num="3.2.70"/>
        <vers num="3.2.71"/>
        <vers num="3.2.72"/>
        <vers num="3.2.73"/>
        <vers num="3.2.74"/>
        <vers num="3.2.75"/>
        <vers num="3.2.76"/>
        <vers num="3.2.77"/>
        <vers num="3.2.78"/>
        <vers num="3.2.79"/>
        <vers num="3.2.80"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition=":~~~~x86~"/>
        <vers num="3.4" edition="rc1:~~~~x86~"/>
        <vers num="3.4" edition="rc2:~~~~x86~"/>
        <vers num="3.4" edition="rc3:~~~~x86~"/>
        <vers num="3.4" edition="rc4:~~~~x86~"/>
        <vers num="3.4" edition="rc5:~~~~x86~"/>
        <vers num="3.4" edition="rc6:~~~~x86~"/>
        <vers num="3.4" edition="rc7:~~~~x86~"/>
        <vers num="3.4.1" edition=":~~~~x86~"/>
        <vers num="3.4.2" edition=":~~~~x86~"/>
        <vers num="3.4.3" edition=":~~~~x86~"/>
        <vers num="3.4.4" edition=":~~~~x86~"/>
        <vers num="3.4.5" edition=":~~~~x86~"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.33"/>
        <vers num="3.4.34"/>
        <vers num="3.4.35"/>
        <vers num="3.4.36"/>
        <vers num="3.4.37"/>
        <vers num="3.4.38"/>
        <vers num="3.4.39"/>
        <vers num="3.4.40"/>
        <vers num="3.4.41"/>
        <vers num="3.4.42"/>
        <vers num="3.4.43"/>
        <vers num="3.4.44"/>
        <vers num="3.4.45"/>
        <vers num="3.4.46"/>
        <vers num="3.4.47"/>
        <vers num="3.4.48"/>
        <vers num="3.4.49"/>
        <vers num="3.4.50"/>
        <vers num="3.4.51"/>
        <vers num="3.4.52"/>
        <vers num="3.4.53"/>
        <vers num="3.4.54"/>
        <vers num="3.4.55"/>
        <vers num="3.4.56"/>
        <vers num="3.4.57"/>
        <vers num="3.4.58"/>
        <vers num="3.4.59"/>
        <vers num="3.4.60"/>
        <vers num="3.4.61"/>
        <vers num="3.4.62"/>
        <vers num="3.4.63"/>
        <vers num="3.4.64"/>
        <vers num="3.4.65"/>
        <vers num="3.4.66"/>
        <vers num="3.4.67"/>
        <vers num="3.4.68"/>
        <vers num="3.4.69"/>
        <vers num="3.4.70"/>
        <vers num="3.4.71"/>
        <vers num="3.4.72"/>
        <vers num="3.4.73"/>
        <vers num="3.4.74"/>
        <vers num="3.4.75"/>
        <vers num="3.4.76"/>
        <vers num="3.4.77"/>
        <vers num="3.4.78"/>
        <vers num="3.4.79"/>
        <vers num="3.4.80"/>
        <vers num="3.4.81"/>
        <vers num="3.4.82"/>
        <vers num="3.4.83"/>
        <vers num="3.4.84"/>
        <vers num="3.4.85"/>
        <vers num="3.4.86"/>
        <vers num="3.4.87"/>
        <vers num="3.4.88"/>
        <vers num="3.4.89"/>
        <vers num="3.4.90"/>
        <vers num="3.4.91"/>
        <vers num="3.4.92"/>
        <vers num="3.4.93"/>
        <vers num="3.4.94"/>
        <vers num="3.4.95"/>
        <vers num="3.4.96"/>
        <vers num="3.4.97"/>
        <vers num="3.4.98"/>
        <vers num="3.4.99"/>
        <vers num="3.4.100"/>
        <vers num="3.4.101"/>
        <vers num="3.4.102"/>
        <vers num="3.4.103"/>
        <vers num="3.4.104"/>
        <vers num="3.4.105"/>
        <vers num="3.4.106"/>
        <vers num="3.4.107"/>
        <vers num="3.4.108"/>
        <vers num="3.4.109"/>
        <vers num="3.4.110"/>
        <vers num="3.4.111"/>
        <vers num="3.4.112"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6" edition="rc5"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.8"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9" edition="rc3"/>
        <vers num="3.9" edition="rc4"/>
        <vers num="3.9" edition="rc5"/>
        <vers num="3.9" edition="rc6"/>
        <vers num="3.9" edition="rc7"/>
        <vers num="3.9.0" edition=":~~~~arm64~"/>
        <vers num="3.9.1" edition=":~~~~arm64~"/>
        <vers num="3.9.2" edition=":~~~~arm64~"/>
        <vers num="3.9.3" edition=":~~~~arm64~"/>
        <vers num="3.9.4" edition=":~~~~arm64~"/>
        <vers num="3.9.5" edition=":~~~~arm64~"/>
        <vers num="3.9.6" edition=":~~~~arm64~"/>
        <vers num="3.9.7" edition=":~~~~arm64~"/>
        <vers num="3.9.8" edition=":~~~~arm64~"/>
        <vers num="3.9.9" edition=":~~~~arm64~"/>
        <vers num="3.9.10" edition=":~~~~arm64~"/>
        <vers num="3.9.11" edition=":~~~~arm64~"/>
        <vers num="3.10"/>
        <vers num="3.10.0" edition=":~~~~arm64~"/>
        <vers num="3.10.1" edition=":~~~~arm64~"/>
        <vers num="3.10.2" edition=":~~~~arm64~"/>
        <vers num="3.10.3" edition=":~~~~arm64~"/>
        <vers num="3.10.4" edition=":~~~~arm64~"/>
        <vers num="3.10.5" edition=":~~~~arm64~"/>
        <vers num="3.10.6" edition=":~~~~arm64~"/>
        <vers num="3.10.7" edition=":~~~~arm64~"/>
        <vers num="3.10.8" edition=":~~~~arm64~"/>
        <vers num="3.10.9" edition=":~~~~arm64~"/>
        <vers num="3.10.10"/>
        <vers num="3.10.11"/>
        <vers num="3.10.12"/>
        <vers num="3.10.13"/>
        <vers num="3.10.14"/>
        <vers num="3.10.15"/>
        <vers num="3.10.16"/>
        <vers num="3.10.17"/>
        <vers num="3.10.18"/>
        <vers num="3.10.19"/>
        <vers num="3.10.20"/>
        <vers num="3.10.21"/>
        <vers num="3.10.22"/>
        <vers num="3.10.23"/>
        <vers num="3.10.24"/>
        <vers num="3.10.25"/>
        <vers num="3.10.26"/>
        <vers num="3.10.27"/>
        <vers num="3.10.28"/>
        <vers num="3.10.29"/>
        <vers num="3.10.30"/>
        <vers num="3.10.31"/>
        <vers num="3.10.32"/>
        <vers num="3.10.33"/>
        <vers num="3.10.34"/>
        <vers num="3.10.35"/>
        <vers num="3.10.36"/>
        <vers num="3.10.37"/>
        <vers num="3.10.38"/>
        <vers num="3.10.39"/>
        <vers num="3.10.40"/>
        <vers num="3.10.41"/>
        <vers num="3.10.42"/>
        <vers num="3.10.43"/>
        <vers num="3.10.44"/>
        <vers num="3.10.45"/>
        <vers num="3.10.46"/>
        <vers num="3.10.47"/>
        <vers num="3.10.48"/>
        <vers num="3.10.49"/>
        <vers num="3.10.50"/>
        <vers num="3.10.51"/>
        <vers num="3.10.52"/>
        <vers num="3.10.53"/>
        <vers num="3.10.54"/>
        <vers num="3.10.55"/>
        <vers num="3.10.56"/>
        <vers num="3.10.57"/>
        <vers num="3.10.58"/>
        <vers num="3.10.59"/>
        <vers num="3.10.60"/>
        <vers num="3.10.61"/>
        <vers num="3.10.62"/>
        <vers num="3.10.63"/>
        <vers num="3.10.64"/>
        <vers num="3.10.65"/>
        <vers num="3.10.66"/>
        <vers num="3.10.67"/>
        <vers num="3.10.68"/>
        <vers num="3.10.69"/>
        <vers num="3.10.70"/>
        <vers num="3.10.71"/>
        <vers num="3.10.72"/>
        <vers num="3.10.73"/>
        <vers num="3.10.74"/>
        <vers num="3.10.75"/>
        <vers num="3.10.76"/>
        <vers num="3.10.77"/>
        <vers num="3.10.78"/>
        <vers num="3.10.79"/>
        <vers num="3.10.80"/>
        <vers num="3.10.81"/>
        <vers num="3.10.82"/>
        <vers num="3.10.83"/>
        <vers num="3.10.84"/>
        <vers num="3.10.85"/>
        <vers num="3.10.86"/>
        <vers num="3.10.87"/>
        <vers num="3.10.88"/>
        <vers num="3.10.89"/>
        <vers num="3.10.90"/>
        <vers num="3.10.91"/>
        <vers num="3.10.92"/>
        <vers num="3.10.93"/>
        <vers num="3.10.94"/>
        <vers num="3.10.95"/>
        <vers num="3.10.96"/>
        <vers num="3.10.97"/>
        <vers num="3.10.98"/>
        <vers num="3.10.99"/>
        <vers num="3.10.100"/>
        <vers num="3.10.101"/>
        <vers num="3.10.102"/>
        <vers num="3.11"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.8"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.8"/>
        <vers num="3.12.9"/>
        <vers num="3.12.10"/>
        <vers num="3.12.11"/>
        <vers num="3.12.12"/>
        <vers num="3.12.13"/>
        <vers num="3.12.14"/>
        <vers num="3.12.15"/>
        <vers num="3.12.16"/>
        <vers num="3.12.17"/>
        <vers num="3.12.18"/>
        <vers num="3.12.19"/>
        <vers num="3.12.20"/>
        <vers num="3.12.21"/>
        <vers num="3.12.22"/>
        <vers num="3.12.23"/>
        <vers num="3.12.24"/>
        <vers num="3.12.25"/>
        <vers num="3.12.26"/>
        <vers num="3.12.27"/>
        <vers num="3.12.28"/>
        <vers num="3.12.29"/>
        <vers num="3.12.30"/>
        <vers num="3.12.31"/>
        <vers num="3.12.32"/>
        <vers num="3.12.33"/>
        <vers num="3.12.34"/>
        <vers num="3.12.35"/>
        <vers num="3.12.36"/>
        <vers num="3.12.37"/>
        <vers num="3.12.38"/>
        <vers num="3.12.39"/>
        <vers num="3.12.40"/>
        <vers num="3.12.41"/>
        <vers num="3.12.42"/>
        <vers num="3.12.43"/>
        <vers num="3.12.44"/>
        <vers num="3.12.45"/>
        <vers num="3.12.46"/>
        <vers num="3.12.47"/>
        <vers num="3.12.48"/>
        <vers num="3.12.49"/>
        <vers num="3.12.50"/>
        <vers num="3.12.51"/>
        <vers num="3.12.52"/>
        <vers num="3.12.53"/>
        <vers num="3.12.54"/>
        <vers num="3.12.55"/>
        <vers num="3.12.56"/>
        <vers num="3.12.57"/>
        <vers num="3.12.58"/>
        <vers num="3.12.59"/>
        <vers num="3.13"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.4"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.8"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.13.11"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="rc1"/>
        <vers num="3.14" edition="rc2"/>
        <vers num="3.14" edition="rc3"/>
        <vers num="3.14" edition="rc4"/>
        <vers num="3.14" edition="rc5"/>
        <vers num="3.14" edition="rc6"/>
        <vers num="3.14" edition="rc7"/>
        <vers num="3.14" edition="rc8"/>
        <vers num="3.14.1"/>
        <vers num="3.14.2"/>
        <vers num="3.14.3"/>
        <vers num="3.14.4"/>
        <vers num="3.14.5"/>
        <vers num="3.14.8"/>
        <vers num="3.14.10"/>
        <vers num="3.14.11"/>
        <vers num="3.14.12"/>
        <vers num="3.14.13"/>
        <vers num="3.14.14"/>
        <vers num="3.14.15"/>
        <vers num="3.14.16"/>
        <vers num="3.14.17"/>
        <vers num="3.14.18"/>
        <vers num="3.14.19"/>
        <vers num="3.14.20"/>
        <vers num="3.14.21"/>
        <vers num="3.14.22"/>
        <vers num="3.14.23"/>
        <vers num="3.14.24"/>
        <vers num="3.14.25"/>
        <vers num="3.14.26"/>
        <vers num="3.14.27"/>
        <vers num="3.14.28"/>
        <vers num="3.14.29"/>
        <vers num="3.14.30"/>
        <vers num="3.14.31"/>
        <vers num="3.14.32"/>
        <vers num="3.14.33"/>
        <vers num="3.14.34"/>
        <vers num="3.14.35"/>
        <vers num="3.14.36"/>
        <vers num="3.14.37"/>
        <vers num="3.14.38"/>
        <vers num="3.14.39"/>
        <vers num="3.14.40"/>
        <vers num="3.14.41"/>
        <vers num="3.14.42"/>
        <vers num="3.14.43"/>
        <vers num="3.14.44"/>
        <vers num="3.14.45"/>
        <vers num="3.14.46"/>
        <vers num="3.14.47"/>
        <vers num="3.14.48"/>
        <vers num="3.14.49"/>
        <vers num="3.14.50"/>
        <vers num="3.14.51"/>
        <vers num="3.14.52"/>
        <vers num="3.14.53"/>
        <vers num="3.14.54"/>
        <vers num="3.14.55"/>
        <vers num="3.14.56"/>
        <vers num="3.14.57"/>
        <vers num="3.14.58"/>
        <vers num="3.14.59"/>
        <vers num="3.14.60"/>
        <vers num="3.14.61"/>
        <vers num="3.14.62"/>
        <vers num="3.14.63"/>
        <vers num="3.14.64"/>
        <vers num="3.14.65"/>
        <vers num="3.14.66"/>
        <vers num="3.14.67"/>
        <vers num="3.14.68"/>
        <vers num="3.14.79"/>
        <vers num="3.15" edition="rc4"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
        <vers num="3.15.4"/>
        <vers num="3.15.5"/>
        <vers num="3.15.6"/>
        <vers num="3.15.7"/>
        <vers num="3.15.8"/>
        <vers num="3.15.10"/>
        <vers num="3.16"/>
        <vers num="3.16.0"/>
        <vers num="3.16.1"/>
        <vers num="3.16.4"/>
        <vers num="3.16.5"/>
        <vers num="3.16.6"/>
        <vers num="3.16.7"/>
        <vers num="3.17"/>
        <vers num="3.17.3" edition=":~~~~arm64~"/>
        <vers num="3.17.5"/>
        <vers num="3.17.6"/>
        <vers num="3.17.7"/>
        <vers num="3.17.8"/>
        <vers num="3.18"/>
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.10"/>
        <vers num="3.18.11"/>
        <vers num="3.18.12"/>
        <vers num="3.18.13"/>
        <vers num="3.18.14"/>
        <vers num="3.18.15"/>
        <vers num="3.18.16"/>
        <vers num="3.18.17"/>
        <vers num="3.18.18"/>
        <vers num="3.18.19"/>
        <vers num="3.18.20"/>
        <vers num="3.18.21"/>
        <vers num="3.18.22"/>
        <vers num="3.18.23"/>
        <vers num="3.18.24"/>
        <vers num="3.18.25"/>
        <vers num="3.18.26"/>
        <vers num="3.18.27"/>
        <vers num="3.18.28"/>
        <vers num="3.18.29"/>
        <vers num="3.18.30"/>
        <vers num="3.18.31"/>
        <vers num="3.18.32"/>
        <vers num="3.18.33"/>
        <vers num="3.18.34"/>
        <vers num="3.18.35"/>
        <vers num="3.18.36"/>
        <vers num="3.18.37"/>
        <vers num="3.18.38"/>
        <vers num="3.18.39"/>
        <vers num="3.18.40"/>
        <vers num="3.18.41"/>
        <vers num="3.18.42"/>
        <vers num="3.18.43"/>
        <vers num="3.18.44"/>
        <vers num="3.18.45"/>
        <vers num="3.18.46"/>
        <vers num="3.18.47"/>
        <vers num="3.18.48"/>
        <vers num="3.18.49"/>
        <vers num="3.18.50"/>
        <vers num="3.18.51"/>
        <vers num="3.18.52"/>
        <vers num="3.18.53"/>
        <vers num="3.18.54"/>
        <vers num="3.18.55"/>
        <vers num="3.18.56"/>
        <vers num="3.18.57"/>
        <vers num="3.18.58"/>
        <vers num="3.18.59"/>
        <vers num="3.18.60"/>
        <vers num="3.18.61"/>
        <vers num="3.18.62"/>
        <vers num="3.18.63"/>
        <vers num="3.18.64"/>
        <vers num="3.18.65"/>
        <vers num="3.18.66"/>
        <vers num="3.19"/>
        <vers num="3.19.1"/>
        <vers num="3.19.2"/>
        <vers num="3.19.3"/>
        <vers num="3.19.4"/>
        <vers num="3.19.5"/>
        <vers num="3.19.6"/>
        <vers num="3.19.7"/>
        <vers num="3.19.8"/>
        <vers num="4"/>
        <vers num="4.0" edition="rc5"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.1" edition="rc2"/>
        <vers num="4.1" edition="rc3"/>
        <vers num="4.1" edition="rc4"/>
        <vers num="4.1" edition="rc5"/>
        <vers num="4.1" edition="rc6"/>
        <vers num="4.1" edition="rc7"/>
        <vers num="4.1" edition="rc8"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.1.27"/>
        <vers num="4.1.28"/>
        <vers num="4.1.29"/>
        <vers num="4.1.30"/>
        <vers num="4.1.31"/>
        <vers num="4.1.32"/>
        <vers num="4.1.33"/>
        <vers num="4.1.34"/>
        <vers num="4.1.35"/>
        <vers num="4.1.36"/>
        <vers num="4.1.37"/>
        <vers num="4.1.38"/>
        <vers num="4.1.39"/>
        <vers num="4.1.40"/>
        <vers num="4.1.41"/>
        <vers num="4.1.42"/>
        <vers num="4.1.43"/>
        <vers num="4.1.44"/>
        <vers num="4.1.45"/>
        <vers num="4.1.46"/>
        <vers num="4.1.47"/>
        <vers num="4.1.48"/>
        <vers num="4.1.49"/>
        <vers num="4.1.50"/>
        <vers num="4.1.51"/>
        <vers num="4.1.52"/>
        <vers num="4.2" edition="rc1"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc3"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.2" edition="rc6"/>
        <vers num="4.2" edition="rc7"/>
        <vers num="4.2" edition="rc8"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.3" edition="rc1"/>
        <vers num="4.3" edition="rc2"/>
        <vers num="4.3" edition="rc3"/>
        <vers num="4.3" edition="rc4"/>
        <vers num="4.3" edition="rc5"/>
        <vers num="4.3" edition="rc6"/>
        <vers num="4.3" edition="rc7"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4" edition="rc8"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.4.19"/>
        <vers num="4.4.20"/>
        <vers num="4.4.21"/>
        <vers num="4.4.22"/>
        <vers num="4.4.23"/>
        <vers num="4.4.24"/>
        <vers num="4.4.25"/>
        <vers num="4.4.26"/>
        <vers num="4.4.27"/>
        <vers num="4.4.28"/>
        <vers num="4.4.29"/>
        <vers num="4.4.30"/>
        <vers num="4.4.31"/>
        <vers num="4.4.32"/>
        <vers num="4.4.33"/>
        <vers num="4.4.34"/>
        <vers num="4.4.35"/>
        <vers num="4.4.36"/>
        <vers num="4.4.37"/>
        <vers num="4.4.38"/>
        <vers num="4.4.39"/>
        <vers num="4.4.40"/>
        <vers num="4.4.41"/>
        <vers num="4.4.42"/>
        <vers num="4.4.43"/>
        <vers num="4.4.44"/>
        <vers num="4.4.45"/>
        <vers num="4.4.46"/>
        <vers num="4.4.47"/>
        <vers num="4.4.48"/>
        <vers num="4.4.49"/>
        <vers num="4.4.50"/>
        <vers num="4.4.51"/>
        <vers num="4.4.52"/>
        <vers num="4.4.53"/>
        <vers num="4.4.54"/>
        <vers num="4.4.55"/>
        <vers num="4.4.56"/>
        <vers num="4.4.57"/>
        <vers num="4.4.58"/>
        <vers num="4.4.59"/>
        <vers num="4.4.60"/>
        <vers num="4.4.61"/>
        <vers num="4.4.62"/>
        <vers num="4.4.63"/>
        <vers num="4.4.64"/>
        <vers num="4.4.65"/>
        <vers num="4.4.66"/>
        <vers num="4.4.67"/>
        <vers num="4.4.68"/>
        <vers num="4.4.69"/>
        <vers num="4.4.70"/>
        <vers num="4.4.71"/>
        <vers num="4.4.72"/>
        <vers num="4.4.73"/>
        <vers num="4.4.74"/>
        <vers num="4.4.75"/>
        <vers num="4.4.76"/>
        <vers num="4.4.77"/>
        <vers num="4.4.78"/>
        <vers num="4.4.79"/>
        <vers num="4.4.80"/>
        <vers num="4.4.81"/>
        <vers num="4.4.82"/>
        <vers num="4.4.83"/>
        <vers num="4.4.84"/>
        <vers num="4.4.85"/>
        <vers num="4.4.86"/>
        <vers num="4.4.87"/>
        <vers num="4.4.88"/>
        <vers num="4.4.89"/>
        <vers num="4.4.90"/>
        <vers num="4.4.91"/>
        <vers num="4.4.92"/>
        <vers num="4.4.93"/>
        <vers num="4.4.94"/>
        <vers num="4.4.95"/>
        <vers num="4.4.96"/>
        <vers num="4.4.97"/>
        <vers num="4.4.98"/>
        <vers num="4.4.99"/>
        <vers num="4.4.100"/>
        <vers num="4.4.101"/>
        <vers num="4.4.102"/>
        <vers num="4.4.103"/>
        <vers num="4.4.104"/>
        <vers num="4.4.105"/>
        <vers num="4.4.106"/>
        <vers num="4.4.107"/>
        <vers num="4.4.108"/>
        <vers num="4.4.109"/>
        <vers num="4.4.110"/>
        <vers num="4.4.111"/>
        <vers num="4.4.112"/>
        <vers num="4.4.113"/>
        <vers num="4.4.114"/>
        <vers num="4.4.115"/>
        <vers num="4.4.116"/>
        <vers num="4.4.117"/>
        <vers num="4.4.118"/>
        <vers num="4.4.119"/>
        <vers num="4.4.120"/>
        <vers num="4.4.121"/>
        <vers num="4.4.122"/>
        <vers num="4.4.123"/>
        <vers num="4.4.124"/>
        <vers num="4.4.125"/>
        <vers num="4.4.126"/>
        <vers num="4.4.127"/>
        <vers num="4.4.128"/>
        <vers num="4.4.129"/>
        <vers num="4.4.130"/>
        <vers num="4.4.131"/>
        <vers num="4.4.132"/>
        <vers num="4.4.133"/>
        <vers num="4.4.134"/>
        <vers num="4.4.135"/>
        <vers num="4.4.136"/>
        <vers num="4.4.137"/>
        <vers num="4.4.138"/>
        <vers num="4.4.139"/>
        <vers num="4.4.140"/>
        <vers num="4.4.141"/>
        <vers num="4.4.142"/>
        <vers num="4.4.143"/>
        <vers num="4.4.144"/>
        <vers num="4.4.145"/>
        <vers num="4.4.146"/>
        <vers num="4.4.147"/>
        <vers num="4.4.148"/>
        <vers num="4.4.149"/>
        <vers num="4.4.150"/>
        <vers num="4.4.151"/>
        <vers num="4.4.152"/>
        <vers num="4.4.153"/>
        <vers num="4.4.154"/>
        <vers num="4.4.155"/>
        <vers num="4.4.156"/>
        <vers num="4.4.157"/>
        <vers num="4.4.158"/>
        <vers num="4.4.159"/>
        <vers num="4.4.160"/>
        <vers num="4.4.161"/>
        <vers num="4.4.162"/>
        <vers num="4.4.163"/>
        <vers num="4.4.164"/>
        <vers num="4.4.165"/>
        <vers num="4.4.166"/>
        <vers num="4.4.167"/>
        <vers num="4.4.168"/>
        <vers num="4.4.169"/>
        <vers num="4.4.170"/>
        <vers num="4.4.171"/>
        <vers num="4.4.172"/>
        <vers num="4.4.173"/>
        <vers num="4.4.174"/>
        <vers num="4.4.175"/>
        <vers num="4.4.176"/>
        <vers num="4.4.177"/>
        <vers num="4.4.178"/>
        <vers num="4.4.179"/>
        <vers num="4.4.180"/>
        <vers num="4.4.181"/>
        <vers num="4.4.182"/>
        <vers num="4.4.183"/>
        <vers num="4.4.184"/>
        <vers num="4.4.185"/>
        <vers num="4.4.186"/>
        <vers num="4.4.187"/>
        <vers num="4.4.188"/>
        <vers num="4.4.189"/>
        <vers num="4.4.190"/>
        <vers num="4.5" edition="rc3"/>
        <vers num="4.5" edition="rc4"/>
        <vers num="4.5.0" edition="rc7"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.7" edition="rc1"/>
        <vers num="4.7" edition="rc2"/>
        <vers num="4.7" edition="rc3"/>
        <vers num="4.7" edition="rc4"/>
        <vers num="4.7" edition="rc5"/>
        <vers num="4.7" edition="rc6"/>
        <vers num="4.7" edition="rc7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7.10"/>
        <vers num="4.8" edition="rc5"/>
        <vers num="4.8" edition="rc6"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="4.8.10"/>
        <vers num="4.8.11"/>
        <vers num="4.8.12"/>
        <vers num="4.8.13"/>
        <vers num="4.8.14"/>
        <vers num="4.8.15"/>
        <vers num="4.8.16"/>
        <vers num="4.8.17"/>
        <vers num="4.9" edition="rc1"/>
        <vers num="4.9" edition="rc2"/>
        <vers num="4.9" edition="rc3"/>
        <vers num="4.9" edition="rc4"/>
        <vers num="4.9" edition="rc5"/>
        <vers num="4.9" edition="rc6"/>
        <vers num="4.9" edition="rc7"/>
        <vers num="4.9" edition="rc8"/>
        <vers num="4.9.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
        <vers num="4.9.13"/>
        <vers num="4.9.14"/>
        <vers num="4.9.15"/>
        <vers num="4.9.16"/>
        <vers num="4.9.17"/>
        <vers num="4.9.18"/>
        <vers num="4.9.19"/>
        <vers num="4.9.20"/>
        <vers num="4.9.21"/>
        <vers num="4.9.22"/>
        <vers num="4.9.23"/>
        <vers num="4.9.24"/>
        <vers num="4.9.25"/>
        <vers num="4.9.26"/>
        <vers num="4.9.27"/>
        <vers num="4.9.28"/>
        <vers num="4.9.29"/>
        <vers num="4.9.30"/>
        <vers num="4.9.31"/>
        <vers num="4.9.32"/>
        <vers num="4.9.33"/>
        <vers num="4.9.34"/>
        <vers num="4.9.35"/>
        <vers num="4.9.36"/>
        <vers num="4.9.37"/>
        <vers num="4.9.38"/>
        <vers num="4.9.39"/>
        <vers num="4.9.40"/>
        <vers num="4.9.41"/>
        <vers num="4.9.42"/>
        <vers num="4.9.43"/>
        <vers num="4.9.44"/>
        <vers num="4.9.45"/>
        <vers num="4.9.46"/>
        <vers num="4.9.47"/>
        <vers num="4.9.48"/>
        <vers num="4.9.49"/>
        <vers num="4.9.50"/>
        <vers num="4.9.51"/>
        <vers num="4.9.52"/>
        <vers num="4.9.53"/>
        <vers num="4.9.54"/>
        <vers num="4.9.55"/>
        <vers num="4.9.56"/>
        <vers num="4.9.57"/>
        <vers num="4.9.58"/>
        <vers num="4.9.59"/>
        <vers num="4.9.60"/>
        <vers num="4.9.61"/>
        <vers num="4.9.62"/>
        <vers num="4.9.63"/>
        <vers num="4.9.64"/>
        <vers num="4.9.65"/>
        <vers num="4.9.66"/>
        <vers num="4.9.67"/>
        <vers num="4.9.68"/>
        <vers num="4.9.69"/>
        <vers num="4.9.70"/>
        <vers num="4.9.71"/>
        <vers num="4.9.72"/>
        <vers num="4.9.73"/>
        <vers num="4.9.74"/>
        <vers num="4.9.75"/>
        <vers num="4.9.76"/>
        <vers num="4.9.77"/>
        <vers num="4.9.78"/>
        <vers num="4.9.79"/>
        <vers num="4.9.80"/>
        <vers num="4.9.81"/>
        <vers num="4.9.82"/>
        <vers num="4.9.83"/>
        <vers num="4.9.84"/>
        <vers num="4.9.85"/>
        <vers num="4.9.86"/>
        <vers num="4.9.87"/>
        <vers num="4.9.88"/>
        <vers num="4.9.89"/>
        <vers num="4.9.90"/>
        <vers num="4.9.91"/>
        <vers num="4.9.92"/>
        <vers num="4.9.93"/>
        <vers num="4.9.94"/>
        <vers num="4.9.95"/>
        <vers num="4.9.96"/>
        <vers num="4.9.97"/>
        <vers num="4.9.98"/>
        <vers num="4.9.99"/>
        <vers num="4.9.100"/>
        <vers num="4.9.101"/>
        <vers num="4.9.102"/>
        <vers num="4.9.103"/>
        <vers num="4.9.104"/>
        <vers num="4.9.105"/>
        <vers num="4.9.106"/>
        <vers num="4.9.107"/>
        <vers num="4.9.108"/>
        <vers num="4.9.109"/>
        <vers num="4.9.110"/>
        <vers num="4.9.111"/>
        <vers num="4.9.112"/>
        <vers num="4.9.113"/>
        <vers num="4.9.114"/>
        <vers num="4.9.115"/>
        <vers num="4.9.116"/>
        <vers num="4.9.117"/>
        <vers num="4.9.118"/>
        <vers num="4.9.119"/>
        <vers num="4.9.120"/>
        <vers num="4.9.121"/>
        <vers num="4.9.122"/>
        <vers num="4.9.123"/>
        <vers num="4.9.124"/>
        <vers num="4.9.125"/>
        <vers num="4.9.126"/>
        <vers num="4.9.127"/>
        <vers num="4.9.128"/>
        <vers num="4.9.129"/>
        <vers num="4.9.130"/>
        <vers num="4.9.131"/>
        <vers num="4.9.132"/>
        <vers num="4.9.133"/>
        <vers num="4.9.134"/>
        <vers num="4.9.135"/>
        <vers num="4.9.136"/>
        <vers num="4.9.137"/>
        <vers num="4.9.138"/>
        <vers num="4.9.139"/>
        <vers num="4.9.140"/>
        <vers num="4.9.141"/>
        <vers num="4.9.142"/>
        <vers num="4.9.143"/>
        <vers num="4.9.144"/>
        <vers num="4.9.145"/>
        <vers num="4.9.146"/>
        <vers num="4.9.147"/>
        <vers num="4.9.148"/>
        <vers num="4.9.149"/>
        <vers num="4.9.150"/>
        <vers num="4.9.151"/>
        <vers num="4.9.152"/>
        <vers num="4.9.153"/>
        <vers num="4.9.154"/>
        <vers num="4.9.155"/>
        <vers num="4.9.156"/>
        <vers num="4.9.157"/>
        <vers num="4.9.158"/>
        <vers num="4.9.159"/>
        <vers num="4.9.160"/>
        <vers num="4.9.161"/>
        <vers num="4.9.162"/>
        <vers num="4.9.163"/>
        <vers num="4.9.164"/>
        <vers num="4.9.165"/>
        <vers num="4.9.166"/>
        <vers num="4.9.167"/>
        <vers num="4.9.168"/>
        <vers num="4.9.169"/>
        <vers num="4.9.170"/>
        <vers num="4.9.171"/>
        <vers num="4.9.172"/>
        <vers num="4.9.173"/>
        <vers num="4.9.174"/>
        <vers num="4.9.175"/>
        <vers num="4.9.176"/>
        <vers num="4.9.177"/>
        <vers num="4.9.178"/>
        <vers num="4.9.179"/>
        <vers num="4.9.180"/>
        <vers num="4.9.181"/>
        <vers num="4.9.182"/>
        <vers num="4.9.183"/>
        <vers num="4.9.184"/>
        <vers num="4.9.185"/>
        <vers num="4.9.186"/>
        <vers num="4.9.187"/>
        <vers num="4.9.188"/>
        <vers num="4.9.189"/>
        <vers num="4.9.190"/>
        <vers num="4.10" edition="rc3"/>
        <vers num="4.10" edition="rc4"/>
        <vers num="4.10.1"/>
        <vers num="4.10.2"/>
        <vers num="4.10.3"/>
        <vers num="4.10.4"/>
        <vers num="4.10.5"/>
        <vers num="4.10.6"/>
        <vers num="4.10.7"/>
        <vers num="4.10.8"/>
        <vers num="4.10.9"/>
        <vers num="4.10.10"/>
        <vers num="4.10.11"/>
        <vers num="4.10.12"/>
        <vers num="4.10.13"/>
        <vers num="4.10.14"/>
        <vers num="4.10.15"/>
        <vers num="4.10.16"/>
        <vers num="4.10.17"/>
        <vers num="4.11" edition="rc1"/>
        <vers num="4.11" edition="rc2"/>
        <vers num="4.11" edition="rc3"/>
        <vers num="4.11" edition="rc4"/>
        <vers num="4.11" edition="rc5"/>
        <vers num="4.11" edition="rc6"/>
        <vers num="4.11" edition="rc7"/>
        <vers num="4.11.1"/>
        <vers num="4.11.2"/>
        <vers num="4.11.3"/>
        <vers num="4.11.4"/>
        <vers num="4.11.5"/>
        <vers num="4.11.6"/>
        <vers num="4.11.7"/>
        <vers num="4.11.8"/>
        <vers num="4.11.9"/>
        <vers num="4.11.10"/>
        <vers num="4.11.11"/>
        <vers num="4.11.12"/>
        <vers num="4.12" edition="rc1"/>
        <vers num="4.12" edition="rc2"/>
        <vers num="4.12" edition="rc3"/>
        <vers num="4.12" edition="rc4"/>
        <vers num="4.12" edition="rc5"/>
        <vers num="4.12" edition="rc6"/>
        <vers num="4.12.1"/>
        <vers num="4.12.2"/>
        <vers num="4.12.3"/>
        <vers num="4.12.4"/>
        <vers num="4.12.5"/>
        <vers num="4.12.6"/>
        <vers num="4.12.7"/>
        <vers num="4.12.8"/>
        <vers num="4.12.9"/>
        <vers num="4.12.10"/>
        <vers num="4.12.11"/>
        <vers num="4.12.12"/>
        <vers num="4.12.13"/>
        <vers num="4.12.14"/>
        <vers num="4.13" edition="rc1"/>
        <vers num="4.13" edition="rc2"/>
        <vers num="4.13" edition="rc3"/>
        <vers num="4.13" edition="rc4"/>
        <vers num="4.13" edition="rc5"/>
        <vers num="4.13" edition="rc6"/>
        <vers num="4.13.1"/>
        <vers num="4.13.2"/>
        <vers num="4.13.3"/>
        <vers num="4.13.4"/>
        <vers num="4.13.5"/>
        <vers num="4.13.6"/>
        <vers num="4.13.7"/>
        <vers num="4.13.8"/>
        <vers num="4.13.9"/>
        <vers num="4.13.10"/>
        <vers num="4.13.11"/>
        <vers num="4.13.12"/>
        <vers num="4.13.13"/>
        <vers num="4.13.14"/>
        <vers num="4.13.15"/>
        <vers num="4.13.16"/>
        <vers num="4.14"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.14.7"/>
        <vers num="4.14.8"/>
        <vers num="4.14.9"/>
        <vers num="4.14.10"/>
        <vers num="4.14.11"/>
        <vers num="4.14.12"/>
        <vers num="4.14.13"/>
        <vers num="4.14.14"/>
        <vers num="4.14.15"/>
        <vers num="4.14.16"/>
        <vers num="4.14.17"/>
        <vers num="4.14.18"/>
        <vers num="4.14.19"/>
        <vers num="4.14.20"/>
        <vers num="4.14.21"/>
        <vers num="4.14.22"/>
        <vers num="4.14.23"/>
        <vers num="4.14.24"/>
        <vers num="4.14.25"/>
        <vers num="4.14.26"/>
        <vers num="4.14.27"/>
        <vers num="4.14.28"/>
        <vers num="4.14.29"/>
        <vers num="4.14.30"/>
        <vers num="4.14.31"/>
        <vers num="4.14.32"/>
        <vers num="4.14.33"/>
        <vers num="4.14.34"/>
        <vers num="4.14.35"/>
        <vers num="4.14.36"/>
        <vers num="4.14.37"/>
        <vers num="4.14.38"/>
        <vers num="4.14.39"/>
        <vers num="4.14.40"/>
        <vers num="4.14.41"/>
        <vers num="4.14.42"/>
        <vers num="4.14.43"/>
        <vers num="4.14.44"/>
        <vers num="4.14.45"/>
        <vers num="4.14.46"/>
        <vers num="4.14.47"/>
        <vers num="4.14.48"/>
        <vers num="4.14.49"/>
        <vers num="4.14.50"/>
        <vers num="4.14.51"/>
        <vers num="4.14.52"/>
        <vers num="4.14.53"/>
        <vers num="4.14.54"/>
        <vers num="4.14.55"/>
        <vers num="4.14.56"/>
        <vers num="4.14.57"/>
        <vers num="4.14.58"/>
        <vers num="4.14.59"/>
        <vers num="4.14.60"/>
        <vers num="4.14.61"/>
        <vers num="4.14.62"/>
        <vers num="4.14.63"/>
        <vers num="4.14.64"/>
        <vers num="4.14.65"/>
        <vers num="4.14.66"/>
        <vers num="4.14.67"/>
        <vers num="4.14.68"/>
        <vers num="4.14.69"/>
        <vers num="4.14.70"/>
        <vers num="4.14.71"/>
        <vers num="4.14.72"/>
        <vers num="4.14.73"/>
        <vers num="4.14.74"/>
        <vers num="4.14.75"/>
        <vers num="4.14.76"/>
        <vers num="4.14.77"/>
        <vers num="4.14.78"/>
        <vers num="4.14.79"/>
        <vers num="4.14.80"/>
        <vers num="4.14.81"/>
        <vers num="4.14.82"/>
        <vers num="4.14.83"/>
        <vers num="4.14.84"/>
        <vers num="4.14.85"/>
        <vers num="4.14.86"/>
        <vers num="4.14.87"/>
        <vers num="4.14.88"/>
        <vers num="4.14.89"/>
        <vers num="4.14.90"/>
        <vers num="4.14.91"/>
        <vers num="4.14.92"/>
        <vers num="4.14.93"/>
        <vers num="4.14.94"/>
        <vers num="4.14.95"/>
        <vers num="4.14.96"/>
        <vers num="4.14.97"/>
        <vers num="4.14.98"/>
        <vers num="4.14.99"/>
        <vers num="4.14.100"/>
        <vers num="4.14.101"/>
        <vers num="4.14.102"/>
        <vers num="4.14.103"/>
        <vers num="4.14.104"/>
        <vers num="4.14.105"/>
        <vers num="4.14.106"/>
        <vers num="4.14.107"/>
        <vers num="4.14.108"/>
        <vers num="4.14.109"/>
        <vers num="4.14.110"/>
        <vers num="4.14.111"/>
        <vers num="4.14.112"/>
        <vers num="4.14.113"/>
        <vers num="4.14.114"/>
        <vers num="4.14.115"/>
        <vers num="4.14.116"/>
        <vers num="4.14.117"/>
        <vers num="4.14.118"/>
        <vers num="4.14.119"/>
        <vers num="4.14.120"/>
        <vers num="4.14.121"/>
        <vers num="4.14.122"/>
        <vers num="4.14.123"/>
        <vers num="4.14.124"/>
        <vers num="4.14.125"/>
        <vers num="4.14.126"/>
        <vers num="4.14.127"/>
        <vers num="4.14.128"/>
        <vers num="4.14.129"/>
        <vers num="4.14.130"/>
        <vers num="4.14.131"/>
        <vers num="4.14.132"/>
        <vers num="4.14.133"/>
        <vers num="4.14.134"/>
        <vers num="4.14.135"/>
        <vers num="4.14.136"/>
        <vers num="4.14.137"/>
        <vers num="4.14.138"/>
        <vers num="4.14.139"/>
        <vers num="4.14.140"/>
        <vers num="4.14.141"/>
        <vers num="4.15" edition="rc1"/>
        <vers num="4.15" edition="rc2"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000408" seq="2017-1000408" published="2018-01-31" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q4/385" adv="1">[oss-security] 20171211 Qualys Security Advisory - Buffer overflow in glibc's ld.so</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/27/7">[oss-security] 20190627 Re: linux-distros membership application - Microsoft</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/28/1">[oss-security] 20190628 Re: linux-distros membership application - Microsoft</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/28/2">[oss-security] 20190628 Re: linux-distros membership application - Microsoft</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20190404-0003/">https://security.netapp.com/advisory/ntap-20190404-0003/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43331/" adv="1">43331</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000409" seq="2017-1000409" published="2018-01-31" modified="2019-04-04" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q4/385" adv="1">[oss-security] 20171211 Qualys Security Advisory - Buffer overflow in glibc's ld.so</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20190404-0003/">https://security.netapp.com/advisory/ntap-20190404-0003/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43331/" adv="1">43331</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000410" seq="2017-1000410" published="2017-12-07" modified="2019-04-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these configuration messages, an attacker can also gain some control over which data will be held in the uninitialized stack variables. This can allow him to bypass KASLR, and stack canaries protection - as both pointers and stack canaries may be leaked in this manner. Combining this vulnerability (for example) with the previously disclosed RCE vulnerability in L2CAP configuration parsing (CVE-2017-1000251) may allow an attacker to exploit the RCE against kernels which were built with the above mitigations. These are the specifics of this vulnerability: In the function l2cap_parse_conf_rsp and in the function l2cap_parse_conf_req the following variable is declared without initialization: struct l2cap_conf_efs efs; In addition, when parsing input configuration parameters in both of these functions, the switch case for handling EFS elements may skip the memcpy call that will write to the efs variable: ... case L2CAP_CONF_EFS: if (olen == sizeof(efs)) memcpy(&amp;efs, (void *)val, olen); ... The olen in the above if is attacker controlled, and regardless of that if, in both of these functions the efs variable would eventually be added to the outgoing configuration request that is being built: l2cap_add_conf_opt(&amp;ptr, L2CAP_CONF_EFS, sizeof(efs), (unsigned long) &amp;efs); So by sending a configuration request, or response, that contains an L2CAP_CONF_EFS element, but with an element length that is not sizeof(efs) - the memcpy to the uninitialized efs variable can be avoided, and the uninitialized variable would be returned to the attacker (16 bytes).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q4/357" adv="1" patch="1">[oss-security] 20171206 Info Leak in the Linux Kernel via Bluetooth</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102101" adv="1">102101</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0654" adv="1">RHSA-2018:0654</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0676" adv="1">RHSA-2018:0676</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1062" adv="1">RHSA-2018:1062</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1130" adv="1">RHSA-2018:1130</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1170" adv="1">RHSA-2018:1170</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1319" adv="1">RHSA-2018:1319</ref>
      <ref source="CONFIRM" url="https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0" adv="1">https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3933-1/">USN-3933-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3933-2/">USN-3933-2</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4073" adv="1">DSA-4073</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4082" adv="1">DSA-4082</ref>
    </refs>
    <vuln_soft>
      <prod name="virtualization_host" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.30"/>
        <vers num="3.2.64"/>
        <vers num="3.2.65"/>
        <vers num="3.2.66"/>
        <vers num="3.2.67"/>
        <vers num="3.2.68"/>
        <vers num="3.2.69"/>
        <vers num="3.2.70"/>
        <vers num="3.2.71"/>
        <vers num="3.2.72"/>
        <vers num="3.2.73"/>
        <vers num="3.2.74"/>
        <vers num="3.2.75"/>
        <vers num="3.2.76"/>
        <vers num="3.2.77"/>
        <vers num="3.2.78"/>
        <vers num="3.2.79"/>
        <vers num="3.2.80"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition=":~~~~x86~"/>
        <vers num="3.4" edition="rc1:~~~~x86~"/>
        <vers num="3.4" edition="rc2:~~~~x86~"/>
        <vers num="3.4" edition="rc3:~~~~x86~"/>
        <vers num="3.4" edition="rc4:~~~~x86~"/>
        <vers num="3.4" edition="rc5:~~~~x86~"/>
        <vers num="3.4" edition="rc6:~~~~x86~"/>
        <vers num="3.4" edition="rc7:~~~~x86~"/>
        <vers num="3.4.1" edition=":~~~~x86~"/>
        <vers num="3.4.2" edition=":~~~~x86~"/>
        <vers num="3.4.3" edition=":~~~~x86~"/>
        <vers num="3.4.4" edition=":~~~~x86~"/>
        <vers num="3.4.5" edition=":~~~~x86~"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.33"/>
        <vers num="3.4.34"/>
        <vers num="3.4.35"/>
        <vers num="3.4.36"/>
        <vers num="3.4.37"/>
        <vers num="3.4.38"/>
        <vers num="3.4.39"/>
        <vers num="3.4.40"/>
        <vers num="3.4.41"/>
        <vers num="3.4.42"/>
        <vers num="3.4.43"/>
        <vers num="3.4.44"/>
        <vers num="3.4.45"/>
        <vers num="3.4.46"/>
        <vers num="3.4.47"/>
        <vers num="3.4.48"/>
        <vers num="3.4.49"/>
        <vers num="3.4.50"/>
        <vers num="3.4.51"/>
        <vers num="3.4.52"/>
        <vers num="3.4.53"/>
        <vers num="3.4.54"/>
        <vers num="3.4.55"/>
        <vers num="3.4.56"/>
        <vers num="3.4.57"/>
        <vers num="3.4.58"/>
        <vers num="3.4.59"/>
        <vers num="3.4.60"/>
        <vers num="3.4.61"/>
        <vers num="3.4.62"/>
        <vers num="3.4.63"/>
        <vers num="3.4.64"/>
        <vers num="3.4.65"/>
        <vers num="3.4.66"/>
        <vers num="3.4.67"/>
        <vers num="3.4.68"/>
        <vers num="3.4.69"/>
        <vers num="3.4.70"/>
        <vers num="3.4.71"/>
        <vers num="3.4.72"/>
        <vers num="3.4.73"/>
        <vers num="3.4.74"/>
        <vers num="3.4.75"/>
        <vers num="3.4.76"/>
        <vers num="3.4.77"/>
        <vers num="3.4.78"/>
        <vers num="3.4.79"/>
        <vers num="3.4.80"/>
        <vers num="3.4.81"/>
        <vers num="3.4.82"/>
        <vers num="3.4.83"/>
        <vers num="3.4.84"/>
        <vers num="3.4.85"/>
        <vers num="3.4.86"/>
        <vers num="3.4.87"/>
        <vers num="3.4.88"/>
        <vers num="3.4.89"/>
        <vers num="3.4.90"/>
        <vers num="3.4.91"/>
        <vers num="3.4.92"/>
        <vers num="3.4.93"/>
        <vers num="3.4.94"/>
        <vers num="3.4.95"/>
        <vers num="3.4.96"/>
        <vers num="3.4.97"/>
        <vers num="3.4.98"/>
        <vers num="3.4.99"/>
        <vers num="3.4.100"/>
        <vers num="3.4.101"/>
        <vers num="3.4.102"/>
        <vers num="3.4.103"/>
        <vers num="3.4.104"/>
        <vers num="3.4.105"/>
        <vers num="3.4.106"/>
        <vers num="3.4.107"/>
        <vers num="3.4.108"/>
        <vers num="3.4.109"/>
        <vers num="3.4.110"/>
        <vers num="3.4.111"/>
        <vers num="3.4.112"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6" edition="rc5"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.8"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9" edition="rc3"/>
        <vers num="3.9" edition="rc4"/>
        <vers num="3.9" edition="rc5"/>
        <vers num="3.9" edition="rc6"/>
        <vers num="3.9" edition="rc7"/>
        <vers num="3.9.0" edition=":~~~~arm64~"/>
        <vers num="3.9.1" edition=":~~~~arm64~"/>
        <vers num="3.9.2" edition=":~~~~arm64~"/>
        <vers num="3.9.3" edition=":~~~~arm64~"/>
        <vers num="3.9.4" edition=":~~~~arm64~"/>
        <vers num="3.9.5" edition=":~~~~arm64~"/>
        <vers num="3.9.6" edition=":~~~~arm64~"/>
        <vers num="3.9.7" edition=":~~~~arm64~"/>
        <vers num="3.9.8" edition=":~~~~arm64~"/>
        <vers num="3.9.9" edition=":~~~~arm64~"/>
        <vers num="3.9.10" edition=":~~~~arm64~"/>
        <vers num="3.9.11" edition=":~~~~arm64~"/>
        <vers num="3.10"/>
        <vers num="3.10.0" edition=":~~~~arm64~"/>
        <vers num="3.10.1" edition=":~~~~arm64~"/>
        <vers num="3.10.2" edition=":~~~~arm64~"/>
        <vers num="3.10.3" edition=":~~~~arm64~"/>
        <vers num="3.10.4" edition=":~~~~arm64~"/>
        <vers num="3.10.5" edition=":~~~~arm64~"/>
        <vers num="3.10.6" edition=":~~~~arm64~"/>
        <vers num="3.10.7" edition=":~~~~arm64~"/>
        <vers num="3.10.8" edition=":~~~~arm64~"/>
        <vers num="3.10.9" edition=":~~~~arm64~"/>
        <vers num="3.10.10"/>
        <vers num="3.10.11"/>
        <vers num="3.10.12"/>
        <vers num="3.10.13"/>
        <vers num="3.10.14"/>
        <vers num="3.10.15"/>
        <vers num="3.10.16"/>
        <vers num="3.10.17"/>
        <vers num="3.10.18"/>
        <vers num="3.10.19"/>
        <vers num="3.10.20"/>
        <vers num="3.10.21"/>
        <vers num="3.10.22"/>
        <vers num="3.10.23"/>
        <vers num="3.10.24"/>
        <vers num="3.10.25"/>
        <vers num="3.10.26"/>
        <vers num="3.10.27"/>
        <vers num="3.10.28"/>
        <vers num="3.10.29"/>
        <vers num="3.10.30"/>
        <vers num="3.10.31"/>
        <vers num="3.10.32"/>
        <vers num="3.10.33"/>
        <vers num="3.10.34"/>
        <vers num="3.10.35"/>
        <vers num="3.10.36"/>
        <vers num="3.10.37"/>
        <vers num="3.10.38"/>
        <vers num="3.10.39"/>
        <vers num="3.10.40"/>
        <vers num="3.10.41"/>
        <vers num="3.10.42"/>
        <vers num="3.10.43"/>
        <vers num="3.10.44"/>
        <vers num="3.10.45"/>
        <vers num="3.10.46"/>
        <vers num="3.10.47"/>
        <vers num="3.10.48"/>
        <vers num="3.10.49"/>
        <vers num="3.10.50"/>
        <vers num="3.10.51"/>
        <vers num="3.10.52"/>
        <vers num="3.10.53"/>
        <vers num="3.10.54"/>
        <vers num="3.10.55"/>
        <vers num="3.10.56"/>
        <vers num="3.10.57"/>
        <vers num="3.10.58"/>
        <vers num="3.10.59"/>
        <vers num="3.10.60"/>
        <vers num="3.10.61"/>
        <vers num="3.10.62"/>
        <vers num="3.10.63"/>
        <vers num="3.10.64"/>
        <vers num="3.10.65"/>
        <vers num="3.10.66"/>
        <vers num="3.10.67"/>
        <vers num="3.10.68"/>
        <vers num="3.10.69"/>
        <vers num="3.10.70"/>
        <vers num="3.10.71"/>
        <vers num="3.10.72"/>
        <vers num="3.10.73"/>
        <vers num="3.10.74"/>
        <vers num="3.10.75"/>
        <vers num="3.10.76"/>
        <vers num="3.10.77"/>
        <vers num="3.10.78"/>
        <vers num="3.10.79"/>
        <vers num="3.10.80"/>
        <vers num="3.10.81"/>
        <vers num="3.10.82"/>
        <vers num="3.10.83"/>
        <vers num="3.10.84"/>
        <vers num="3.10.85"/>
        <vers num="3.10.86"/>
        <vers num="3.10.87"/>
        <vers num="3.10.88"/>
        <vers num="3.10.89"/>
        <vers num="3.10.90"/>
        <vers num="3.10.91"/>
        <vers num="3.10.92"/>
        <vers num="3.10.93"/>
        <vers num="3.10.94"/>
        <vers num="3.10.95"/>
        <vers num="3.10.96"/>
        <vers num="3.10.97"/>
        <vers num="3.10.98"/>
        <vers num="3.10.99"/>
        <vers num="3.10.100"/>
        <vers num="3.10.101"/>
        <vers num="3.10.102"/>
        <vers num="3.11"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.8"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.8"/>
        <vers num="3.12.9"/>
        <vers num="3.12.10"/>
        <vers num="3.12.11"/>
        <vers num="3.12.12"/>
        <vers num="3.12.13"/>
        <vers num="3.12.14"/>
        <vers num="3.12.15"/>
        <vers num="3.12.16"/>
        <vers num="3.12.17"/>
        <vers num="3.12.18"/>
        <vers num="3.12.19"/>
        <vers num="3.12.20"/>
        <vers num="3.12.21"/>
        <vers num="3.12.22"/>
        <vers num="3.12.23"/>
        <vers num="3.12.24"/>
        <vers num="3.12.25"/>
        <vers num="3.12.26"/>
        <vers num="3.12.27"/>
        <vers num="3.12.28"/>
        <vers num="3.12.29"/>
        <vers num="3.12.30"/>
        <vers num="3.12.31"/>
        <vers num="3.12.32"/>
        <vers num="3.12.33"/>
        <vers num="3.12.34"/>
        <vers num="3.12.35"/>
        <vers num="3.12.36"/>
        <vers num="3.12.37"/>
        <vers num="3.12.38"/>
        <vers num="3.12.39"/>
        <vers num="3.12.40"/>
        <vers num="3.12.41"/>
        <vers num="3.12.42"/>
        <vers num="3.12.43"/>
        <vers num="3.12.44"/>
        <vers num="3.12.45"/>
        <vers num="3.12.46"/>
        <vers num="3.12.47"/>
        <vers num="3.12.48"/>
        <vers num="3.12.49"/>
        <vers num="3.12.50"/>
        <vers num="3.12.51"/>
        <vers num="3.12.52"/>
        <vers num="3.12.53"/>
        <vers num="3.12.54"/>
        <vers num="3.12.55"/>
        <vers num="3.12.56"/>
        <vers num="3.12.57"/>
        <vers num="3.12.58"/>
        <vers num="3.12.59"/>
        <vers num="3.13"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.4"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.8"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.13.11"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="rc1"/>
        <vers num="3.14" edition="rc2"/>
        <vers num="3.14" edition="rc3"/>
        <vers num="3.14" edition="rc4"/>
        <vers num="3.14" edition="rc5"/>
        <vers num="3.14" edition="rc6"/>
        <vers num="3.14" edition="rc7"/>
        <vers num="3.14" edition="rc8"/>
        <vers num="3.14.1"/>
        <vers num="3.14.2"/>
        <vers num="3.14.3"/>
        <vers num="3.14.4"/>
        <vers num="3.14.5"/>
        <vers num="3.14.8"/>
        <vers num="3.14.10"/>
        <vers num="3.14.11"/>
        <vers num="3.14.12"/>
        <vers num="3.14.13"/>
        <vers num="3.14.14"/>
        <vers num="3.14.15"/>
        <vers num="3.14.16"/>
        <vers num="3.14.17"/>
        <vers num="3.14.18"/>
        <vers num="3.14.19"/>
        <vers num="3.14.20"/>
        <vers num="3.14.21"/>
        <vers num="3.14.22"/>
        <vers num="3.14.23"/>
        <vers num="3.14.24"/>
        <vers num="3.14.25"/>
        <vers num="3.14.26"/>
        <vers num="3.14.27"/>
        <vers num="3.14.28"/>
        <vers num="3.14.29"/>
        <vers num="3.14.30"/>
        <vers num="3.14.31"/>
        <vers num="3.14.32"/>
        <vers num="3.14.33"/>
        <vers num="3.14.34"/>
        <vers num="3.14.35"/>
        <vers num="3.14.36"/>
        <vers num="3.14.37"/>
        <vers num="3.14.38"/>
        <vers num="3.14.39"/>
        <vers num="3.14.40"/>
        <vers num="3.14.41"/>
        <vers num="3.14.42"/>
        <vers num="3.14.43"/>
        <vers num="3.14.44"/>
        <vers num="3.14.45"/>
        <vers num="3.14.46"/>
        <vers num="3.14.47"/>
        <vers num="3.14.48"/>
        <vers num="3.14.49"/>
        <vers num="3.14.50"/>
        <vers num="3.14.51"/>
        <vers num="3.14.52"/>
        <vers num="3.14.53"/>
        <vers num="3.14.54"/>
        <vers num="3.14.55"/>
        <vers num="3.14.56"/>
        <vers num="3.14.57"/>
        <vers num="3.14.58"/>
        <vers num="3.14.59"/>
        <vers num="3.14.60"/>
        <vers num="3.14.61"/>
        <vers num="3.14.62"/>
        <vers num="3.14.63"/>
        <vers num="3.14.64"/>
        <vers num="3.14.65"/>
        <vers num="3.14.66"/>
        <vers num="3.14.67"/>
        <vers num="3.14.68"/>
        <vers num="3.14.79"/>
        <vers num="3.15" edition="rc4"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
        <vers num="3.15.4"/>
        <vers num="3.15.5"/>
        <vers num="3.15.6"/>
        <vers num="3.15.7"/>
        <vers num="3.15.8"/>
        <vers num="3.15.10"/>
        <vers num="3.16"/>
        <vers num="3.16.0"/>
        <vers num="3.16.1"/>
        <vers num="3.16.4"/>
        <vers num="3.16.5"/>
        <vers num="3.16.6"/>
        <vers num="3.16.7"/>
        <vers num="3.17"/>
        <vers num="3.17.3" edition=":~~~~arm64~"/>
        <vers num="3.17.5"/>
        <vers num="3.17.6"/>
        <vers num="3.17.7"/>
        <vers num="3.17.8"/>
        <vers num="3.18"/>
        <vers num="3.18.0"/>
        <vers num="3.18.1"/>
        <vers num="3.18.2"/>
        <vers num="3.18.3"/>
        <vers num="3.18.4"/>
        <vers num="3.18.5"/>
        <vers num="3.18.6"/>
        <vers num="3.18.7"/>
        <vers num="3.18.8"/>
        <vers num="3.18.10"/>
        <vers num="3.18.11"/>
        <vers num="3.18.12"/>
        <vers num="3.18.13"/>
        <vers num="3.18.14"/>
        <vers num="3.18.15"/>
        <vers num="3.18.16"/>
        <vers num="3.18.17"/>
        <vers num="3.18.18"/>
        <vers num="3.18.19"/>
        <vers num="3.18.20"/>
        <vers num="3.18.21"/>
        <vers num="3.18.22"/>
        <vers num="3.18.23"/>
        <vers num="3.18.24"/>
        <vers num="3.18.25"/>
        <vers num="3.18.26"/>
        <vers num="3.18.27"/>
        <vers num="3.18.28"/>
        <vers num="3.18.29"/>
        <vers num="3.18.30"/>
        <vers num="3.18.31"/>
        <vers num="3.18.32"/>
        <vers num="3.18.33"/>
        <vers num="3.18.34"/>
        <vers num="3.18.35"/>
        <vers num="3.18.36"/>
        <vers num="3.18.37"/>
        <vers num="3.18.38"/>
        <vers num="3.18.39"/>
        <vers num="3.18.40"/>
        <vers num="3.18.41"/>
        <vers num="3.18.42"/>
        <vers num="3.18.43"/>
        <vers num="3.18.44"/>
        <vers num="3.18.45"/>
        <vers num="3.18.46"/>
        <vers num="3.18.47"/>
        <vers num="3.18.48"/>
        <vers num="3.18.49"/>
        <vers num="3.18.50"/>
        <vers num="3.18.51"/>
        <vers num="3.18.52"/>
        <vers num="3.18.53"/>
        <vers num="3.18.54"/>
        <vers num="3.18.55"/>
        <vers num="3.18.56"/>
        <vers num="3.18.57"/>
        <vers num="3.18.58"/>
        <vers num="3.18.59"/>
        <vers num="3.18.60"/>
        <vers num="3.18.61"/>
        <vers num="3.18.62"/>
        <vers num="3.18.63"/>
        <vers num="3.18.64"/>
        <vers num="3.18.65"/>
        <vers num="3.18.66"/>
        <vers num="3.19"/>
        <vers num="3.19.1"/>
        <vers num="3.19.2"/>
        <vers num="3.19.3"/>
        <vers num="3.19.4"/>
        <vers num="3.19.5"/>
        <vers num="3.19.6"/>
        <vers num="3.19.7"/>
        <vers num="3.19.8"/>
        <vers num="4"/>
        <vers num="4.0" edition="rc5"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.1" edition="rc2"/>
        <vers num="4.1" edition="rc3"/>
        <vers num="4.1" edition="rc4"/>
        <vers num="4.1" edition="rc5"/>
        <vers num="4.1" edition="rc6"/>
        <vers num="4.1" edition="rc7"/>
        <vers num="4.1" edition="rc8"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.1.27"/>
        <vers num="4.1.28"/>
        <vers num="4.1.29"/>
        <vers num="4.1.30"/>
        <vers num="4.1.31"/>
        <vers num="4.1.32"/>
        <vers num="4.1.33"/>
        <vers num="4.1.34"/>
        <vers num="4.1.35"/>
        <vers num="4.1.36"/>
        <vers num="4.1.37"/>
        <vers num="4.1.38"/>
        <vers num="4.1.39"/>
        <vers num="4.1.40"/>
        <vers num="4.1.41"/>
        <vers num="4.1.42"/>
        <vers num="4.1.43"/>
        <vers num="4.1.44"/>
        <vers num="4.1.45"/>
        <vers num="4.1.46"/>
        <vers num="4.1.47"/>
        <vers num="4.1.48"/>
        <vers num="4.1.49"/>
        <vers num="4.1.50"/>
        <vers num="4.1.51"/>
        <vers num="4.1.52"/>
        <vers num="4.2" edition="rc1"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc3"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.2" edition="rc6"/>
        <vers num="4.2" edition="rc7"/>
        <vers num="4.2" edition="rc8"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.3" edition="rc1"/>
        <vers num="4.3" edition="rc2"/>
        <vers num="4.3" edition="rc3"/>
        <vers num="4.3" edition="rc4"/>
        <vers num="4.3" edition="rc5"/>
        <vers num="4.3" edition="rc6"/>
        <vers num="4.3" edition="rc7"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4" edition="rc8"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.4.19"/>
        <vers num="4.4.20"/>
        <vers num="4.4.21"/>
        <vers num="4.4.22"/>
        <vers num="4.4.23"/>
        <vers num="4.4.24"/>
        <vers num="4.4.25"/>
        <vers num="4.4.26"/>
        <vers num="4.4.27"/>
        <vers num="4.4.28"/>
        <vers num="4.4.29"/>
        <vers num="4.4.30"/>
        <vers num="4.4.31"/>
        <vers num="4.4.32"/>
        <vers num="4.4.33"/>
        <vers num="4.4.34"/>
        <vers num="4.4.35"/>
        <vers num="4.4.36"/>
        <vers num="4.4.37"/>
        <vers num="4.4.38"/>
        <vers num="4.4.39"/>
        <vers num="4.4.40"/>
        <vers num="4.4.41"/>
        <vers num="4.4.42"/>
        <vers num="4.4.43"/>
        <vers num="4.4.44"/>
        <vers num="4.4.45"/>
        <vers num="4.4.46"/>
        <vers num="4.4.47"/>
        <vers num="4.4.48"/>
        <vers num="4.4.49"/>
        <vers num="4.4.50"/>
        <vers num="4.4.51"/>
        <vers num="4.4.52"/>
        <vers num="4.4.53"/>
        <vers num="4.4.54"/>
        <vers num="4.4.55"/>
        <vers num="4.4.56"/>
        <vers num="4.4.57"/>
        <vers num="4.4.58"/>
        <vers num="4.4.59"/>
        <vers num="4.4.60"/>
        <vers num="4.4.61"/>
        <vers num="4.4.62"/>
        <vers num="4.4.63"/>
        <vers num="4.4.64"/>
        <vers num="4.4.65"/>
        <vers num="4.4.66"/>
        <vers num="4.4.67"/>
        <vers num="4.4.68"/>
        <vers num="4.4.69"/>
        <vers num="4.4.70"/>
        <vers num="4.4.71"/>
        <vers num="4.4.72"/>
        <vers num="4.4.73"/>
        <vers num="4.4.74"/>
        <vers num="4.4.75"/>
        <vers num="4.4.76"/>
        <vers num="4.4.77"/>
        <vers num="4.4.78"/>
        <vers num="4.4.79"/>
        <vers num="4.4.80"/>
        <vers num="4.4.81"/>
        <vers num="4.4.82"/>
        <vers num="4.4.83"/>
        <vers num="4.4.84"/>
        <vers num="4.4.85"/>
        <vers num="4.4.86"/>
        <vers num="4.4.87"/>
        <vers num="4.4.88"/>
        <vers num="4.4.89"/>
        <vers num="4.4.90"/>
        <vers num="4.4.91"/>
        <vers num="4.4.92"/>
        <vers num="4.4.93"/>
        <vers num="4.4.94"/>
        <vers num="4.4.95"/>
        <vers num="4.4.96"/>
        <vers num="4.4.97"/>
        <vers num="4.4.98"/>
        <vers num="4.4.99"/>
        <vers num="4.4.100"/>
        <vers num="4.4.101"/>
        <vers num="4.4.102"/>
        <vers num="4.4.103"/>
        <vers num="4.4.104"/>
        <vers num="4.4.105"/>
        <vers num="4.4.106"/>
        <vers num="4.4.107"/>
        <vers num="4.4.108"/>
        <vers num="4.4.109"/>
        <vers num="4.4.110"/>
        <vers num="4.4.111"/>
        <vers num="4.4.112"/>
        <vers num="4.4.113"/>
        <vers num="4.4.114"/>
        <vers num="4.4.115"/>
        <vers num="4.4.116"/>
        <vers num="4.4.117"/>
        <vers num="4.4.118"/>
        <vers num="4.4.119"/>
        <vers num="4.4.120"/>
        <vers num="4.4.121"/>
        <vers num="4.4.122"/>
        <vers num="4.4.123"/>
        <vers num="4.4.124"/>
        <vers num="4.4.125"/>
        <vers num="4.4.126"/>
        <vers num="4.4.127"/>
        <vers num="4.4.128"/>
        <vers num="4.4.129"/>
        <vers num="4.4.130"/>
        <vers num="4.4.131"/>
        <vers num="4.4.132"/>
        <vers num="4.4.133"/>
        <vers num="4.4.134"/>
        <vers num="4.4.135"/>
        <vers num="4.4.136"/>
        <vers num="4.4.137"/>
        <vers num="4.4.138"/>
        <vers num="4.4.139"/>
        <vers num="4.4.140"/>
        <vers num="4.4.141"/>
        <vers num="4.4.142"/>
        <vers num="4.4.143"/>
        <vers num="4.4.144"/>
        <vers num="4.4.145"/>
        <vers num="4.4.146"/>
        <vers num="4.4.147"/>
        <vers num="4.4.148"/>
        <vers num="4.4.149"/>
        <vers num="4.4.150"/>
        <vers num="4.4.151"/>
        <vers num="4.4.152"/>
        <vers num="4.4.153"/>
        <vers num="4.4.154"/>
        <vers num="4.4.155"/>
        <vers num="4.4.156"/>
        <vers num="4.4.157"/>
        <vers num="4.4.158"/>
        <vers num="4.4.159"/>
        <vers num="4.4.160"/>
        <vers num="4.4.161"/>
        <vers num="4.4.162"/>
        <vers num="4.4.163"/>
        <vers num="4.4.164"/>
        <vers num="4.4.165"/>
        <vers num="4.4.166"/>
        <vers num="4.4.167"/>
        <vers num="4.4.168"/>
        <vers num="4.4.169"/>
        <vers num="4.4.170"/>
        <vers num="4.4.171"/>
        <vers num="4.4.172"/>
        <vers num="4.4.173"/>
        <vers num="4.4.174"/>
        <vers num="4.4.175"/>
        <vers num="4.4.176"/>
        <vers num="4.4.177"/>
        <vers num="4.4.178"/>
        <vers num="4.4.179"/>
        <vers num="4.4.180"/>
        <vers num="4.4.181"/>
        <vers num="4.4.182"/>
        <vers num="4.4.183"/>
        <vers num="4.4.184"/>
        <vers num="4.4.185"/>
        <vers num="4.4.186"/>
        <vers num="4.4.187"/>
        <vers num="4.4.188"/>
        <vers num="4.4.189"/>
        <vers num="4.4.190"/>
        <vers num="4.5" edition="rc3"/>
        <vers num="4.5" edition="rc4"/>
        <vers num="4.5.0" edition="rc7"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.7" edition="rc1"/>
        <vers num="4.7" edition="rc2"/>
        <vers num="4.7" edition="rc3"/>
        <vers num="4.7" edition="rc4"/>
        <vers num="4.7" edition="rc5"/>
        <vers num="4.7" edition="rc6"/>
        <vers num="4.7" edition="rc7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7.10"/>
        <vers num="4.8" edition="rc5"/>
        <vers num="4.8" edition="rc6"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="4.8.10"/>
        <vers num="4.8.11"/>
        <vers num="4.8.12"/>
        <vers num="4.8.13"/>
        <vers num="4.8.14"/>
        <vers num="4.8.15"/>
        <vers num="4.8.16"/>
        <vers num="4.8.17"/>
        <vers num="4.9" edition="rc1"/>
        <vers num="4.9" edition="rc2"/>
        <vers num="4.9" edition="rc3"/>
        <vers num="4.9" edition="rc4"/>
        <vers num="4.9" edition="rc5"/>
        <vers num="4.9" edition="rc6"/>
        <vers num="4.9" edition="rc7"/>
        <vers num="4.9" edition="rc8"/>
        <vers num="4.9.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
        <vers num="4.9.13"/>
        <vers num="4.9.14"/>
        <vers num="4.9.15"/>
        <vers num="4.9.16"/>
        <vers num="4.9.17"/>
        <vers num="4.9.18"/>
        <vers num="4.9.19"/>
        <vers num="4.9.20"/>
        <vers num="4.9.21"/>
        <vers num="4.9.22"/>
        <vers num="4.9.23"/>
        <vers num="4.9.24"/>
        <vers num="4.9.25"/>
        <vers num="4.9.26"/>
        <vers num="4.9.27"/>
        <vers num="4.9.28"/>
        <vers num="4.9.29"/>
        <vers num="4.9.30"/>
        <vers num="4.9.31"/>
        <vers num="4.9.32"/>
        <vers num="4.9.33"/>
        <vers num="4.9.34"/>
        <vers num="4.9.35"/>
        <vers num="4.9.36"/>
        <vers num="4.9.37"/>
        <vers num="4.9.38"/>
        <vers num="4.9.39"/>
        <vers num="4.9.40"/>
        <vers num="4.9.41"/>
        <vers num="4.9.42"/>
        <vers num="4.9.43"/>
        <vers num="4.9.44"/>
        <vers num="4.9.45"/>
        <vers num="4.9.46"/>
        <vers num="4.9.47"/>
        <vers num="4.9.48"/>
        <vers num="4.9.49"/>
        <vers num="4.9.50"/>
        <vers num="4.9.51"/>
        <vers num="4.9.52"/>
        <vers num="4.9.53"/>
        <vers num="4.9.54"/>
        <vers num="4.9.55"/>
        <vers num="4.9.56"/>
        <vers num="4.9.57"/>
        <vers num="4.9.58"/>
        <vers num="4.9.59"/>
        <vers num="4.9.60"/>
        <vers num="4.9.61"/>
        <vers num="4.9.62"/>
        <vers num="4.9.63"/>
        <vers num="4.9.64"/>
        <vers num="4.9.65"/>
        <vers num="4.9.66"/>
        <vers num="4.9.67"/>
        <vers num="4.9.68"/>
        <vers num="4.9.69"/>
        <vers num="4.9.70"/>
        <vers num="4.9.71"/>
        <vers num="4.9.72"/>
        <vers num="4.9.73"/>
        <vers num="4.9.74"/>
        <vers num="4.9.75"/>
        <vers num="4.9.76"/>
        <vers num="4.9.77"/>
        <vers num="4.9.78"/>
        <vers num="4.9.79"/>
        <vers num="4.9.80"/>
        <vers num="4.9.81"/>
        <vers num="4.9.82"/>
        <vers num="4.9.83"/>
        <vers num="4.9.84"/>
        <vers num="4.9.85"/>
        <vers num="4.9.86"/>
        <vers num="4.9.87"/>
        <vers num="4.9.88"/>
        <vers num="4.9.89"/>
        <vers num="4.9.90"/>
        <vers num="4.9.91"/>
        <vers num="4.9.92"/>
        <vers num="4.9.93"/>
        <vers num="4.9.94"/>
        <vers num="4.9.95"/>
        <vers num="4.9.96"/>
        <vers num="4.9.97"/>
        <vers num="4.9.98"/>
        <vers num="4.9.99"/>
        <vers num="4.9.100"/>
        <vers num="4.9.101"/>
        <vers num="4.9.102"/>
        <vers num="4.9.103"/>
        <vers num="4.9.104"/>
        <vers num="4.9.105"/>
        <vers num="4.9.106"/>
        <vers num="4.9.107"/>
        <vers num="4.9.108"/>
        <vers num="4.9.109"/>
        <vers num="4.9.110"/>
        <vers num="4.9.111"/>
        <vers num="4.9.112"/>
        <vers num="4.9.113"/>
        <vers num="4.9.114"/>
        <vers num="4.9.115"/>
        <vers num="4.9.116"/>
        <vers num="4.9.117"/>
        <vers num="4.9.118"/>
        <vers num="4.9.119"/>
        <vers num="4.9.120"/>
        <vers num="4.9.121"/>
        <vers num="4.9.122"/>
        <vers num="4.9.123"/>
        <vers num="4.9.124"/>
        <vers num="4.9.125"/>
        <vers num="4.9.126"/>
        <vers num="4.9.127"/>
        <vers num="4.9.128"/>
        <vers num="4.9.129"/>
        <vers num="4.9.130"/>
        <vers num="4.9.131"/>
        <vers num="4.9.132"/>
        <vers num="4.9.133"/>
        <vers num="4.9.134"/>
        <vers num="4.9.135"/>
        <vers num="4.9.136"/>
        <vers num="4.9.137"/>
        <vers num="4.9.138"/>
        <vers num="4.9.139"/>
        <vers num="4.9.140"/>
        <vers num="4.9.141"/>
        <vers num="4.9.142"/>
        <vers num="4.9.143"/>
        <vers num="4.9.144"/>
        <vers num="4.9.145"/>
        <vers num="4.9.146"/>
        <vers num="4.9.147"/>
        <vers num="4.9.148"/>
        <vers num="4.9.149"/>
        <vers num="4.9.150"/>
        <vers num="4.9.151"/>
        <vers num="4.9.152"/>
        <vers num="4.9.153"/>
        <vers num="4.9.154"/>
        <vers num="4.9.155"/>
        <vers num="4.9.156"/>
        <vers num="4.9.157"/>
        <vers num="4.9.158"/>
        <vers num="4.9.159"/>
        <vers num="4.9.160"/>
        <vers num="4.9.161"/>
        <vers num="4.9.162"/>
        <vers num="4.9.163"/>
        <vers num="4.9.164"/>
        <vers num="4.9.165"/>
        <vers num="4.9.166"/>
        <vers num="4.9.167"/>
        <vers num="4.9.168"/>
        <vers num="4.9.169"/>
        <vers num="4.9.170"/>
        <vers num="4.9.171"/>
        <vers num="4.9.172"/>
        <vers num="4.9.173"/>
        <vers num="4.9.174"/>
        <vers num="4.9.175"/>
        <vers num="4.9.176"/>
        <vers num="4.9.177"/>
        <vers num="4.9.178"/>
        <vers num="4.9.179"/>
        <vers num="4.9.180"/>
        <vers num="4.9.181"/>
        <vers num="4.9.182"/>
        <vers num="4.9.183"/>
        <vers num="4.9.184"/>
        <vers num="4.9.185"/>
        <vers num="4.9.186"/>
        <vers num="4.9.187"/>
        <vers num="4.9.188"/>
        <vers num="4.9.189"/>
        <vers num="4.9.190"/>
        <vers num="4.10" edition="rc3"/>
        <vers num="4.10" edition="rc4"/>
        <vers num="4.10.1"/>
        <vers num="4.10.2"/>
        <vers num="4.10.3"/>
        <vers num="4.10.4"/>
        <vers num="4.10.5"/>
        <vers num="4.10.6"/>
        <vers num="4.10.7"/>
        <vers num="4.10.8"/>
        <vers num="4.10.9"/>
        <vers num="4.10.10"/>
        <vers num="4.10.11"/>
        <vers num="4.10.12"/>
        <vers num="4.10.13"/>
        <vers num="4.10.14"/>
        <vers num="4.10.15"/>
        <vers num="4.10.16"/>
        <vers num="4.10.17"/>
        <vers num="4.11" edition="rc1"/>
        <vers num="4.11" edition="rc2"/>
        <vers num="4.11" edition="rc3"/>
        <vers num="4.11" edition="rc4"/>
        <vers num="4.11" edition="rc5"/>
        <vers num="4.11" edition="rc6"/>
        <vers num="4.11" edition="rc7"/>
        <vers num="4.11.1"/>
        <vers num="4.11.2"/>
        <vers num="4.11.3"/>
        <vers num="4.11.4"/>
        <vers num="4.11.5"/>
        <vers num="4.11.6"/>
        <vers num="4.11.7"/>
        <vers num="4.11.8"/>
        <vers num="4.11.9"/>
        <vers num="4.11.10"/>
        <vers num="4.11.11"/>
        <vers num="4.11.12"/>
        <vers num="4.12" edition="rc1"/>
        <vers num="4.12" edition="rc2"/>
        <vers num="4.12" edition="rc3"/>
        <vers num="4.12" edition="rc4"/>
        <vers num="4.12" edition="rc5"/>
        <vers num="4.12" edition="rc6"/>
        <vers num="4.12.1"/>
        <vers num="4.12.2"/>
        <vers num="4.12.3"/>
        <vers num="4.12.4"/>
        <vers num="4.12.5"/>
        <vers num="4.12.6"/>
        <vers num="4.12.7"/>
        <vers num="4.12.8"/>
        <vers num="4.12.9"/>
        <vers num="4.12.10"/>
        <vers num="4.12.11"/>
        <vers num="4.12.12"/>
        <vers num="4.12.13"/>
        <vers num="4.12.14"/>
        <vers num="4.13" edition="rc1"/>
        <vers num="4.13" edition="rc2"/>
        <vers num="4.13" edition="rc3"/>
        <vers num="4.13" edition="rc4"/>
        <vers num="4.13" edition="rc5"/>
        <vers num="4.13" edition="rc6"/>
        <vers num="4.13.1"/>
        <vers num="4.13.2"/>
        <vers num="4.13.3"/>
        <vers num="4.13.4"/>
        <vers num="4.13.5"/>
        <vers num="4.13.6"/>
        <vers num="4.13.7"/>
        <vers num="4.13.8"/>
        <vers num="4.13.9"/>
        <vers num="4.13.10"/>
        <vers num="4.13.11"/>
        <vers num="4.13.12"/>
        <vers num="4.13.13"/>
        <vers num="4.13.14"/>
        <vers num="4.13.15"/>
        <vers num="4.13.16"/>
        <vers num="4.14"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.14.7"/>
        <vers num="4.14.8"/>
        <vers num="4.14.9"/>
        <vers num="4.14.10"/>
        <vers num="4.14.11"/>
        <vers num="4.14.12"/>
        <vers num="4.14.13"/>
        <vers num="4.14.14"/>
        <vers num="4.14.15"/>
        <vers num="4.14.16"/>
        <vers num="4.14.17"/>
        <vers num="4.14.18"/>
        <vers num="4.14.19"/>
        <vers num="4.14.20"/>
        <vers num="4.14.21"/>
        <vers num="4.14.22"/>
        <vers num="4.14.23"/>
        <vers num="4.14.24"/>
        <vers num="4.14.25"/>
        <vers num="4.14.26"/>
        <vers num="4.14.27"/>
        <vers num="4.14.28"/>
        <vers num="4.14.29"/>
        <vers num="4.14.30"/>
        <vers num="4.14.31"/>
        <vers num="4.14.32"/>
        <vers num="4.14.33"/>
        <vers num="4.14.34"/>
        <vers num="4.14.35"/>
        <vers num="4.14.36"/>
        <vers num="4.14.37"/>
        <vers num="4.14.38"/>
        <vers num="4.14.39"/>
        <vers num="4.14.40"/>
        <vers num="4.14.41"/>
        <vers num="4.14.42"/>
        <vers num="4.14.43"/>
        <vers num="4.14.44"/>
        <vers num="4.14.45"/>
        <vers num="4.14.46"/>
        <vers num="4.14.47"/>
        <vers num="4.14.48"/>
        <vers num="4.14.49"/>
        <vers num="4.14.50"/>
        <vers num="4.14.51"/>
        <vers num="4.14.52"/>
        <vers num="4.14.53"/>
        <vers num="4.14.54"/>
        <vers num="4.14.55"/>
        <vers num="4.14.56"/>
        <vers num="4.14.57"/>
        <vers num="4.14.58"/>
        <vers num="4.14.59"/>
        <vers num="4.14.60"/>
        <vers num="4.14.61"/>
        <vers num="4.14.62"/>
        <vers num="4.14.63"/>
        <vers num="4.14.64"/>
        <vers num="4.14.65"/>
        <vers num="4.14.66"/>
        <vers num="4.14.67"/>
        <vers num="4.14.68"/>
        <vers num="4.14.69"/>
        <vers num="4.14.70"/>
        <vers num="4.14.71"/>
        <vers num="4.14.72"/>
        <vers num="4.14.73"/>
        <vers num="4.14.74"/>
        <vers num="4.14.75"/>
        <vers num="4.14.76"/>
        <vers num="4.14.77"/>
        <vers num="4.14.78"/>
        <vers num="4.14.79"/>
        <vers num="4.14.80"/>
        <vers num="4.14.81"/>
        <vers num="4.14.82"/>
        <vers num="4.14.83"/>
        <vers num="4.14.84"/>
        <vers num="4.14.85"/>
        <vers num="4.14.86"/>
        <vers num="4.14.87"/>
        <vers num="4.14.88"/>
        <vers num="4.14.89"/>
        <vers num="4.14.90"/>
        <vers num="4.14.91"/>
        <vers num="4.14.92"/>
        <vers num="4.14.93"/>
        <vers num="4.14.94"/>
        <vers num="4.14.95"/>
        <vers num="4.14.96"/>
        <vers num="4.14.97"/>
        <vers num="4.14.98"/>
        <vers num="4.14.99"/>
        <vers num="4.14.100"/>
        <vers num="4.14.101"/>
        <vers num="4.14.102"/>
        <vers num="4.14.103"/>
        <vers num="4.14.104"/>
        <vers num="4.14.105"/>
        <vers num="4.14.106"/>
        <vers num="4.14.107"/>
        <vers num="4.14.108"/>
        <vers num="4.14.109"/>
        <vers num="4.14.110"/>
        <vers num="4.14.111"/>
        <vers num="4.14.112"/>
        <vers num="4.14.113"/>
        <vers num="4.14.114"/>
        <vers num="4.14.115"/>
        <vers num="4.14.116"/>
        <vers num="4.14.117"/>
        <vers num="4.14.118"/>
        <vers num="4.14.119"/>
        <vers num="4.14.120"/>
        <vers num="4.14.121"/>
        <vers num="4.14.122"/>
        <vers num="4.14.123"/>
        <vers num="4.14.124"/>
        <vers num="4.14.125"/>
        <vers num="4.14.126"/>
        <vers num="4.14.127"/>
        <vers num="4.14.128"/>
        <vers num="4.14.129"/>
        <vers num="4.14.130"/>
        <vers num="4.14.131"/>
        <vers num="4.14.132"/>
        <vers num="4.14.133"/>
        <vers num="4.14.134"/>
        <vers num="4.14.135"/>
        <vers num="4.14.136"/>
        <vers num="4.14.137"/>
        <vers num="4.14.138"/>
        <vers num="4.14.139"/>
        <vers num="4.14.140"/>
        <vers num="4.14.141"/>
        <vers num="4.15" edition="rc1"/>
        <vers num="4.15" edition="rc2"/>
        <vers num="4.15" edition="rc3"/>
        <vers num="4.15" edition="rc4"/>
        <vers num="4.15" edition="rc5"/>
        <vers num="4.15" edition="rc6"/>
        <vers num="4.15" edition="rc7"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000411" seq="2017-1000411" published="2018-01-31" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple different flows with 'idle-timeout' and 'hard-timeout' are sent to the Openflow Plugin REST API, the expired flows will eventually crash the controller once its resource allocations set with the JVM size are exceeded. Although the installed flows (with timeout set) are removed from network (and thus also from controller's operations DS), the expired entries are still present in CONFIG DS. The attack can originate both from NORTH or SOUTH. The above description is for a north bound attack. A south bound attack can originate when an attacker attempts a flow flooding attack and since flows come with timeouts, the attack is not successful. However, the attacker will now be successful in CONTROLLER overflow attack (resource consumption). Although, the network (actual flow tables) and operational DS are only (~)1% occupied, the controller requests for resource consumption. This happens because the installed flows get removed from the network upon timeout.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2018/q1/52" adv="1">[oss-security] 20180116 opendaylight-advisory: Multiple "expired" flows consume the memory resource of CONFIG DS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102736" adv="1">102736</ref>
    </refs>
    <vuln_soft>
      <prod name="opendaylight" vendor="opendaylight">
        <vers num="boron"/>
        <vers num="carbon"/>
        <vers num="nitrogen"/>
      </prod>
      <prod name="openflow" vendor="opendaylight">
        <vers num="boron" edition=":~~~opendaylight~~"/>
        <vers num="carbon" edition=":~~~opendaylight~~"/>
        <vers num="nitrogen" edition=":~~~opendaylight~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000412" seq="2017-1000412" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/OP-TEE/optee_os/blob/2.5.0/CHANGELOG.md" adv="1">https://github.com/OP-TEE/optee_os/blob/2.5.0/CHANGELOG.md</ref>
      <ref source="CONFIRM" url="https://github.com/OP-TEE/optee_os/pull/1610" adv="1">https://github.com/OP-TEE/optee_os/pull/1610</ref>
      <ref source="CONFIRM" url="https://www.op-tee.org/security-advisories/" adv="1">https://www.op-tee.org/security-advisories/</ref>
    </refs>
    <vuln_soft>
      <prod name="op-tee" vendor="linaro">
        <vers num="2.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000413" seq="2017-1000413" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/OP-TEE/optee_os/blob/2.5.0/CHANGELOG.md" adv="1">https://github.com/OP-TEE/optee_os/blob/2.5.0/CHANGELOG.md</ref>
      <ref source="CONFIRM" url="https://github.com/OP-TEE/optee_os/pull/1610" adv="1">https://github.com/OP-TEE/optee_os/pull/1610</ref>
      <ref source="CONFIRM" url="https://www.op-tee.org/security-advisories/" adv="1">https://www.op-tee.org/security-advisories/</ref>
    </refs>
    <vuln_soft>
      <prod name="op-tee" vendor="linaro">
        <vers num="2.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000414" seq="2017-1000414" published="2018-01-25" modified="2018-02-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ImpulseAdventure JPEGsnoop version 1.7.5 is vulnerable to a division by zero in the JFIF decode handling resulting denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/ImpulseAdventure/JPEGsnoop/commit/b4e458612d4294e0cfe01dbf1c0b09a07a8133a4#diff-cf9182aecc9d630e8db2e0e35f1eec65" patch="1">https://github.com/ImpulseAdventure/JPEGsnoop/commit/b4e458612d4294e0cfe01dbf1c0b09a07a8133a4#diff-cf9182aecc9d630e8db2e0e35f1eec65</ref>
      <ref source="CONFIRM" url="https://www.impulseadventure.com/photo/jpeg-snoop-history.html">https://www.impulseadventure.com/photo/jpeg-snoop-history.html</ref>
    </refs>
    <vuln_soft>
      <prod name="jpegsnoop" vendor="impulseadventure">
        <vers num="1.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000415" seq="2017-1000415" published="2018-01-09" modified="2018-01-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.ieee-security.org/TC/SP2017/papers/231.pdf" adv="1">https://www.ieee-security.org/TC/SP2017/papers/231.pdf</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=FW--c_F_cY8" adv="1">https://www.youtube.com/watch?v=FW--c_F_cY8</ref>
    </refs>
    <vuln_soft>
      <prod name="matrixssl" vendor="matrixssl">
        <vers num="3.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000416" seq="2017-1000416" published="2018-01-22" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">axTLS version 1.5.3 has a coding error in the ASN.1 parser resulting in the year (19)50 of UTCTime being misinterpreted as 2050.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.ieee-security.org/TC/SP2017/papers/231.pdf" adv="1">https://www.ieee-security.org/TC/SP2017/papers/231.pdf</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=FW--c_F_cY8" adv="1">https://www.youtube.com/watch?v=FW--c_F_cY8</ref>
    </refs>
    <vuln_soft>
      <prod name="axtls" vendor="axtls_project">
        <vers num="1.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000417" seq="2017-1000417" published="2018-01-22" modified="2018-02-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matrixssl/matrixssl/blob/master/doc/CHANGES.md">https://github.com/matrixssl/matrixssl/blob/master/doc/CHANGES.md</ref>
      <ref source="MISC" url="https://www.ieee-security.org/TC/SP2017/papers/231.pdf" adv="1">https://www.ieee-security.org/TC/SP2017/papers/231.pdf</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=FW--c_F_cY8" adv="1">https://www.youtube.com/watch?v=FW--c_F_cY8</ref>
    </refs>
    <vuln_soft>
      <prod name="matrixssl" vendor="matrixssl">
        <vers num="3.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000418" seq="2017-1000418" published="2018-01-02" modified="2018-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Mindwerks/wildmidi/commit/814f31d8eceda8401eb812fc2e94ed143fdad0ab" adv="1" patch="1">https://github.com/Mindwerks/wildmidi/commit/814f31d8eceda8401eb812fc2e94ed143fdad0ab</ref>
      <ref source="CONFIRM" url="https://github.com/Mindwerks/wildmidi/issues/178" adv="1">https://github.com/Mindwerks/wildmidi/issues/178</ref>
    </refs>
    <vuln_soft>
      <prod name="wildmidi" vendor="mindwerks">
        <vers num="0.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000419" seq="2017-1000419" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.phpbb.com/community/viewtopic.php?f=14&amp;p=14782136" adv="1">https://www.phpbb.com/community/viewtopic.php?f=14&amp;p=14782136</ref>
      <ref source="MISC" url="https://www.sec-consult.com/en/blog/advisories/phpbb-server-side-request-forgery-vulnerability/index.html" adv="1">https://www.sec-consult.com/en/blog/advisories/phpbb-server-side-request-forgery-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb">
        <vers num="3.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000420" seq="2017-1000420" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/syncthing/syncthing/issues/4286" adv="1" patch="1">https://github.com/syncthing/syncthing/issues/4286</ref>
    </refs>
    <vuln_soft>
      <prod name="syncthing" vendor="syncthing">
        <vers num="0.14.33" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000421" seq="2017-1000421" published="2018-01-02" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/kohler/gifsicle/issues/114" adv="1" patch="1">https://github.com/kohler/gifsicle/issues/114</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00006.html" adv="1">[debian-lts-announce] 20180108 [SECURITY] [DLA 1233-1] gifsicle security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4084" adv="1">DSA-4084</ref>
    </refs>
    <vuln_soft>
      <prod name="gifsicle" vendor="gifsicle_project">
        <vers num="1.89" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000422" seq="2017-1000422" published="2018-01-02" modified="2019-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.gnome.org/show_bug.cgi?id=785973" adv="1" patch="1">https://bugzilla.gnome.org/show_bug.cgi?id=785973</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00007.html" adv="1">[debian-lts-announce] 20180108 [SECURITY] [DLA 1234-1] gdk-pixbuf security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-14" adv="1">GLSA-201804-14</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3532-1/" adv="1">USN-3532-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4088" adv="1">DSA-4088</ref>
    </refs>
    <vuln_soft>
      <prod name="gdk-pixbuf" vendor="gnome">
        <vers num="2.36.8" prev="1"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000423" seq="2017-1000423" published="2018-01-02" modified="2018-01-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/b2evolution/b2evolution/commit/0096a3ebc85f6aadbda2c4427cd092a538b161d2" adv="1" patch="1">https://github.com/b2evolution/b2evolution/commit/0096a3ebc85f6aadbda2c4427cd092a538b161d2</ref>
      <ref source="CONFIRM" url="https://github.com/b2evolution/b2evolution/commit/b899d654d931f3bf3cfbbdd71e0d1a0f3a16d04c" adv="1" patch="1">https://github.com/b2evolution/b2evolution/commit/b899d654d931f3bf3cfbbdd71e0d1a0f3a16d04c</ref>
    </refs>
    <vuln_soft>
      <prod name="b2evolution" vendor="b2evolution">
        <vers num="6.6.0"/>
        <vers num="6.6.1"/>
        <vers num="6.6.2"/>
        <vers num="6.6.3"/>
        <vers num="6.6.4"/>
        <vers num="6.6.5"/>
        <vers num="6.6.6"/>
        <vers num="6.6.7"/>
        <vers num="6.6.8"/>
        <vers num="6.6.9"/>
        <vers num="6.6.10"/>
        <vers num="6.7.0" edition="alpha"/>
        <vers num="6.7.1" edition="beta"/>
        <vers num="6.7.2"/>
        <vers num="6.7.3"/>
        <vers num="6.7.4"/>
        <vers num="6.7.5"/>
        <vers num="6.7.6"/>
        <vers num="6.7.7"/>
        <vers num="6.7.8"/>
        <vers num="6.7.9"/>
        <vers num="6.7.10"/>
        <vers num="6.7.11"/>
        <vers num="6.8.0" edition="beta"/>
        <vers num="6.8.1"/>
        <vers num="6.8.2"/>
        <vers num="6.8.3"/>
        <vers num="6.8.4"/>
        <vers num="6.8.5"/>
        <vers num="6.8.6"/>
        <vers num="6.8.7"/>
        <vers num="6.8.8"/>
        <vers num="6.8.9"/>
        <vers num="6.8.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000424" seq="2017-1000424" published="2018-01-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/electron/electron/pull/10008" adv="1">https://github.com/electron/electron/pull/10008</ref>
      <ref source="CONFIRM" url="https://github.com/electron/electron/pull/10008/files" adv="1">https://github.com/electron/electron/pull/10008/files</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000425" seq="2017-1000425" published="2018-01-02" modified="2018-03-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://dev.liferay.com/web/community-security-team/known-vulnerabilities/-/asset_publisher/4AHAYapUm8Xc/content/cst-7030-multiple-xss-vulnerabilities-in-7-0-ce-ga4" adv="1" patch="1">https://dev.liferay.com/web/community-security-team/known-vulnerabilities/-/asset_publisher/4AHAYapUm8Xc/content/cst-7030-multiple-xss-vulnerabilities-in-7-0-ce-ga4</ref>
      <ref source="MISC" url="https://github.com/liferay/liferay-portal/commit/9435af4ef8a90b5333da925a5ec860a43d18c031" adv="1" patch="1">https://github.com/liferay/liferay-portal/commit/9435af4ef8a90b5333da925a5ec860a43d18c031</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1000426" seq="2017-1000426" published="2018-01-02" modified="2019-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/mapproxy/mapproxy/issues/322" adv="1" patch="1">https://github.com/mapproxy/mapproxy/issues/322</ref>
    </refs>
    <vuln_soft>
      <prod name="mapproxy" vendor="omniscale">
        <vers num="1.10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000427" seq="2017-1000427" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://snyk.io/vuln/npm:marked:20170112" adv="1" patch="1">https://snyk.io/vuln/npm:marked:20170112</ref>
    </refs>
    <vuln_soft>
      <prod name="marked" vendor="marked_project">
        <vers num="0.3.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000428" seq="2017-1000428" published="2018-01-09" modified="2018-01-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/flatCore/flatCore-CMS/issues/35" adv="1">https://github.com/flatCore/flatCore-CMS/issues/35</ref>
    </refs>
    <vuln_soft>
      <prod name="flatcore-cms" vendor="flatcore">
        <vers num="1.4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000429" seq="2017-1000429" published="2018-01-09" modified="2018-01-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lucifaer.com/index.php/archives/35/" adv="1">http://lucifaer.com/index.php/archives/35/</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="5.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000430" seq="2017-1000430" published="2018-01-02" modified="2018-01-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">rust-base64 version &lt;= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/RustSec/advisory-db/blob/master/crates/base64/RUSTSEC-2017-0004.toml" adv="1">https://github.com/RustSec/advisory-db/blob/master/crates/base64/RUSTSEC-2017-0004.toml</ref>
    </refs>
    <vuln_soft>
      <prod name="rust-base64" vendor="rust-base64_project">
        <vers num="0.5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000431" seq="2017-1000431" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://share.ez.no/community-project/security-advisories/ezsa-2017-005-xss-issue-in-search" adv="1" patch="1">http://share.ez.no/community-project/security-advisories/ezsa-2017-005-xss-issue-in-search</ref>
    </refs>
    <vuln_soft>
      <prod name="ez_publish" vendor="ez">
        <vers num="5.3.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000432" seq="2017-1000432" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://open.vanillaforums.com/discussion/28337/vanilla-2-1-5-released-and-2-0-18-14">https://open.vanillaforums.com/discussion/28337/vanilla-2-1-5-released-and-2-0-18-14</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43462/" adv="1">43462</ref>
    </refs>
    <vuln_soft>
      <prod name="vanilla_forums" vendor="vanillaforums">
        <vers num="-"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.16.1"/>
        <vers num="2.0.17"/>
        <vers num="2.0.17.1"/>
        <vers num="2.0.17.2"/>
        <vers num="2.0.17.3"/>
        <vers num="2.0.17.4"/>
        <vers num="2.0.17.5"/>
        <vers num="2.0.17.6"/>
        <vers num="2.0.17.7"/>
        <vers num="2.0.17.8"/>
        <vers num="2.0.17.9"/>
        <vers num="2.0.17.10"/>
        <vers num="2.0.18" edition="a3"/>
        <vers num="2.0.18" edition="b1"/>
        <vers num="2.0.18" edition="b2"/>
        <vers num="2.0.18" edition="b4"/>
        <vers num="2.0.18" edition="rc1"/>
        <vers num="2.0.18" edition="rc2"/>
        <vers num="2.0.18" edition="rc3"/>
        <vers num="2.0.18.1"/>
        <vers num="2.0.18.3"/>
        <vers num="2.0.18.4"/>
        <vers num="2.0.18.5"/>
        <vers num="2.0.18.6"/>
        <vers num="2.0.18.7"/>
        <vers num="2.0.18.12"/>
        <vers num="2.1" edition="a26"/>
        <vers num="2.1" edition="a32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000433" seq="2017-1000433" published="2018-01-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/rohe/pysaml2/issues/451" adv="1" patch="1">https://github.com/rohe/pysaml2/issues/451</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00000.html" adv="1">[debian-lts-announce] 20180701 [SECURITY] [DLA 1410-1] python-pysaml2 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201801-11" adv="1">GLSA-201801-11</ref>
    </refs>
    <vuln_soft>
      <prod name="pysaml2" vendor="pysaml2_project">
        <vers num="4.4.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000434" seq="2017-1000434" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-redirect']));</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://cjc.im/advisories/0008/" adv="1">https://cjc.im/advisories/0008/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8992" adv="1">https://wpvulndb.com/vulnerabilities/8992</ref>
    </refs>
    <vuln_soft>
      <prod name="furikake" vendor="furikake_project">
        <vers num="0.1.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000435" seq="2017-1000435" published="2017-12-30" modified="2017-12-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-16227. Reason: This candidate is a reservation duplicate of CVE-2017-16227. Notes: All CVE users should reference CVE-2017-16227 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000436" seq="2017-1000436" published="2017-12-30" modified="2017-12-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-14975. Reason: This candidate is a reservation duplicate of CVE-2017-14975. Notes: All CVE users should reference CVE-2017-14975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000437" seq="2017-1000437" published="2018-01-02" modified="2018-01-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/marcobambini/gravity/issues/186" adv="1">https://github.com/marcobambini/gravity/issues/186</ref>
    </refs>
    <vuln_soft>
      <prod name="gravity" vendor="creolabs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000438" seq="2017-1000438" published="2018-01-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.openmicroscopy.org/security/advisories/2017-SV5-filename-2/" adv="1">https://www.openmicroscopy.org/security/advisories/2017-SV5-filename-2/</ref>
    </refs>
    <vuln_soft>
      <prod name="omero" vendor="openmicroscopy">
        <vers num="5.3.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000439" seq="2017-1000439" published="2018-01-10" modified="2018-01-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-14601.  Reason: This candidate is a reservation duplicate of CVE-2017-14601.  Notes: All CVE users should reference CVE-2017-14601 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000440" seq="2017-1000440" published="2017-12-30" modified="2017-12-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-14976. Reason: This candidate is a reservation duplicate of CVE-2017-14976. Notes: All CVE users should reference CVE-2017-14976 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000441" seq="2017-1000441" published="2018-01-10" modified="2018-01-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-14931.  Reason: This candidate is a reservation duplicate of CVE-2017-14931.  Notes: All CVE users should reference CVE-2017-14931 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000442" seq="2017-1000442" published="2018-01-02" modified="2018-01-16" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.passbolt.com/incidents/20170914_xss_on_resource_urls" adv="1">https://www.passbolt.com/incidents/20170914_xss_on_resource_urls</ref>
      <ref source="CONFIRM" url="https://www.passbolt.com/release/notes#September" adv="1" patch="1">https://www.passbolt.com/release/notes#September</ref>
    </refs>
    <vuln_soft>
      <prod name="passbolt_api" vendor="passbolt">
        <vers num="1.6.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000443" seq="2017-1000443" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Eleix/openhacker/commit/9da5c237ba5e2311f01edc83389bc5aaf0a9885c" patch="1">https://github.com/Eleix/openhacker/commit/9da5c237ba5e2311f01edc83389bc5aaf0a9885c</ref>
      <ref source="CONFIRM" url="https://github.com/Eleix/openhacker/issues/5" adv="1">https://github.com/Eleix/openhacker/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="openhacker" vendor="openhacker_project">
        <vers num="0.1.47"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000444" seq="2017-1000444" published="2018-01-02" modified="2018-01-11" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Eleix/openhacker/commit/9da5c237ba5e2311f01edc83389bc5aaf0a9885c" patch="1">https://github.com/Eleix/openhacker/commit/9da5c237ba5e2311f01edc83389bc5aaf0a9885c</ref>
      <ref source="CONFIRM" url="https://github.com/Eleix/openhacker/issues/4" adv="1">https://github.com/Eleix/openhacker/issues/4</ref>
    </refs>
    <vuln_soft>
      <prod name="openhacker" vendor="openhacker_project">
        <vers num="0.1.47"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000445" seq="2017-1000445" published="2018-01-02" modified="2019-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102368" adv="1">102368</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/775" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/775</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00002.html" adv="1">[debian-lts-announce] 20180104 [SECURITY] [DLA 1229-1] imagemagick security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html">[debian-lts-announce] 20190514 [SECURITY] [DLA 1785-1] imagemagick security update</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3681-1/" adv="1">USN-3681-1</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.7-1" prev="1"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
        <vers num="18.04" edition=":~~lts~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000446" seq="2017-1000446" published="2017-12-30" modified="2017-12-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-15954. Reason: This candidate is a reservation duplicate of CVE-2017-15954. Notes: All CVE users should reference CVE-2017-15954 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000447" seq="2017-1000447" published="2017-12-30" modified="2017-12-30" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-15955. Reason: This candidate is a reservation duplicate of CVE-2017-15955. Notes: All CVE users should reference CVE-2017-15955 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000448" seq="2017-1000448" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/structured-data/linter/issues/41" adv="1">https://github.com/structured-data/linter/issues/41</ref>
    </refs>
    <vuln_soft>
      <prod name="structured_data_linter" vendor="structured-data">
        <vers num="2.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000449" seq="2017-1000449" published="2018-01-02" modified="2018-01-03" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000450" seq="2017-1000450" published="2018-01-02" modified="2019-03-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/blendin/pocs/blob/master/opencv/0.OOB_Write_FillUniColor" adv="1">https://github.com/blendin/pocs/blob/master/opencv/0.OOB_Write_FillUniColor</ref>
      <ref source="MISC" url="https://github.com/opencv/opencv/issues/9723" adv="1">https://github.com/opencv/opencv/issues/9723</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00008.html" adv="1">[debian-lts-announce] 20180108 [SECURITY] [DLA 1235-1] opencv security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00030.html" adv="1">[debian-lts-announce] 20180722 [SECURITY] [DLA 1438-1] opencv security update</ref>
    </refs>
    <vuln_soft>
      <prod name="opencv" vendor="opencv">
        <vers num="3.3.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000451" seq="2017-1000451" published="2018-01-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://nodesecurity.io/advisories/360" adv="1" patch="1">https://nodesecurity.io/advisories/360</ref>
    </refs>
    <vuln_soft>
      <prod name="fs-git" vendor="fs-git_project">
        <vers num="1.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000452" seq="2017-1000452" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/tngan/samlify/releases/tag/v2.3.0" adv="1" patch="1">https://github.com/tngan/samlify/releases/tag/v2.3.0</ref>
      <ref source="MISC" url="https://www.whitehats.nl/blog/xml-signature-wrapping-samlify" adv="1">https://www.whitehats.nl/blog/xml-signature-wrapping-samlify</ref>
    </refs>
    <vuln_soft>
      <prod name="samlify" vendor="samlify_project">
        <vers num="2.2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000453" seq="2017-1000453" published="2018-01-02" modified="2018-01-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.cmsmadesimple.org/2017/06/Announcing-CMSMS-2-2-1-Hearts-Desire/" adv="1">https://www.cmsmadesimple.org/2017/06/Announcing-CMSMS-2-2-1-Hearts-Desire/</ref>
    </refs>
    <vuln_soft>
      <prod name="cms_made_simple" vendor="cmsmadesimple">
        <vers num="-"/>
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.11"/>
        <vers num="0.11.1"/>
        <vers num="0.11.2"/>
        <vers num="0.12"/>
        <vers num="0.12.1"/>
        <vers num="0.12.2"/>
        <vers num="0.13"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.2.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.3.1"/>
        <vers num="1.1.4"/>
        <vers num="1.1.4.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3" edition="beta1"/>
        <vers num="1.3" edition="beta2"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.6.10"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.9"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.4.1"/>
        <vers num="1.9.4.2"/>
        <vers num="1.9.4.3"/>
        <vers num="1.10"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.2.1"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.11.7"/>
        <vers num="1.11.8"/>
        <vers num="1.11.9"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.12"/>
        <vers num="1.11.13"/>
        <vers num="1.12"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="2.0" edition="-"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="beta2"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="beta4"/>
        <vers num="2.0.1"/>
        <vers num="2.0.1.1"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3.1"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.9.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3" edition="beta4"/>
        <vers num="2.3" edition="beta5"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4" edition="beta4"/>
        <vers num="2.4" edition="beta5"/>
        <vers num="2.7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000454" seq="2017-1000454" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-Content" adv="1">https://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-Content</ref>
    </refs>
    <vuln_soft>
      <prod name="cms_made_simple" vendor="cmsmadesimple">
        <vers num="-"/>
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.11"/>
        <vers num="0.11.1"/>
        <vers num="0.11.2"/>
        <vers num="0.12"/>
        <vers num="0.12.1"/>
        <vers num="0.12.2"/>
        <vers num="0.13"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.2.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.3.1"/>
        <vers num="1.1.4"/>
        <vers num="1.1.4.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3" edition="beta1"/>
        <vers num="1.3" edition="beta2"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.6.10"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.9"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.4.1"/>
        <vers num="1.9.4.2"/>
        <vers num="1.9.4.3"/>
        <vers num="1.10"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.2.1"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.11.7"/>
        <vers num="1.11.8"/>
        <vers num="1.11.9"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.12"/>
        <vers num="1.11.13"/>
        <vers num="1.12"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="2.0" edition="-"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="beta2"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="beta4"/>
        <vers num="2.0.1"/>
        <vers num="2.0.1.1"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3.1"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.9.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3" edition="beta4"/>
        <vers num="2.3" edition="beta5"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4" edition="beta4"/>
        <vers num="2.4" edition="beta5"/>
        <vers num="2.7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000455" seq="2017-1000455" published="2018-01-02" modified="2018-01-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://lists.gnu.org/archive/html/guix-devel/2017-10/msg00090.html" adv="1" patch="1">https://lists.gnu.org/archive/html/guix-devel/2017-10/msg00090.html</ref>
    </refs>
    <vuln_soft>
      <prod name="guixsd" vendor="gnu">
        <vers num="0.13.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000456" seq="2017-1000456" published="2018-01-02" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.freedesktop.org/show_bug.cgi?id=103116" adv="1" patch="1">https://bugs.freedesktop.org/show_bug.cgi?id=103116</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00001.html" adv="1">[debian-lts-announce] 20180103 [SECURITY] [DLA 1228-1] poppler security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4097" adv="1">DSA-4097</ref>
    </refs>
    <vuln_soft>
      <prod name="poppler" vendor="freedesktop">
        <vers num="0.60.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000457" seq="2017-1000457" published="2018-01-02" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/i7MEDIA/mojoportal/commit/5ea8129f74c80cbf1f68b9083c745cc8a685485d" patch="1">https://github.com/i7MEDIA/mojoportal/commit/5ea8129f74c80cbf1f68b9083c745cc8a685485d</ref>
      <ref source="MISC" url="https://www.mojoportal.com/mojoportal-2-6">https://www.mojoportal.com/mojoportal-2-6</ref>
    </refs>
    <vuln_soft>
      <prod name="mojoportal" vendor="mojoportal">
        <vers num="2.5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000458" seq="2017-1000458" published="2018-01-02" modified="2018-01-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bro-tracker.atlassian.net/browse/BIT-1856" adv="1">https://bro-tracker.atlassian.net/browse/BIT-1856</ref>
      <ref source="MISC" url="https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282" adv="1">https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282</ref>
    </refs>
    <vuln_soft>
      <prod name="bro" vendor="bro">
        <vers num="2.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000459" seq="2017-1000459" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Leanote version &lt;= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/leanote/leanote/issues/676" adv="1">https://github.com/leanote/leanote/issues/676</ref>
    </refs>
    <vuln_soft>
      <prod name="leanote" vendor="leanote">
        <vers num="2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000460" seq="2017-1000460" published="2018-01-03" modified="2019-03-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&amp;gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.libav.org/show_bug.cgi?id=952" adv="1">https://bugzilla.libav.org/show_bug.cgi?id=952</ref>
      <ref source="MISC" url="https://chromium.googlesource.com/chromium/third_party/ffmpeg/+/8e313ca08800178efce00045e07dc494d437b70c" patch="1">https://chromium.googlesource.com/chromium/third_party/ffmpeg/+/8e313ca08800178efce00045e07dc494d437b70c</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/03/msg00041.html">[debian-lts-announce] 20190330 [SECURITY] [DLA 1740-1] libav security update</ref>
      <ref source="MISC" url="https://lists.ffmpeg.org/pipermail/ffmpeg-cvslog/2017-January/104221.html" patch="1">https://lists.ffmpeg.org/pipermail/ffmpeg-cvslog/2017-January/104221.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ffmpeg" vendor="ffmpeg">
        <vers num="3.4"/>
      </prod>
      <prod name="chrome" vendor="google">
        <vers num="56.0.2924" prev="1"/>
      </prod>
      <prod name="libav" vendor="libav">
        <vers num="13_dev0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000461" seq="2017-1000461" published="2018-01-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/brave/browser-laptop/issues/11683#issuecomment-339835601" adv="1">https://github.com/brave/browser-laptop/issues/11683#issuecomment-339835601</ref>
    </refs>
    <vuln_soft>
      <prod name="browser" vendor="brave">
        <vers num="0.19.73" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000462" seq="2017-1000462" published="2018-01-03" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/BookStackApp/BookStack/issues/575" adv="1">https://github.com/BookStackApp/BookStack/issues/575</ref>
    </refs>
    <vuln_soft>
      <prod name="bookstack" vendor="bookstackapp">
        <vers num="0.18.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000463" seq="2017-1000463" published="2018-01-02" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/Leafpub/leafpub/issues/125" adv="1">https://github.com/Leafpub/leafpub/issues/125</ref>
    </refs>
    <vuln_soft>
      <prod name="leafpub" vendor="leafpub">
        <vers num="1.2.0" edition="beta6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000464" seq="2017-1000464" published="2018-01-25" modified="2018-01-25" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000465" seq="2017-1000465" published="2018-01-09" modified="2018-02-01" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/sulu/sulu-standard/issues/835" adv="1">https://github.com/sulu/sulu-standard/issues/835</ref>
    </refs>
    <vuln_soft>
      <prod name="sulu-standard" vendor="sulu">
        <vers num="1.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000466" seq="2017-1000466" published="2018-01-02" modified="2018-01-16" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/invoiceninja/invoiceninja/issues/1727" adv="1">https://github.com/invoiceninja/invoiceninja/issues/1727</ref>
    </refs>
    <vuln_soft>
      <prod name="invoice_ninja" vendor="invoiceninja">
        <vers num="3.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000467" seq="2017-1000467" published="2018-01-03" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/LavaLite/cms/issues/209" adv="1">https://github.com/LavaLite/cms/issues/209</ref>
    </refs>
    <vuln_soft>
      <prod name="lavalite" vendor="lavalite">
        <vers num="5.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000468" seq="2017-1000468" published="2018-01-25" modified="2018-01-25" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000469" seq="2017-1000469" published="2018-01-03" modified="2018-01-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/cobbler/cobbler/issues/1845" adv="1">https://github.com/cobbler/cobbler/issues/1845</ref>
    </refs>
    <vuln_soft>
      <prod name="cobbler" vendor="cobbler_project">
        <vers num="2.8.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000470" seq="2017-1000470" published="2018-01-03" modified="2018-01-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/embedthis/goahead/commit/adeb4abc6c998c19524e09fde20c02b4a26765a3" adv="1" patch="1">https://github.com/embedthis/goahead/commit/adeb4abc6c998c19524e09fde20c02b4a26765a3</ref>
      <ref source="MISC" url="https://github.com/embedthis/goahead/pull/258" adv="1" patch="1">https://github.com/embedthis/goahead/pull/258</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead_web_server" vendor="embedthis">
        <vers num="4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000471" seq="2017-1000471" published="2018-01-03" modified="2018-01-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/embedthis/goahead/commit/5e6be61e42448f503e75e287dc332b1ecbf2a665#diff-7c9c60c790648b06210f57b9e2f53ca7" adv="1" patch="1">https://github.com/embedthis/goahead/commit/5e6be61e42448f503e75e287dc332b1ecbf2a665#diff-7c9c60c790648b06210f57b9e2f53ca7</ref>
      <ref source="MISC" url="https://github.com/embedthis/goahead/pull/258" adv="1">https://github.com/embedthis/goahead/pull/258</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead" vendor="embedthis">
        <vers num="4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000472" seq="2017-1000472" published="2018-01-03" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/pocoproject/poco/issues/1968" patch="1">https://github.com/pocoproject/poco/issues/1968</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00013.html">[debian-lts-announce] 20180110 [SECURITY] [DLA 1239-1] poco security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4083" adv="1">DSA-4083</ref>
    </refs>
    <vuln_soft>
      <prod name="poco" vendor="pocoproject">
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.6"/>
        <vers num="1.7.7"/>
        <vers num="1.7.8"/>
        <vers num="1.7.9"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000473" seq="2017-1000473" published="2018-01-03" modified="2018-01-19" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/afaqurk/linux-dash/issues/447" adv="1" patch="1">https://github.com/afaqurk/linux-dash/issues/447</ref>
    </refs>
    <vuln_soft>
      <prod name="linux-dash" vendor="linux-dash_project">
        <vers num="0.5"/>
        <vers num="1.0"/>
        <vers num="1.2.0"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000474" seq="2017-1000474" published="2018-01-24" modified="2018-03-22" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://singsip.wixsite.com/singsip/vuln" adv="1">http://singsip.wixsite.com/singsip/vuln</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44318/">44318</ref>
    </refs>
    <vuln_soft>
      <prod name="vehicle_sales_management_system" vendor="vehicle_sales_management_system_project">
        <vers num="2017-07-30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000475" seq="2017-1000475" published="2018-01-24" modified="2018-02-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/lajarajorge/CVE-2017-1000475/blob/master/README.md" adv="1">https://github.com/lajarajorge/CVE-2017-1000475/blob/master/README.md</ref>
    </refs>
    <vuln_soft>
      <prod name="freesshd" vendor="freesshd">
        <vers num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000476" seq="2017-1000476" published="2018-01-03" modified="2019-05-14" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102428" adv="1">102428</ref>
      <ref source="MISC" url="https://github.com/ImageMagick/ImageMagick/issues/867" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/867</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00002.html" adv="1">[debian-lts-announce] 20180104 [SECURITY] [DLA 1229-1] imagemagick security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html">[debian-lts-announce] 20190514 [SECURITY] [DLA 1785-1] imagemagick security update</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3681-1/" adv="1">USN-3681-1</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.7-12" edition="q16"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
        <vers num="16.04" edition=":~~lts~~~"/>
        <vers num="17.10"/>
        <vers num="18.04" edition=":~~lts~~~"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000477" seq="2017-1000477" published="2018-01-03" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/pravednik/xmlBundle">https://github.com/pravednik/xmlBundle</ref>
      <ref source="MISC" url="https://github.com/pravednik/xmlBundle/issues/2" adv="1">https://github.com/pravednik/xmlBundle/issues/2</ref>
    </refs>
    <vuln_soft>
      <prod name="xmlbundle" vendor="xmlbundle_project">
        <vers num="0.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000478" seq="2017-1000478" published="2018-01-03" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/elabftw/elabftw/issues/531" adv="1">https://github.com/elabftw/elabftw/issues/531</ref>
    </refs>
    <vuln_soft>
      <prod name="elabftw" vendor="elabftw">
        <vers num="1.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000479" seq="2017-1000479" published="2018-01-03" modified="2019-05-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/11/22/7" adv="1">[oss-security] 20171122 Clickjacking vulnerability in CSRF error page pfSense</ref>
      <ref source="MISC" url="https://doc.pfsense.org/index.php/2.4.2_New_Features_and_Changes" adv="1">https://doc.pfsense.org/index.php/2.4.2_New_Features_and_Changes</ref>
      <ref source="MISC" url="https://github.com/opnsense/core/commit/d218b225" adv="1" patch="1">https://github.com/opnsense/core/commit/d218b225</ref>
      <ref source="MISC" url="https://github.com/pfsense/pfsense/commit/386d89b07" adv="1" patch="1">https://github.com/pfsense/pfsense/commit/386d89b07</ref>
      <ref source="MISC" url="https://www.netgate.com/blog/pfsense-2-4-2-release-p1-and-2-3-5-release-p1-now-available.html" adv="1">https://www.netgate.com/blog/pfsense-2-4-2-release-p1-and-2-3-5-release-p1-now-available.html</ref>
      <ref source="MISC" url="https://www.securify.nl/en/advisory/SFY20171101/clickjacking-vulnerability-in-csrf-error-page-pfsense.html" adv="1">https://www.securify.nl/en/advisory/SFY20171101/clickjacking-vulnerability-in-csrf-error-page-pfsense.html</ref>
    </refs>
    <vuln_soft>
      <prod name="pfsense" vendor="netgate">
        <vers num="2.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000480" seq="2017-1000480" published="2018-01-03" modified="2018-02-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/smarty-php/smarty/blob/master/change_log.txt" adv="1">https://github.com/smarty-php/smarty/blob/master/change_log.txt</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00023.html">[debian-lts-announce] 20180119 [SECURITY] [DLA 1249-1] smarty3 security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/02/msg00000.html">[debian-lts-announce] 20180201 [SECURITY] [DLA 1249-2] smarty3 regression update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4094">DSA-4094</ref>
    </refs>
    <vuln_soft>
      <prod name="smarty" vendor="smarty">
        <vers num="3.0.0" edition="beta4"/>
        <vers num="3.0.0" edition="beta5"/>
        <vers num="3.0.0" edition="beta6"/>
        <vers num="3.0.0" edition="beta7"/>
        <vers num="3.0.0" edition="beta8"/>
        <vers num="3.0.0" edition="rc1"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.0" edition="rc3"/>
        <vers num="3.0.0" edition="rc4"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.18"/>
        <vers num="3.1.19"/>
        <vers num="3.1.20"/>
        <vers num="3.1.21"/>
        <vers num="3.1.23"/>
        <vers num="3.1.24"/>
        <vers num="3.1.25"/>
        <vers num="3.1.26"/>
        <vers num="3.1.27"/>
        <vers num="3.1.28"/>
        <vers num="3.1.29"/>
        <vers num="3.1.30"/>
        <vers num="3.1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000481" seq="2017-1000481" published="2018-01-03" modified="2018-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you click on a specially crafted link. You would login, and get redirected to the site of the attacker, letting you think that you are still on the original Plone site. Or some javascript of the attacker could be executed. Most of these types of attacks are already blocked by Plone, using the `isURLInPortal` check to make sure we only redirect to a page on the same Plone site. But a few more ways of tricking Plone into accepting a malicious link were discovered, and fixed with this hotfix.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://plone.org/security/hotfix/20171128/open-redirection-on-login-form" adv="1">https://plone.org/security/hotfix/20171128/open-redirection-on-login-form</ref>
    </refs>
    <vuln_soft>
      <prod name="plone" vendor="plone">
        <vers num="2.5.5"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.12"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.1" edition="a1"/>
        <vers num="5.1" edition="a2"/>
        <vers num="5.1" edition="b2"/>
        <vers num="5.1" edition="b3"/>
        <vers num="5.1" edition="b4"/>
        <vers num="5.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000482" seq="2017-1000482" published="2018-01-03" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://plone.org/security/hotfix/20171128/xss-using-the-home_page-member-property" adv="1">https://plone.org/security/hotfix/20171128/xss-using-the-home_page-member-property</ref>
    </refs>
    <vuln_soft>
      <prod name="plone" vendor="plone">
        <vers num="5.0.9" prev="1"/>
        <vers num="5.1" edition="a1"/>
        <vers num="5.1" edition="a2"/>
        <vers num="5.1" edition="b2"/>
        <vers num="5.1" edition="b3"/>
        <vers num="5.1" edition="b4"/>
        <vers num="5.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000483" seq="2017-1000483" published="2018-01-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://plone.org/security/hotfix/20171128/sandbox-escape" adv="1">https://plone.org/security/hotfix/20171128/sandbox-escape</ref>
    </refs>
    <vuln_soft>
      <prod name="plone" vendor="plone">
        <vers num="2.5.5"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.12"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.1" edition="a1"/>
        <vers num="5.1" edition="a2"/>
        <vers num="5.1" edition="b2"/>
        <vers num="5.1" edition="b3"/>
        <vers num="5.1" edition="b4"/>
        <vers num="5.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000484" seq="2017-1000484" published="2018-01-03" modified="2018-01-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another attack, you could be sent to the Plone login form and login, then get redirected to the specific url, and then get a second redirect to the attacker website. (The specific url can be seen by inspecting the hotfix code, but we don't want to make it too easy for attackers by spelling it out here.)</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://plone.org/security/hotfix/20171128/an-open-redirection-when-calling-a-specific-url" adv="1">https://plone.org/security/hotfix/20171128/an-open-redirection-when-calling-a-specific-url</ref>
    </refs>
    <vuln_soft>
      <prod name="plone" vendor="plone">
        <vers num="2.5.5"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.12"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.1" edition="a1"/>
        <vers num="5.1" edition="a2"/>
        <vers num="5.1" edition="b2"/>
        <vers num="5.1" edition="b3"/>
        <vers num="5.1" edition="b4"/>
        <vers num="5.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000485" seq="2017-1000485" published="2018-01-03" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via standard filesystem operations.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/nylas-mail-lives/nylas-mail/issues/181" adv="1">https://github.com/nylas-mail-lives/nylas-mail/issues/181</ref>
    </refs>
    <vuln_soft>
      <prod name="nylas_mail" vendor="nylas_mail_lives_project">
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000486" seq="2017-1000486" published="2018-01-03" modified="2018-01-24" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html" adv="1">http://blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html</ref>
      <ref source="MISC" url="https://cryptosense.com/weak-encryption-flaw-in-primefaces/" adv="1">https://cryptosense.com/weak-encryption-flaw-in-primefaces/</ref>
      <ref source="CONFIRM" url="https://github.com/primefaces/primefaces/issues/1152" adv="1">https://github.com/primefaces/primefaces/issues/1152</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43733/" adv="1">43733</ref>
    </refs>
    <vuln_soft>
      <prod name="primefaces" vendor="primetek">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.0.17"/>
        <vers num="4.0.18"/>
        <vers num="4.0.19"/>
        <vers num="4.0.20"/>
        <vers num="4.0.21"/>
        <vers num="4.0.22"/>
        <vers num="4.0.23"/>
        <vers num="4.0.24"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.0.10"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.16"/>
        <vers num="5.0.17"/>
        <vers num="5.0.18"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.2"/>
        <vers num="5.1.3"/>
        <vers num="5.1.4"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.2"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.5"/>
        <vers num="5.2.6"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.2.9"/>
        <vers num="5.2.10"/>
        <vers num="5.2.11"/>
        <vers num="5.2.12"/>
        <vers num="5.2.13"/>
        <vers num="5.2.14"/>
        <vers num="5.2.15"/>
        <vers num="5.2.16"/>
        <vers num="5.2.17"/>
        <vers num="5.2.18"/>
        <vers num="5.2.19"/>
        <vers num="5.2.20"/>
        <vers num="5.3"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000487" seq="2017-1000487" published="2018-01-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1322">RHSA-2018:1322</ref>
      <ref source="CONFIRM" url="https://github.com/codehaus-plexus/plexus-utils/commit/b38a1b3a4352303e4312b2bb601a0d7ec6e28f41" adv="1" patch="1">https://github.com/codehaus-plexus/plexus-utils/commit/b38a1b3a4352303e4312b2bb601a0d7ec6e28f41</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00010.html">[debian-lts-announce] 20180109 [SECURITY] [DLA 1236-1] plexus-utils security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00011.html">[debian-lts-announce] 20180109 [SECURITY] [DLA 1237-1] plexus-utils2 security update</ref>
      <ref source="MISC" url="https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522" adv="1" patch="1">https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4146">DSA-4146</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4149">DSA-4149</ref>
    </refs>
    <vuln_soft>
      <prod name="plexus-utils" vendor="plexus-utils_project">
        <vers num="1.4" edition="-"/>
        <vers num="1.4" edition="alpha1"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.14"/>
        <vers num="1.5.15"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.7"/>
        <vers num="2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000488" seq="2017-1000488" published="2018-01-03" modified="2018-01-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/mautic/mautic/releases/tag/2.12.0" adv="1">https://github.com/mautic/mautic/releases/tag/2.12.0</ref>
    </refs>
    <vuln_soft>
      <prod name="mautic" vendor="mautic">
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.9.0" edition="beta"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.10.0" edition="beta"/>
        <vers num="2.10.1"/>
        <vers num="2.11.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000489" seq="2017-1000489" published="2018-01-03" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/mautic/mautic/releases/tag/2.12.0" adv="1">https://github.com/mautic/mautic/releases/tag/2.12.0</ref>
    </refs>
    <vuln_soft>
      <prod name="mautic" vendor="mautic">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.9.0" edition="beta"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.10.0" edition="beta"/>
        <vers num="2.10.1"/>
        <vers num="2.11.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000490" seq="2017-1000490" published="2018-01-03" modified="2018-01-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/mautic/mautic/releases/tag/2.12.0" adv="1">https://github.com/mautic/mautic/releases/tag/2.12.0</ref>
    </refs>
    <vuln_soft>
      <prod name="mautic" vendor="mautic">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0" edition="beta1"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.3.0"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.9.0" edition="beta"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.10.0" edition="beta"/>
        <vers num="2.10.1"/>
        <vers num="2.11.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000491" seq="2017-1000491" published="2018-01-02" modified="2018-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/rhysd/Shiba/commit/e8a65b0f81eb04903eedd29500d7e1bedf249eab" adv="1" patch="1">https://github.com/rhysd/Shiba/commit/e8a65b0f81eb04903eedd29500d7e1bedf249eab</ref>
      <ref source="CONFIRM" url="https://github.com/rhysd/Shiba/issues/42" adv="1">https://github.com/rhysd/Shiba/issues/42</ref>
    </refs>
    <vuln_soft>
      <prod name="shiba" vendor="shiba_project">
        <vers num="1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000492" seq="2017-1000492" published="2018-01-02" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/leanote/desktop-app/commit/a2ed226637f8e66c9b089784b5e58eccf2e2fb30" patch="1">https://github.com/leanote/desktop-app/commit/a2ed226637f8e66c9b089784b5e58eccf2e2fb30</ref>
      <ref source="CONFIRM" url="https://github.com/leanote/leanote/issues/695" adv="1">https://github.com/leanote/leanote/issues/695</ref>
    </refs>
    <vuln_soft>
      <prod name="desktop" vendor="leanote">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000493" seq="2017-1000493" published="2018-01-02" modified="2019-05-01" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.sbarbeau.fr/2018/03/nosql-injection-leading-to.html" adv="1">http://blog.sbarbeau.fr/2018/03/nosql-injection-leading-to.html</ref>
      <ref source="CONFIRM" url="https://github.com/RocketChat/Rocket.Chat/pull/8408" adv="1" patch="1">https://github.com/RocketChat/Rocket.Chat/pull/8408</ref>
    </refs>
    <vuln_soft>
      <prod name="rocket.chat" vendor="rocket.chat">
        <vers num="0.59" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000494" seq="2017-1000494" published="2018-01-03" modified="2019-05-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd &lt; 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/miniupnp/miniupnp/commit/7aeb624b44f86d335841242ff427433190e7168a" patch="1">https://github.com/miniupnp/miniupnp/commit/7aeb624b44f86d335841242ff427433190e7168a</ref>
      <ref source="CONFIRM" url="https://github.com/miniupnp/miniupnp/issues/268" adv="1">https://github.com/miniupnp/miniupnp/issues/268</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/05/msg00045.html">[debian-lts-announce] 20190530 [SECURITY] [DLA 1811-1] miniupnpd security update</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3562-1/">USN-3562-1</ref>
    </refs>
    <vuln_soft>
      <prod name="miniupnpd" vendor="miniupnp_project">
        <vers num="1.0" edition="-"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc10"/>
        <vers num="1.0" edition="rc11"/>
        <vers num="1.0" edition="rc12"/>
        <vers num="1.0" edition="rc13"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0" edition="rc3"/>
        <vers num="1.0" edition="rc4"/>
        <vers num="1.0" edition="rc5"/>
        <vers num="1.0" edition="rc6"/>
        <vers num="1.0" edition="rc7"/>
        <vers num="1.0" edition="rc8"/>
        <vers num="1.0" edition="rc9"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4" edition="-"/>
        <vers num="1.4" edition="2009-11-06"/>
        <vers num="1.4" edition="2009-12-22"/>
        <vers num="1.4" edition="2010-03-08"/>
        <vers num="1.4" edition="2010-05-11"/>
        <vers num="1.4" edition="2010-09-21"/>
        <vers num="1.5" edition="-"/>
        <vers num="1.5" edition="2011-01-27"/>
        <vers num="1.5" edition="2011-02-14"/>
        <vers num="1.5" edition="2011-02-21"/>
        <vers num="1.5" edition="2011-03-02"/>
        <vers num="1.5" edition="2011-03-09"/>
        <vers num="1.5" edition="2011-05-13"/>
        <vers num="1.5" edition="2011-05-15"/>
        <vers num="1.5" edition="2011-05-16"/>
        <vers num="1.5" edition="2011-05-19"/>
        <vers num="1.5" edition="2011-05-20"/>
        <vers num="1.5" edition="2011-05-27"/>
        <vers num="1.5" edition="2011-05-28"/>
        <vers num="1.5" edition="2011-06-18"/>
        <vers num="1.5" edition="2011-06-20"/>
        <vers num="1.5" edition="2011-06-23"/>
        <vers num="1.5" edition="2011-07-15"/>
        <vers num="1.6" edition="-"/>
        <vers num="1.6" edition="2011-07-30"/>
        <vers num="1.6" edition="2011-11-18"/>
        <vers num="1.6" edition="2012-01-21"/>
        <vers num="1.6" edition="2012-02-03"/>
        <vers num="1.6" edition="2012-02-07"/>
        <vers num="1.6" edition="2012-03-05"/>
        <vers num="1.6" edition="2012-03-20"/>
        <vers num="1.6" edition="2012-04-06"/>
        <vers num="1.6" edition="2012-04-18"/>
        <vers num="1.6" edition="2012-04-19"/>
        <vers num="1.6" edition="2012-04-20"/>
        <vers num="1.6" edition="2012-04-24"/>
        <vers num="1.6" edition="2012-04-26"/>
        <vers num="1.6" edition="2012-05-02"/>
        <vers num="1.6" edition="2012-05-09"/>
        <vers num="1.7" edition="-"/>
        <vers num="1.7" edition="2012-07-11"/>
        <vers num="1.7" edition="2012-08-24"/>
        <vers num="1.7" edition="2012-10-05"/>
        <vers num="1.8" edition="-"/>
        <vers num="1.8" edition="2013-02-07"/>
        <vers num="1.8" edition="2013-04-26"/>
        <vers num="1.8" edition="2013-05-03"/>
        <vers num="1.8" edition="2013-05-21"/>
        <vers num="1.8" edition="2013-06-07"/>
        <vers num="1.8" edition="2013-07-30"/>
        <vers num="1.8" edition="2013-12-13"/>
        <vers num="1.8" edition="2013-12-16"/>
        <vers num="1.8" edition="2014-01-27"/>
        <vers num="1.8" edition="2014-02-03"/>
        <vers num="1.8" edition="2014-02-25"/>
        <vers num="1.8" edition="2014-03-10"/>
        <vers num="1.8" edition="2014-03-13"/>
        <vers num="1.8" edition="2014-04-01"/>
        <vers num="1.8" edition="2014-04-22"/>
        <vers num="1.8" edition="2014-05-23"/>
        <vers num="1.8" edition="2014-09-06"/>
        <vers num="1.8" edition="2014-10-21"/>
        <vers num="1.8" edition="2014-10-22"/>
        <vers num="1.8.20130207"/>
        <vers num="1.9" edition="-"/>
        <vers num="1.9" edition="2014-11-08"/>
        <vers num="1.9" edition="2014-11-28"/>
        <vers num="1.9" edition="2014-12-04"/>
        <vers num="1.9" edition="2014-12-09"/>
        <vers num="1.9" edition="2015-03-07"/>
        <vers num="1.9" edition="2015-04-27"/>
        <vers num="1.9" edition="2015-04-30"/>
        <vers num="1.9" edition="2015-06-09"/>
        <vers num="1.9" edition="2015-07-21"/>
        <vers num="1.9" edition="2015-09-22"/>
        <vers num="1.9" edition="2015-11-18"/>
        <vers num="1.9" edition="2015-12-12"/>
        <vers num="1.9" edition="2016-01-13"/>
        <vers num="1.9" edition="2016-02-09"/>
        <vers num="1.9" edition="2016-02-12"/>
        <vers num="1.9" edition="2016-02-16"/>
        <vers num="1.9" edition="2016-02-22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000495" seq="2017-1000495" published="2018-01-03" modified="2018-01-17" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/quickapps/cms/issues/183" adv="1">https://github.com/quickapps/cms/issues/183</ref>
    </refs>
    <vuln_soft>
      <prod name="quickapps_cms" vendor="quickappscms">
        <vers num="2.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000496" seq="2017-1000496" published="2018-01-03" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/commsy/commsy/issues/2" adv="1">https://github.com/commsy/commsy/issues/2</ref>
    </refs>
    <vuln_soft>
      <prod name="commsy" vendor="commsy">
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000497" seq="2017-1000497" published="2018-01-03" modified="2018-01-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/sbrl/Pepperminty-Wiki/issues/152" adv="1">https://github.com/sbrl/Pepperminty-Wiki/issues/152</ref>
    </refs>
    <vuln_soft>
      <prod name="pepperminty-wiki" vendor="pepperminty-wiki_project">
        <vers num="0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000498" seq="2017-1000498" published="2018-01-03" modified="2018-01-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/BigBadaboom/androidsvg/issues/122" adv="1">https://github.com/BigBadaboom/androidsvg/issues/122</ref>
    </refs>
    <vuln_soft>
      <prod name="androidsvg" vendor="androidsvg_project">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000499" seq="2017-1000499" published="2018-01-03" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/" adv="1" patch="1">http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040163" adv="1">1040163</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45284/" adv="1">45284</ref>
      <ref source="CONFIRM" url="https://www.phpmyadmin.net/security/PMASA-2017-9/" adv="1" patch="1">https://www.phpmyadmin.net/security/PMASA-2017-9/</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="4.7.0" edition="beta1"/>
        <vers num="4.7.0" edition="rc1"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10005" seq="2017-10005" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99766" adv="1">99766</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000500" seq="2017-1000500" published="2018-01-03" modified="2018-12-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-12161.  Reason: This candidate is a reservation duplicate of CVE-2017-12161.  Notes: All CVE users should reference CVE-2017-12161 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-1000501" seq="2017-1000501" published="2018-01-03" modified="2019-05-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.awstats.org/" adv="1">http://www.awstats.org/</ref>
      <ref source="CONFIRM" url="https://github.com/eldy/awstats/commit/06c0ab29c1e5059d9e0279c6b64d573d619e1651" adv="1" patch="1">https://github.com/eldy/awstats/commit/06c0ab29c1e5059d9e0279c6b64d573d619e1651</ref>
      <ref source="CONFIRM" url="https://github.com/eldy/awstats/commit/cf219843a74c951bf5986f3a7fffa3dcf99c3899" adv="1" patch="1">https://github.com/eldy/awstats/commit/cf219843a74c951bf5986f3a7fffa3dcf99c3899</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/01/msg00012.html" adv="1">[debian-lts-announce] 20180110 [SECURITY] [DLA 1238-1] awstats security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4092" adv="1">DSA-4092</ref>
    </refs>
    <vuln_soft>
      <prod name="awstats" vendor="awstats">
        <vers num="7.6.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000502" seq="2017-1000502" published="2018-01-24" modified="2018-02-12" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-12-06/" adv="1">https://jenkins.io/security/advisory/2017-12-06/</ref>
    </refs>
    <vuln_soft>
      <prod name="ec2" vendor="jenkins">
        <vers num="1.37" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000503" seq="2017-1000503" published="2018-01-24" modified="2018-02-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-12-14/" adv="1">https://jenkins.io/security/advisory/2017-12-14/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.81" edition=":~~-~~~"/>
        <vers num="2.81" edition=":~~lts~~~"/>
        <vers num="2.82" edition=":~~-~~~"/>
        <vers num="2.82" edition=":~~lts~~~"/>
        <vers num="2.83" edition=":~~-~~~"/>
        <vers num="2.83" edition=":~~lts~~~"/>
        <vers num="2.84" edition=":~~-~~~"/>
        <vers num="2.84" edition=":~~lts~~~"/>
        <vers num="2.85" edition=":~~-~~~"/>
        <vers num="2.85" edition=":~~lts~~~"/>
        <vers num="2.86" edition=":~~-~~~"/>
        <vers num="2.86" edition=":~~lts~~~"/>
        <vers num="2.87" edition=":~~-~~~"/>
        <vers num="2.87" edition=":~~lts~~~"/>
        <vers num="2.88" edition=":~~-~~~"/>
        <vers num="2.88" edition=":~~lts~~~"/>
        <vers num="2.89" edition=":~~-~~~"/>
        <vers num="2.89" edition=":~~lts~~~"/>
        <vers num="2.89.1" edition=":~~-~~~"/>
        <vers num="2.89.1" edition=":~~lts~~~"/>
        <vers num="2.89.2" edition=":~~-~~~"/>
        <vers num="2.89.2" edition=":~~lts~~~"/>
        <vers num="2.89.3" edition=":~~-~~~"/>
        <vers num="2.89.3" edition=":~~lts~~~"/>
        <vers num="2.89.4" edition=":~~lts~~~"/>
        <vers num="2.90" edition=":~~-~~~"/>
        <vers num="2.90" edition=":~~lts~~~"/>
        <vers num="2.91" edition=":~~-~~~"/>
        <vers num="2.91" edition=":~~lts~~~"/>
        <vers num="2.92" edition=":~~-~~~"/>
        <vers num="2.92" edition=":~~lts~~~"/>
        <vers num="2.93" edition=":~~-~~~"/>
        <vers num="2.93" edition=":~~lts~~~"/>
        <vers num="2.94" edition=":~~-~~~"/>
        <vers num="2.94" edition=":~~lts~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000504" seq="2017-1000504" published="2018-01-24" modified="2019-05-08" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-12-14/" adv="1">https://jenkins.io/security/advisory/2017-12-14/</ref>
    </refs>
    <vuln_soft>
      <prod name="jenkins" vendor="jenkins">
        <vers num="2.89.1" prev="1" edition=":~~lts~~~"/>
        <vers num="2.94" prev="1" edition=":~~-~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000505" seq="2017-1000505" published="2018-01-25" modified="2018-02-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://jenkins.io/security/advisory/2017-12-11/" adv="1">https://jenkins.io/security/advisory/2017-12-11/</ref>
    </refs>
    <vuln_soft>
      <prod name="script_security" vendor="jenkins">
        <vers num="1.36" prev="1" edition=":~~~jenkins~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000506" seq="2017-1000506" published="2018-02-09" modified="2018-02-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/mautic/mautic/issues/5222" adv="1">https://github.com/mautic/mautic/issues/5222</ref>
    </refs>
    <vuln_soft>
      <prod name="mautic" vendor="mautic">
        <vers num="2.11.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000507" seq="2017-1000507" published="2018-02-09" modified="2018-02-26" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/cnvs/canvas/issues/359" adv="1">https://github.com/cnvs/canvas/issues/359</ref>
    </refs>
    <vuln_soft>
      <prod name="canvas" vendor="cnvs">
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000508" seq="2017-1000508" published="2018-02-09" modified="2018-02-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/InvoicePlane/InvoicePlane/pull/557">https://github.com/InvoicePlane/InvoicePlane/pull/557</ref>
      <ref source="CONFIRM" url="https://github.com/InvoicePlane/InvoicePlane/pull/557/commits/3fc256ccef403f5be9982f02ef340d9e01daabb2" patch="1">https://github.com/InvoicePlane/InvoicePlane/pull/557/commits/3fc256ccef403f5be9982f02ef340d9e01daabb2</ref>
    </refs>
    <vuln_soft>
      <prod name="invoiceplane" vendor="invoiceplane">
        <vers num="1.5.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000509" seq="2017-1000509" published="2018-02-09" modified="2018-02-26" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/Dolibarr/dolibarr/issues/7727" adv="1">https://github.com/Dolibarr/dolibarr/issues/7727</ref>
    </refs>
    <vuln_soft>
      <prod name="dolibarr" vendor="dolibarr">
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000510" seq="2017-1000510" published="2018-02-09" modified="2018-02-26" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/croogo/croogo/issues/847" adv="1">https://github.com/croogo/croogo/issues/847</ref>
    </refs>
    <vuln_soft>
      <prod name="croogo" vendor="croogo">
        <vers num="2.3.1-17-g6f82e6c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10006" seq="2017-10006" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99716" adv="1">99716</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1000600" seq="2017-1000600" published="2018-09-06" modified="2018-10-26" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WordPress version &lt;4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/105305" adv="1">105305</ref>
      <ref source="MISC" url="https://www.theregister.co.uk/2018/08/20/php_unserialisation_wordpress_vuln/" adv="1">https://www.theregister.co.uk/2018/08/20/php_unserialisation_wordpress_vuln/</ref>
      <ref source="MISC" url="https://youtu.be/GePBmsNJw6Y?t=1763" adv="1">https://youtu.be/GePBmsNJw6Y?t=1763</ref>
    </refs>
    <vuln_soft>
      <prod name="wordpress" vendor="wordpress">
        <vers num="-"/>
        <vers num="0.71" edition="-"/>
        <vers num="0.71" edition="beta"/>
        <vers num="0.71" edition="beta3"/>
        <vers num="0.72" edition="beta1"/>
        <vers num="0.72" edition="beta2"/>
        <vers num="0.72" edition="rc1"/>
        <vers num="0.711"/>
        <vers num="1.0" edition="-"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0.1" edition="-"/>
        <vers num="1.0.1" edition="rc1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.1"/>
        <vers num="1.2" edition="-"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2" edition="rc1"/>
        <vers num="1.2" edition="rc2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5" edition="a"/>
        <vers num="1.3"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.1.1"/>
        <vers num="1.5.1.2"/>
        <vers num="1.5.1.3"/>
        <vers num="1.5.2"/>
        <vers num="1.6.2"/>
        <vers num="2.0" edition="-"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0.1" edition="-"/>
        <vers num="2.0.1" edition="rc1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="-"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5" edition="-"/>
        <vers num="2.0.5" edition="beta1"/>
        <vers num="2.0.5" edition="rc1"/>
        <vers num="2.0.6" edition="-"/>
        <vers num="2.0.6" edition="beta1"/>
        <vers num="2.0.6" edition="rc1"/>
        <vers num="2.0.6" edition="rc2"/>
        <vers num="2.0.7" edition="-"/>
        <vers num="2.0.7" edition="rc1"/>
        <vers num="2.0.7" edition="rc2"/>
        <vers num="2.0.8" edition="-"/>
        <vers num="2.0.8" edition="rc1"/>
        <vers num="2.0.9" edition="-"/>
        <vers num="2.0.9" edition="beta1"/>
        <vers num="2.0.9" edition="rc1"/>
        <vers num="2.0.10" edition="-"/>
        <vers num="2.0.10" edition="rc1"/>
        <vers num="2.0.10" edition="rc2"/>
        <vers num="2.0.10" edition="rc3"/>
        <vers num="2.0.11" edition="-"/>
        <vers num="2.0.11" edition="rc1"/>
        <vers num="2.0.11" edition="rc2"/>
        <vers num="2.0.11" edition="rc3"/>
        <vers num="2.1" edition="-"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="beta4"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.1.1" edition="-"/>
        <vers num="2.1.1" edition="beta1"/>
        <vers num="2.1.1" edition="rc1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3" edition="-"/>
        <vers num="2.1.3" edition="rc1"/>
        <vers num="2.1.3" edition="rc2"/>
        <vers num="2.1.3" edition="rc3"/>
        <vers num="2.2" edition="-"/>
        <vers num="2.2" edition="rc1"/>
        <vers num="2.2" edition="rc2"/>
        <vers num="2.2.1" edition="-"/>
        <vers num="2.2.1" edition="rc1"/>
        <vers num="2.2.1" edition="rc2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3" edition="-"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3" edition="rc1"/>
        <vers num="2.3.1" edition="-"/>
        <vers num="2.3.1" edition="beta1"/>
        <vers num="2.3.1" edition="rc1"/>
        <vers num="2.3.2" edition="-"/>
        <vers num="2.3.2" edition="beta1"/>
        <vers num="2.3.2" edition="beta2"/>
        <vers num="2.3.2" edition="beta3"/>
        <vers num="2.3.2" edition="rc1"/>
        <vers num="2.3.3"/>
        <vers num="2.5" edition="-"/>
        <vers num="2.5" edition="rc1"/>
        <vers num="2.5" edition="rc2"/>
        <vers num="2.5" edition="rc3"/>
        <vers num="2.5.1"/>
        <vers num="2.6" edition="-"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="rc1"/>
        <vers num="2.6.1" edition="-"/>
        <vers num="2.6.1" edition="beta1"/>
        <vers num="2.6.1" edition="beta2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.5"/>
        <vers num="2.7" edition="-"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="rc1"/>
        <vers num="2.7" edition="rc2"/>
        <vers num="2.7.1"/>
        <vers num="2.8" edition="-"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="rc1"/>
        <vers num="2.8.1" edition="-"/>
        <vers num="2.8.1" edition="beta1"/>
        <vers num="2.8.1" edition="beta2"/>
        <vers num="2.8.1" edition="rc1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4" edition="a"/>
        <vers num="2.8.5" edition="-"/>
        <vers num="2.8.5" edition="beta1"/>
        <vers num="2.8.5.1"/>
        <vers num="2.8.5.2"/>
        <vers num="2.8.6" edition="-"/>
        <vers num="2.8.6" edition="beta1"/>
        <vers num="2.9" edition="-"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="rc1"/>
        <vers num="2.9.1" edition="-"/>
        <vers num="2.9.1" edition="beta1"/>
        <vers num="2.9.1" edition="rc1"/>
        <vers num="2.9.1.1"/>
        <vers num="2.9.2"/>
        <vers num="3.0" edition="-"/>
        <vers num="3.0" edition="beta1"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.1" edition="-"/>
        <vers num="3.1" edition="beta1"/>
        <vers num="3.1" edition="beta2"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1" edition="-"/>
        <vers num="3.1.1" edition="rc1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2" edition="-"/>
        <vers num="3.2" edition="beta1"/>
        <vers num="3.2" edition="beta2"/>
        <vers num="3.2" edition="rc1"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2.1"/>
        <vers num="3.3" edition="-"/>
        <vers num="3.3" edition="beta1"/>
        <vers num="3.3" edition="beta2"/>
        <vers num="3.3" edition="beta3"/>
        <vers num="3.3" edition="beta4"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2" edition="-"/>
        <vers num="3.3.2" edition="rc1"/>
        <vers num="3.3.3"/>
        <vers num="3.4" edition="-"/>
        <vers num="3.4" edition="beta1"/>
        <vers num="3.4" edition="beta2"/>
        <vers num="3.4" edition="beta3"/>
        <vers num="3.4" edition="beta4"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5" edition="-"/>
        <vers num="3.5" edition="beta1"/>
        <vers num="3.5" edition="beta2"/>
        <vers num="3.5" edition="beta3"/>
        <vers num="3.5" edition="rc1"/>
        <vers num="3.5" edition="rc2"/>
        <vers num="3.5" edition="rc3"/>
        <vers num="3.5" edition="rc4"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.6" edition="-"/>
        <vers num="3.6" edition="beta1"/>
        <vers num="3.6" edition="beta2"/>
        <vers num="3.6" edition="beta3"/>
        <vers num="3.6" edition="beta4"/>
        <vers num="3.6" edition="rc1"/>
        <vers num="3.6" edition="rc2"/>
        <vers num="3.6.1"/>
        <vers num="3.7" edition="-"/>
        <vers num="3.7" edition="beta1"/>
        <vers num="3.7" edition="beta2"/>
        <vers num="3.7" edition="rc1"/>
        <vers num="3.7" edition="rc2"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.7.11"/>
        <vers num="3.7.12"/>
        <vers num="3.7.13"/>
        <vers num="3.7.14"/>
        <vers num="3.7.15"/>
        <vers num="3.7.16"/>
        <vers num="3.7.17"/>
        <vers num="3.7.18"/>
        <vers num="3.7.19"/>
        <vers num="3.7.20"/>
        <vers num="3.7.21"/>
        <vers num="3.7.22"/>
        <vers num="3.7.23"/>
        <vers num="3.7.24"/>
        <vers num="3.7.25"/>
        <vers num="3.7.26"/>
        <vers num="3.7.27"/>
        <vers num="3.7.28"/>
        <vers num="3.7.29"/>
        <vers num="3.8" edition="-"/>
        <vers num="3.8" edition="beta1"/>
        <vers num="3.8" edition="rc1"/>
        <vers num="3.8" edition="rc2"/>
        <vers num="3.8.1" edition="-"/>
        <vers num="3.8.1" edition="rc1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.8.10"/>
        <vers num="3.8.11"/>
        <vers num="3.8.12"/>
        <vers num="3.8.13"/>
        <vers num="3.8.14"/>
        <vers num="3.8.15"/>
        <vers num="3.8.16"/>
        <vers num="3.8.17"/>
        <vers num="3.8.18"/>
        <vers num="3.8.19"/>
        <vers num="3.8.20"/>
        <vers num="3.8.21"/>
        <vers num="3.8.22"/>
        <vers num="3.8.23"/>
        <vers num="3.8.24"/>
        <vers num="3.8.25"/>
        <vers num="3.8.26"/>
        <vers num="3.8.27"/>
        <vers num="3.8.28"/>
        <vers num="3.8.29"/>
        <vers num="3.9" edition="-"/>
        <vers num="3.9" edition="beta1"/>
        <vers num="3.9" edition="beta2"/>
        <vers num="3.9" edition="beta3"/>
        <vers num="3.9" edition="rc1"/>
        <vers num="3.9" edition="rc2"/>
        <vers num="3.9.0"/>
        <vers num="3.9.1" edition="-"/>
        <vers num="3.9.1" edition="rc1"/>
        <vers num="3.9.2"/>
        <vers num="3.9.3"/>
        <vers num="3.9.4"/>
        <vers num="3.9.5"/>
        <vers num="3.9.6"/>
        <vers num="3.9.7"/>
        <vers num="3.9.8"/>
        <vers num="3.9.9"/>
        <vers num="3.9.10"/>
        <vers num="3.9.11"/>
        <vers num="3.9.12"/>
        <vers num="3.9.13"/>
        <vers num="3.9.14"/>
        <vers num="3.9.15"/>
        <vers num="3.9.16"/>
        <vers num="3.9.17"/>
        <vers num="3.9.18"/>
        <vers num="3.9.19"/>
        <vers num="3.9.20"/>
        <vers num="3.9.21"/>
        <vers num="3.9.22"/>
        <vers num="3.9.23"/>
        <vers num="3.9.24"/>
        <vers num="3.9.25"/>
        <vers num="3.9.26"/>
        <vers num="3.9.27"/>
        <vers num="4.0" edition="-"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="rc1"/>
        <vers num="4.0" edition="rc2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.0.17"/>
        <vers num="4.0.18"/>
        <vers num="4.0.19"/>
        <vers num="4.0.20"/>
        <vers num="4.0.21"/>
        <vers num="4.0.22"/>
        <vers num="4.0.23"/>
        <vers num="4.0.24"/>
        <vers num="4.0.25"/>
        <vers num="4.0.26"/>
        <vers num="4.1" edition="-"/>
        <vers num="4.1" edition="beta1"/>
        <vers num="4.1" edition="beta2"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.1" edition="rc2"/>
        <vers num="4.1" edition="rc3"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.2" edition="-"/>
        <vers num="4.2" edition="beta1"/>
        <vers num="4.2" edition="beta2"/>
        <vers num="4.2" edition="beta3"/>
        <vers num="4.2" edition="beta4"/>
        <vers num="4.2" edition="rc1"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc3"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4" edition="-"/>
        <vers num="4.2.4" edition="rc1"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers num="4.2.10"/>
        <vers num="4.2.11"/>
        <vers num="4.2.12"/>
        <vers num="4.2.13"/>
        <vers num="4.2.14"/>
        <vers num="4.2.15"/>
        <vers num="4.2.16"/>
        <vers num="4.2.17"/>
        <vers num="4.2.18"/>
        <vers num="4.2.19"/>
        <vers num="4.2.20"/>
        <vers num="4.2.21"/>
        <vers num="4.2.22"/>
        <vers num="4.2.23"/>
        <vers num="4.3" edition="-"/>
        <vers num="4.3" edition="beta1"/>
        <vers num="4.3" edition="beta2"/>
        <vers num="4.3" edition="beta3"/>
        <vers num="4.3" edition="beta4"/>
        <vers num="4.3" edition="rc1"/>
        <vers num="4.3" edition="rc2"/>
        <vers num="4.3" edition="rc3"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.12"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.16"/>
        <vers num="4.3.17"/>
        <vers num="4.3.18"/>
        <vers num="4.3.19"/>
        <vers num="4.4" edition="-"/>
        <vers num="4.4" edition="beta1"/>
        <vers num="4.4" edition="beta2"/>
        <vers num="4.4" edition="beta3"/>
        <vers num="4.4" edition="beta4"/>
        <vers num="4.4" edition="rc1"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.4.5"/>
        <vers num="4.4.6"/>
        <vers num="4.4.7"/>
        <vers num="4.4.8"/>
        <vers num="4.4.9"/>
        <vers num="4.4.10"/>
        <vers num="4.4.11"/>
        <vers num="4.4.12"/>
        <vers num="4.4.13"/>
        <vers num="4.4.14"/>
        <vers num="4.4.15"/>
        <vers num="4.4.16"/>
        <vers num="4.4.17"/>
        <vers num="4.4.18"/>
        <vers num="4.5" edition="-"/>
        <vers num="4.5" edition="beta1"/>
        <vers num="4.5" edition="beta2"/>
        <vers num="4.5" edition="beta3"/>
        <vers num="4.5" edition="beta4"/>
        <vers num="4.5" edition="rc1"/>
        <vers num="4.5" edition="rc2"/>
        <vers num="4.5" edition="rc3"/>
        <vers num="4.5.1" edition="-"/>
        <vers num="4.5.1" edition="rc1"/>
        <vers num="4.5.1" edition="rc2"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.5.9"/>
        <vers num="4.5.10"/>
        <vers num="4.5.11"/>
        <vers num="4.5.12"/>
        <vers num="4.5.13"/>
        <vers num="4.5.14"/>
        <vers num="4.5.15"/>
        <vers num="4.5.16"/>
        <vers num="4.5.17"/>
        <vers num="4.6" edition="-"/>
        <vers num="4.6" edition="beta1"/>
        <vers num="4.6" edition="beta2"/>
        <vers num="4.6" edition="beta3"/>
        <vers num="4.6" edition="beta4"/>
        <vers num="4.6" edition="rc1"/>
        <vers num="4.6" edition="rc2"/>
        <vers num="4.6" edition="rc3"/>
        <vers num="4.6" edition="rc4"/>
        <vers num="4.6.1" edition="-"/>
        <vers num="4.6.1" edition="rc1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.6.10"/>
        <vers num="4.6.11"/>
        <vers num="4.6.12"/>
        <vers num="4.6.13"/>
        <vers num="4.6.14"/>
        <vers num="4.7" edition="-"/>
        <vers num="4.7" edition="beta1"/>
        <vers num="4.7" edition="beta2"/>
        <vers num="4.7" edition="beta3"/>
        <vers num="4.7" edition="beta4"/>
        <vers num="4.7" edition="rc1"/>
        <vers num="4.7" edition="rc2"/>
        <vers num="4.7" edition="rc3"/>
        <vers num="4.7.1" edition="-"/>
        <vers num="4.7.1" edition="rc1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3" edition="-"/>
        <vers num="4.7.3" edition="rc1"/>
        <vers num="4.7.4" edition="-"/>
        <vers num="4.7.4" edition="rc1"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7.10"/>
        <vers num="4.7.11"/>
        <vers num="4.7.12"/>
        <vers num="4.7.13"/>
        <vers num="4.8" edition="-"/>
        <vers num="4.8" edition="beta1"/>
        <vers num="4.8" edition="beta2"/>
        <vers num="4.8" edition="rc1"/>
        <vers num="4.8" edition="rc2"/>
        <vers num="4.8.1" edition="-"/>
        <vers num="4.8.1" edition="beta1"/>
        <vers num="4.8.1" edition="rc1"/>
        <vers num="4.8.1" edition="rc2"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10007" seq="2017-10007" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99812" adv="1">99812</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10008" seq="2017-10008" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100266" adv="1">100266</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10009" seq="2017-10009" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99792" adv="1">99792</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10010" seq="2017-10010" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: FileUploads). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99829" adv="1">99829</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1001000" seq="2017-1001000" published="2017-04-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/02/10/16" adv="1" patch="1">[oss-security] 20170210 Re: Asking for a CVE id for the WordPress Privilege Escalation vulnerability (4.7/4.7.1)</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037731">1037731</ref>
      <ref source="MISC" url="https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html" adv="1">https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html</ref>
      <ref source="MISC" url="https://blogs.akamai.com/2017/02/wordpress-web-api-vulnerability.html" adv="1">https://blogs.akamai.com/2017/02/wordpress-web-api-vulnerability.html</ref>
      <ref source="CONFIRM" url="https://codex.wordpress.org/Version_4.7.2" adv="1" patch="1">https://codex.wordpress.org/Version_4.7.2</ref>
      <ref source="MISC" url="https://gist.github.com/leonjza/2244eb15510a0687ed93160c623762ab" adv="1" patch="1">https://gist.github.com/leonjza/2244eb15510a0687ed93160c623762ab</ref>
      <ref source="CONFIRM" url="https://github.com/WordPress/WordPress/commit/e357195ce303017d517aff944644a7a1232926f7" adv="1" patch="1">https://github.com/WordPress/WordPress/commit/e357195ce303017d517aff944644a7a1232926f7</ref>
      <ref source="CONFIRM" url="https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/" adv="1" patch="1">https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/</ref>
      <ref source="CONFIRM" url="https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/" adv="1" patch="1">https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/</ref>
    </refs>
    <vuln_soft>
      <prod name="wordpress" vendor="wordpress">
        <vers num="4.7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1001001" seq="2017-1001001" published="2017-11-01" modified="2017-11-18" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/pluxml/PluXml/issues/253" adv="1">https://github.com/pluxml/PluXml/issues/253</ref>
    </refs>
    <vuln_soft>
      <prod name="pluxml" vendor="pluxml">
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1001002" seq="2017-1001002" published="2017-11-27" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170" adv="1">https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170</ref>
      <ref source="CONFIRM" url="https://github.com/josdejong/mathjs/commit/8d2d48d81b3c233fb64eb2ec1d7a9e1cf6a55a90" adv="1" patch="1">https://github.com/josdejong/mathjs/commit/8d2d48d81b3c233fb64eb2ec1d7a9e1cf6a55a90</ref>
    </refs>
    <vuln_soft>
      <prod name="math.js" vendor="mathjs">
        <vers num="3.17.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1001003" seq="2017-1001003" published="2017-11-27" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170" adv="1">https://github.com/josdejong/mathjs/blob/master/HISTORY.md#2017-11-18-version-3170</ref>
      <ref source="CONFIRM" url="https://github.com/josdejong/mathjs/commit/a60f3c8d9dd714244aed7a5569c3dccaa3a4e761" adv="1" patch="1">https://github.com/josdejong/mathjs/commit/a60f3c8d9dd714244aed7a5569c3dccaa3a4e761</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-1001004" seq="2017-1001004" published="2017-11-27" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/josdejong/typed-function/blob/master/HISTORY.md#2017-11-18-version-0106">https://github.com/josdejong/typed-function/blob/master/HISTORY.md#2017-11-18-version-0106</ref>
      <ref source="CONFIRM" url="https://github.com/josdejong/typed-function/commit/6478ef4f2c3f3c2d9f2c820e2db4b4ba3425e6fe" patch="1">https://github.com/josdejong/typed-function/commit/6478ef4f2c3f3c2d9f2c820e2db4b4ba3425e6fe</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10011" seq="2017-10011" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle FLEXCUBE Private Banking executes to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99675" adv="1">99675</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10012" seq="2017-10012" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99862" adv="1">99862</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10013" seq="2017-10013" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: User Interface). The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Sun ZFS Storage Appliance Kit (AK), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99833" adv="1">99833</ref>
    </refs>
    <vuln_soft>
      <prod name="sun_zfs_storage_appliance_kit_software" vendor="oracle">
        <vers num="2013"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10014" seq="2017-10014" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Hotel Mobile accessible data. CVSS 3.0 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101299" adv="1">101299</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10015" seq="2017-10015" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.7" CVSS_base_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Designer). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99819" adv="1">99819</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10016" seq="2017-10016" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: User Interface). The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99855" adv="1">99855</ref>
    </refs>
    <vuln_soft>
      <prod name="sun_zfs_storage_appliance_kit_software" vendor="oracle">
        <vers num="2013"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10017" seq="2017-10017" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Workcenter). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99784" adv="1">99784</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10018" seq="2017-10018" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99811" adv="1">99811</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_scm_strategic_sourcing" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10019" seq="2017-10019" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99735" adv="1">99735</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10020" seq="2017-10020" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Updates Change Assistant). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99825" adv="1">99825</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002000" seq="2017-1002000" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96899" adv="1">96899</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96905" adv="1">96905</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=179" adv="1">http://www.vapidlabs.com/advisory.php?v=179</ref>
      <ref source="MISC" url="https://wordpress.org/plugins-wp/mobile-friendly-app-builder-by-easytouch/">https://wordpress.org/plugins-wp/mobile-friendly-app-builder-by-easytouch/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41540/" adv="1">41540</ref>
    </refs>
    <vuln_soft>
      <prod name="mobile-friendly-app-builder-by-easytouch" vendor="mobile-friendly-app-builder-by-easytouch_project">
        <vers num="3.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002001" seq="2017-1002001" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=180" adv="1">http://www.vapidlabs.com/advisory.php?v=180</ref>
      <ref source="MISC" url="https://wordpress.org/plugins-wp/mobile-app-builder-by-wappress/">https://wordpress.org/plugins-wp/mobile-app-builder-by-wappress/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41540/" adv="1">41540</ref>
    </refs>
    <vuln_soft>
      <prod name="mobile-app-builder-by-wappress" vendor="mobile-app-builder-by-wappress_project">
        <vers num="1.05" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002002" seq="2017-1002002" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96906" adv="1">96906</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=181" adv="1">http://www.vapidlabs.com/advisory.php?v=181</ref>
      <ref source="MISC" url="https://wordpress.org/plugins-wp/webapp-builder/">https://wordpress.org/plugins-wp/webapp-builder/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41540/" adv="1">41540</ref>
    </refs>
    <vuln_soft>
      <prod name="webapp-builder" vendor="webapp-builder_project">
        <vers num="2.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002003" seq="2017-1002003" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96908" adv="1">96908</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=182" adv="1">http://www.vapidlabs.com/advisory.php?v=182</ref>
      <ref source="MISC" url="https://wordpress.org/plugins-wp/wp2android-turn-wp-site-into-android-app/">https://wordpress.org/plugins-wp/wp2android-turn-wp-site-into-android-app/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41540/" adv="1">41540</ref>
    </refs>
    <vuln_soft>
      <prod name="wp2android-turn-wp-site-into-android-app" vendor="wp2android-turn-wp-site-into-android-app_project">
        <vers num="1.1.4" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002004" seq="2017-1002004" published="2017-09-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96781" adv="1">96781</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=183" adv="1">http://www.vapidlabs.com/advisory.php?v=183</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/dtracker/" adv="1">https://wordpress.org/plugins/dtracker/</ref>
    </refs>
    <vuln_soft>
      <prod name="dtracker" vendor="dtracker_project">
        <vers num="1.5" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002005" seq="2017-1002005" published="2017-09-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96781" adv="1">96781</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=183">http://www.vapidlabs.com/advisory.php?v=183</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/dtracker/" adv="1">https://wordpress.org/plugins/dtracker/</ref>
    </refs>
    <vuln_soft>
      <prod name="dtracker" vendor="dtracker_project">
        <vers num="1.5" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002006" seq="2017-1002006" published="2017-09-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96890" adv="1">96890</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=186" adv="1">http://www.vapidlabs.com/advisory.php?v=186</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/dtracker/" adv="1">https://wordpress.org/plugins/dtracker/</ref>
    </refs>
    <vuln_soft>
      <prod name="dtracker" vendor="dtracker_project">
        <vers num="1.5" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002007" seq="2017-1002007" published="2017-09-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/96890" adv="1">96890</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=186" adv="1">http://www.vapidlabs.com/advisory.php?v=186</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/dtracker/" adv="1">https://wordpress.org/plugins/dtracker/</ref>
    </refs>
    <vuln_soft>
      <prod name="dtracker" vendor="dtracker_project">
        <vers num="1.5" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002008" seq="2017-1002008" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=187" adv="1">http://www.vapidlabs.com/advisory.php?v=187</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/membership-simplified-for-oap-members-only">https://wordpress.org/plugins/membership-simplified-for-oap-members-only</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8777" adv="1">https://wpvulndb.com/vulnerabilities/8777</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/41622/" adv="1">41622</ref>
    </refs>
    <vuln_soft>
      <prod name="membership-simplified-for-oap-members-only" vendor="membership-simplified-for-oap-members-only_project">
        <vers num="1.58" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002009" seq="2017-1002009" published="2017-09-14" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://membership.officeautopilot.com/get-it-now/">http://membership.officeautopilot.com/get-it-now/</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=188" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=188</ref>
    </refs>
    <vuln_soft>
      <prod name="membership_simplified" vendor="ontraport">
        <vers num="1.58" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002010" seq="2017-1002010" published="2017-09-14" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://membership.officeautopilot.com/get-it-now/">http://membership.officeautopilot.com/get-it-now/</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=188" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=188</ref>
    </refs>
    <vuln_soft>
      <prod name="membership_simplified" vendor="ontraport">
        <vers num="1.58" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002011" seq="2017-1002011" published="2017-09-14" modified="2017-09-20" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=189" adv="1">http://www.vapidlabs.com/advisory.php?v=189</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/image-gallery-with-slideshow/" adv="1">https://wordpress.org/plugins/image-gallery-with-slideshow/</ref>
    </refs>
    <vuln_soft>
      <prod name="image-gallery-with-slideshow" vendor="anblik">
        <vers num="1.5.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002012" seq="2017-1002012" published="2017-09-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=189" adv="1">http://www.vapidlabs.com/advisory.php?v=189</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/image-gallery-with-slideshow/" adv="1">https://wordpress.org/plugins/image-gallery-with-slideshow/</ref>
    </refs>
    <vuln_soft>
      <prod name="image-gallery-with-slideshow" vendor="anblik">
        <vers num="1.5.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002013" seq="2017-1002013" published="2017-09-14" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=189" adv="1">http://www.vapidlabs.com/advisory.php?v=189</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/image-gallery-with-slideshow/" adv="1">https://wordpress.org/plugins/image-gallery-with-slideshow/</ref>
    </refs>
    <vuln_soft>
      <prod name="image-gallery-with-slideshow" vendor="anblik">
        <vers num="1.5.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002014" seq="2017-1002014" published="2017-09-14" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=189" adv="1">http://www.vapidlabs.com/advisory.php?v=189</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/image-gallery-with-slideshow/" adv="1">https://wordpress.org/plugins/image-gallery-with-slideshow/</ref>
    </refs>
    <vuln_soft>
      <prod name="image-gallery-with-slideshow" vendor="anblik">
        <vers num="1.5.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002015" seq="2017-1002015" published="2017-09-14" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=189" adv="1">http://www.vapidlabs.com/advisory.php?v=189</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/image-gallery-with-slideshow/" adv="1">https://wordpress.org/plugins/image-gallery-with-slideshow/</ref>
    </refs>
    <vuln_soft>
      <prod name="image-gallery-with-slideshow" vendor="anblik">
        <vers num="1.5.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002016" seq="2017-1002016" published="2017-09-14" modified="2017-09-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=190" adv="1">http://www.vapidlabs.com/advisory.php?v=190</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/flickr-picture-backup/">https://wordpress.org/plugins/flickr-picture-backup/</ref>
    </refs>
    <vuln_soft>
      <prod name="flickr-picture-backup" vendor="flickr-picture-backup_project">
        <vers num="0.7" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002017" seq="2017-1002017" published="2017-09-14" modified="2017-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=191" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=191</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/gift-certificate-creator/" adv="1">https://wordpress.org/plugins/gift-certificate-creator/</ref>
    </refs>
    <vuln_soft>
      <prod name="gift-certificate-creator" vendor="bobcares">
        <vers num="1.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002018" seq="2017-1002018" published="2017-09-14" modified="2017-09-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=192" adv="1">http://www.vapidlabs.com/advisory.php?v=192</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/eventr/" adv="1">https://wordpress.org/plugins/eventr/</ref>
    </refs>
    <vuln_soft>
      <prod name="eventr" vendor="eventr_project">
        <vers num="1.02.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002019" seq="2017-1002019" published="2017-09-14" modified="2017-09-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=192" adv="1">http://www.vapidlabs.com/advisory.php?v=192</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/eventr/" adv="1">https://wordpress.org/plugins/eventr/</ref>
    </refs>
    <vuln_soft>
      <prod name="eventr" vendor="eventr_project">
        <vers num="1.02.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002020" seq="2017-1002020" published="2017-09-14" modified="2017-09-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=193" adv="1">http://www.vapidlabs.com/advisory.php?v=193</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/surveys/" adv="1">https://wordpress.org/plugins/surveys/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8833" adv="1">https://wpvulndb.com/vulnerabilities/8833</ref>
    </refs>
    <vuln_soft>
      <prod name="surveys" vendor="surveys_project">
        <vers num="1.01.8" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002021" seq="2017-1002021" published="2017-09-14" modified="2017-09-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=193" adv="1">http://www.vapidlabs.com/advisory.php?v=193</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/surveys/" adv="1">https://wordpress.org/plugins/surveys/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8833" adv="1">https://wpvulndb.com/vulnerabilities/8833</ref>
    </refs>
    <vuln_soft>
      <prod name="surveys" vendor="surveys_project">
        <vers num="1.01.8" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002022" seq="2017-1002022" published="2017-09-14" modified="2017-09-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=193" adv="1">http://www.vapidlabs.com/advisory.php?v=193</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/surveys/" adv="1">https://wordpress.org/plugins/surveys/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8833" adv="1">https://wpvulndb.com/vulnerabilities/8833</ref>
    </refs>
    <vuln_soft>
      <prod name="surveys" vendor="surveys_project">
        <vers num="1.01.8" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002023" seq="2017-1002023" published="2017-09-14" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=194" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=194</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/easy-team-manager/" adv="1">https://wordpress.org/plugins/easy-team-manager/</ref>
    </refs>
    <vuln_soft>
      <prod name="easy_team_manager" vendor="daisythemes">
        <vers num="1.3.2" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002024" seq="2017-1002024" published="2017-09-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://kindeditor.org">http://kindeditor.org</ref>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=195" adv="1">http://www.vapidlabs.com/advisory.php?v=195</ref>
      <ref source="MISC" url="https://github.com/kindsoft/kindeditor" adv="1" patch="1">https://github.com/kindsoft/kindeditor</ref>
    </refs>
    <vuln_soft>
      <prod name="kind_editor" vendor="kindsoft">
        <vers num="3.5.6" prev="1"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
      </prod>
      <prod name="kindeditor" vendor="kindsoft">
        <vers num="4.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002025" seq="2017-1002025" published="2017-09-14" modified="2017-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=196" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=196</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/add-edit-delete-listing-for-member-module/" adv="1">https://wordpress.org/plugins/add-edit-delete-listing-for-member-module/</ref>
    </refs>
    <vuln_soft>
      <prod name="add-edit-delete-listing-for-member-module" vendor="add-edit-delete-listing-for-member-module_project">
        <vers num="1.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002026" seq="2017-1002026" published="2017-09-14" modified="2019-07-31" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=197" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=197</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/event-espresso-free/" adv="1">https://wordpress.org/plugins/event-espresso-free/</ref>
    </refs>
    <vuln_soft>
      <prod name="event_espresso" vendor="eventespresso">
        <vers num="3.1.37.11.l" edition=":~~free~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002027" seq="2017-1002027" published="2017-09-14" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=198" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=198</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/rk-responsive-contact-form/" adv="1">https://wordpress.org/plugins/rk-responsive-contact-form/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8889" adv="1">https://wpvulndb.com/vulnerabilities/8889</ref>
    </refs>
    <vuln_soft>
      <prod name="rk-responsive-contact-form" vendor="rayanehdownload">
        <vers num="1.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002028" seq="2017-1002028" published="2017-09-14" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.vapidlabs.com/advisory.php?v=199" adv="1" patch="1">http://www.vapidlabs.com/advisory.php?v=199</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/wordpress-gallery-transformation/" adv="1">https://wordpress.org/plugins/wordpress-gallery-transformation/</ref>
      <ref source="MISC" url="https://wpvulndb.com/vulnerabilities/8888" adv="1">https://wpvulndb.com/vulnerabilities/8888</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery-transformation" vendor="angrybyte">
        <vers num="1.0" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10021" seq="2017-10021" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99768" adv="1">99768</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002100" seq="2017-1002100" published="2017-09-14" modified="2017-09-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/kubernetes/kubernetes/issues/47611" adv="1" patch="1">https://github.com/kubernetes/kubernetes/issues/47611</ref>
      <ref source="MISC" url="https://groups.google.com/d/msg/kubernetes-security-announce/n3VBg_WJZic/-ddIqKXqAAAJ" adv="1" patch="1">https://groups.google.com/d/msg/kubernetes-security-announce/n3VBg_WJZic/-ddIqKXqAAAJ</ref>
    </refs>
    <vuln_soft>
      <prod name="kubernetes" vendor="kubernetes">
        <vers num="1.6.0" edition="alpha.0"/>
        <vers num="1.6.0" edition="alpha.1"/>
        <vers num="1.6.0" edition="alpha.2"/>
        <vers num="1.6.0" edition="alpha.3"/>
        <vers num="1.6.0" edition="beta.0"/>
        <vers num="1.6.0" edition="beta.1"/>
        <vers num="1.6.0" edition="beta.2"/>
        <vers num="1.6.0" edition="beta.3"/>
        <vers num="1.6.0" edition="beta.4"/>
        <vers num="1.6.0" edition="rc.1"/>
        <vers num="1.6.1" edition="beta.0"/>
        <vers num="1.6.2" edition="beta.0"/>
        <vers num="1.6.3" edition="beta.0"/>
        <vers num="1.6.3" edition="beta.1"/>
        <vers num="1.6.4" edition="beta.0"/>
        <vers num="1.6.4" edition="beta.1"/>
        <vers num="1.6.5" edition="beta.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002101" seq="2017-1002101" published="2018-03-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0475" adv="1">RHSA-2018:0475</ref>
      <ref source="MISC" url="https://github.com/bgeesaman/subpath-exploit/" adv="1">https://github.com/bgeesaman/subpath-exploit/</ref>
      <ref source="CONFIRM" url="https://github.com/kubernetes/kubernetes/issues/60813" adv="1">https://github.com/kubernetes/kubernetes/issues/60813</ref>
    </refs>
    <vuln_soft>
      <prod name="kubernetes" vendor="kubernetes">
        <vers num="1.3.0" edition="-"/>
        <vers num="1.3.0" edition="alpha0"/>
        <vers num="1.3.0" edition="alpha1"/>
        <vers num="1.3.0" edition="alpha2"/>
        <vers num="1.3.0" edition="alpha3"/>
        <vers num="1.3.0" edition="alpha4"/>
        <vers num="1.3.0" edition="alpha5"/>
        <vers num="1.3.0" edition="beta0"/>
        <vers num="1.3.0" edition="beta1"/>
        <vers num="1.3.0" edition="beta2"/>
        <vers num="1.3.0" edition="beta3"/>
        <vers num="1.3.1" edition="-"/>
        <vers num="1.3.1" edition="beta0"/>
        <vers num="1.3.1" edition="beta1"/>
        <vers num="1.3.2" edition="-"/>
        <vers num="1.3.2" edition="beta0"/>
        <vers num="1.3.3" edition="-"/>
        <vers num="1.3.3" edition="beta0"/>
        <vers num="1.3.4" edition="-"/>
        <vers num="1.3.4" edition="beta0"/>
        <vers num="1.3.5" edition="-"/>
        <vers num="1.3.5" edition="beta0"/>
        <vers num="1.3.6" edition="-"/>
        <vers num="1.3.6" edition="beta0"/>
        <vers num="1.3.7" edition="-"/>
        <vers num="1.3.7" edition="beta0"/>
        <vers num="1.3.8" edition="-"/>
        <vers num="1.3.8" edition="beta0"/>
        <vers num="1.3.9" edition="-"/>
        <vers num="1.3.9" edition="beta0"/>
        <vers num="1.3.10" edition="-"/>
        <vers num="1.3.10" edition="beta0"/>
        <vers num="1.4.0" edition="-"/>
        <vers num="1.4.0" edition="alpha0"/>
        <vers num="1.4.0" edition="alpha1"/>
        <vers num="1.4.0" edition="alpha2"/>
        <vers num="1.4.0" edition="alpha3"/>
        <vers num="1.4.0" edition="beta0"/>
        <vers num="1.4.0" edition="beta1"/>
        <vers num="1.4.0" edition="beta10"/>
        <vers num="1.4.0" edition="beta11"/>
        <vers num="1.4.0" edition="beta2"/>
        <vers num="1.4.0" edition="beta3"/>
        <vers num="1.4.0" edition="beta4"/>
        <vers num="1.4.0" edition="beta5"/>
        <vers num="1.4.0" edition="beta6"/>
        <vers num="1.4.0" edition="beta7"/>
        <vers num="1.4.0" edition="beta8"/>
        <vers num="1.4.0" edition="beta9"/>
        <vers num="1.4.1" edition="-"/>
        <vers num="1.4.1" edition="beta0"/>
        <vers num="1.4.1" edition="beta1"/>
        <vers num="1.4.1" edition="beta2"/>
        <vers num="1.4.2" edition="-"/>
        <vers num="1.4.2" edition="beta0"/>
        <vers num="1.4.2" edition="beta1"/>
        <vers num="1.4.3" edition="-"/>
        <vers num="1.4.3" edition="beta0"/>
        <vers num="1.4.4" edition="-"/>
        <vers num="1.4.4" edition="beta0"/>
        <vers num="1.4.5" edition="-"/>
        <vers num="1.4.5" edition="beta0"/>
        <vers num="1.4.6" edition="-"/>
        <vers num="1.4.6" edition="beta0"/>
        <vers num="1.4.7" edition="-"/>
        <vers num="1.4.7" edition="beta0"/>
        <vers num="1.4.8" edition="-"/>
        <vers num="1.4.8" edition="beta0"/>
        <vers num="1.4.9" edition="-"/>
        <vers num="1.4.9" edition="beta0"/>
        <vers num="1.4.11" edition="beta0"/>
        <vers num="1.4.12" edition="-"/>
        <vers num="1.4.12" edition="beta0"/>
        <vers num="1.5.0" edition="-"/>
        <vers num="1.5.0" edition="alpha0"/>
        <vers num="1.5.0" edition="alpha1"/>
        <vers num="1.5.0" edition="alpha2"/>
        <vers num="1.5.0" edition="beta0"/>
        <vers num="1.5.0" edition="beta1"/>
        <vers num="1.5.0" edition="beta2"/>
        <vers num="1.5.0" edition="beta3"/>
        <vers num="1.5.1" edition="-"/>
        <vers num="1.5.1" edition="beta0"/>
        <vers num="1.5.2" edition="-"/>
        <vers num="1.5.2" edition="beta0"/>
        <vers num="1.5.3" edition="-"/>
        <vers num="1.5.3" edition="beta0"/>
        <vers num="1.5.4" edition="-"/>
        <vers num="1.5.4" edition="beta0"/>
        <vers num="1.5.5" edition="-"/>
        <vers num="1.5.5" edition="beta0"/>
        <vers num="1.5.6" edition="-"/>
        <vers num="1.5.6" edition="beta0"/>
        <vers num="1.5.7" edition="-"/>
        <vers num="1.5.7" edition="beta0"/>
        <vers num="1.5.8" edition="-"/>
        <vers num="1.5.8" edition="beta0"/>
        <vers num="1.6.0" edition="-"/>
        <vers num="1.6.0" edition="alpha0"/>
        <vers num="1.6.0" edition="alpha1"/>
        <vers num="1.6.0" edition="alpha2"/>
        <vers num="1.6.0" edition="alpha3"/>
        <vers num="1.6.0" edition="beta0"/>
        <vers num="1.6.0" edition="beta1"/>
        <vers num="1.6.0" edition="beta2"/>
        <vers num="1.6.0" edition="beta3"/>
        <vers num="1.6.0" edition="beta4"/>
        <vers num="1.6.0" edition="rc1"/>
        <vers num="1.6.1" edition="-"/>
        <vers num="1.6.1" edition="beta0"/>
        <vers num="1.6.2" edition="-"/>
        <vers num="1.6.2" edition="beta0"/>
        <vers num="1.6.3" edition="-"/>
        <vers num="1.6.3" edition="beta0"/>
        <vers num="1.6.3" edition="beta1"/>
        <vers num="1.6.4" edition="-"/>
        <vers num="1.6.4" edition="beta0"/>
        <vers num="1.6.4" edition="beta1"/>
        <vers num="1.6.5" edition="-"/>
        <vers num="1.6.5" edition="beta0"/>
        <vers num="1.6.6" edition="-"/>
        <vers num="1.6.6" edition="beta0"/>
        <vers num="1.6.7" edition="-"/>
        <vers num="1.6.7" edition="beta0"/>
        <vers num="1.6.8" edition="-"/>
        <vers num="1.6.8" edition="beta0"/>
        <vers num="1.6.9" edition="-"/>
        <vers num="1.6.9" edition="beta0"/>
        <vers num="1.6.10" edition="-"/>
        <vers num="1.6.10" edition="beta0"/>
        <vers num="1.6.11" edition="-"/>
        <vers num="1.6.11" edition="beta0"/>
        <vers num="1.6.12" edition="-"/>
        <vers num="1.6.12" edition="beta0"/>
        <vers num="1.6.13" edition="-"/>
        <vers num="1.6.13" edition="beta0"/>
        <vers num="1.7.0" edition="-"/>
        <vers num="1.7.0" edition="alpha0"/>
        <vers num="1.7.0" edition="alpha1"/>
        <vers num="1.7.0" edition="alpha2"/>
        <vers num="1.7.0" edition="alpha3"/>
        <vers num="1.7.0" edition="alpha4"/>
        <vers num="1.7.0" edition="beta0"/>
        <vers num="1.7.0" edition="beta1"/>
        <vers num="1.7.0" edition="beta2"/>
        <vers num="1.7.0" edition="beta3"/>
        <vers num="1.7.0" edition="rc1"/>
        <vers num="1.7.1" edition="-"/>
        <vers num="1.7.1" edition="beta0"/>
        <vers num="1.7.2" edition="-"/>
        <vers num="1.7.2" edition="beta0"/>
        <vers num="1.7.3" edition="-"/>
        <vers num="1.7.3" edition="beta0"/>
        <vers num="1.7.4" edition="-"/>
        <vers num="1.7.4" edition="beta0"/>
        <vers num="1.7.5" edition="-"/>
        <vers num="1.7.5" edition="beta0"/>
        <vers num="1.7.6" edition="-"/>
        <vers num="1.7.6" edition="beta0"/>
        <vers num="1.7.7" edition="-"/>
        <vers num="1.7.7" edition="beta0"/>
        <vers num="1.7.8" edition="-"/>
        <vers num="1.7.8" edition="beta0"/>
        <vers num="1.7.9" edition="-"/>
        <vers num="1.7.9" edition="beta0"/>
        <vers num="1.7.10" edition="-"/>
        <vers num="1.7.10" edition="beta0"/>
        <vers num="1.7.11" edition="-"/>
        <vers num="1.7.11" edition="beta0"/>
        <vers num="1.7.12" edition="-"/>
        <vers num="1.7.12" edition="beta0"/>
        <vers num="1.7.13" edition="-"/>
        <vers num="1.7.13" edition="beta0"/>
        <vers num="1.8.0" edition="-"/>
        <vers num="1.8.0" edition="alpha0"/>
        <vers num="1.8.0" edition="alpha1"/>
        <vers num="1.8.0" edition="alpha2"/>
        <vers num="1.8.0" edition="alpha3"/>
        <vers num="1.8.0" edition="beta0"/>
        <vers num="1.8.0" edition="beta1"/>
        <vers num="1.8.0" edition="rc1"/>
        <vers num="1.8.1" edition="-"/>
        <vers num="1.8.1" edition="beta0"/>
        <vers num="1.8.2" edition="-"/>
        <vers num="1.8.2" edition="beta0"/>
        <vers num="1.8.3" edition="-"/>
        <vers num="1.8.3" edition="beta0"/>
        <vers num="1.8.4" edition="-"/>
        <vers num="1.8.4" edition="beta0"/>
        <vers num="1.8.5" edition="-"/>
        <vers num="1.8.5" edition="beta0"/>
        <vers num="1.8.6" edition="-"/>
        <vers num="1.8.6" edition="beta0"/>
        <vers num="1.8.7" edition="-"/>
        <vers num="1.8.7" edition="beta0"/>
        <vers num="1.8.8" edition="-"/>
        <vers num="1.8.8" edition="beta0"/>
        <vers num="1.9.0" edition="-"/>
        <vers num="1.9.0" edition="alpha0"/>
        <vers num="1.9.0" edition="alpha1"/>
        <vers num="1.9.0" edition="alpha2"/>
        <vers num="1.9.0" edition="alpha3"/>
        <vers num="1.9.0" edition="beta0"/>
        <vers num="1.9.0" edition="beta1"/>
        <vers num="1.9.0" edition="beta2"/>
        <vers num="1.9.1" edition="-"/>
        <vers num="1.9.1" edition="beta0"/>
        <vers num="1.9.2" edition="-"/>
        <vers num="1.9.2" edition="beta0"/>
        <vers num="1.9.3" edition="-"/>
        <vers num="1.9.3" edition="beta0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002102" seq="2017-1002102" published="2018-03-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:C/A:C)">
    <desc>
      <descript source="cve">In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0475" adv="1">RHSA-2018:0475</ref>
      <ref source="CONFIRM" url="https://github.com/kubernetes/kubernetes/issues/60814" adv="1">https://github.com/kubernetes/kubernetes/issues/60814</ref>
    </refs>
    <vuln_soft>
      <prod name="kubernetes" vendor="kubernetes">
        <vers num="1.3.0" edition="-"/>
        <vers num="1.3.0" edition="alpha0"/>
        <vers num="1.3.0" edition="alpha1"/>
        <vers num="1.3.0" edition="alpha2"/>
        <vers num="1.3.0" edition="alpha3"/>
        <vers num="1.3.0" edition="alpha4"/>
        <vers num="1.3.0" edition="alpha5"/>
        <vers num="1.3.0" edition="beta0"/>
        <vers num="1.3.0" edition="beta1"/>
        <vers num="1.3.0" edition="beta2"/>
        <vers num="1.3.0" edition="beta3"/>
        <vers num="1.3.1" edition="-"/>
        <vers num="1.3.1" edition="beta0"/>
        <vers num="1.3.1" edition="beta1"/>
        <vers num="1.3.2" edition="-"/>
        <vers num="1.3.2" edition="beta0"/>
        <vers num="1.3.3" edition="-"/>
        <vers num="1.3.3" edition="beta0"/>
        <vers num="1.3.4" edition="-"/>
        <vers num="1.3.4" edition="beta0"/>
        <vers num="1.3.5" edition="-"/>
        <vers num="1.3.5" edition="beta0"/>
        <vers num="1.3.6" edition="-"/>
        <vers num="1.3.6" edition="beta0"/>
        <vers num="1.3.7" edition="-"/>
        <vers num="1.3.7" edition="beta0"/>
        <vers num="1.3.8" edition="-"/>
        <vers num="1.3.8" edition="beta0"/>
        <vers num="1.3.9" edition="-"/>
        <vers num="1.3.9" edition="beta0"/>
        <vers num="1.3.10" edition="-"/>
        <vers num="1.3.10" edition="beta0"/>
        <vers num="1.4.0" edition="-"/>
        <vers num="1.4.0" edition="alpha0"/>
        <vers num="1.4.0" edition="alpha1"/>
        <vers num="1.4.0" edition="alpha2"/>
        <vers num="1.4.0" edition="alpha3"/>
        <vers num="1.4.0" edition="beta0"/>
        <vers num="1.4.0" edition="beta1"/>
        <vers num="1.4.0" edition="beta10"/>
        <vers num="1.4.0" edition="beta11"/>
        <vers num="1.4.0" edition="beta2"/>
        <vers num="1.4.0" edition="beta3"/>
        <vers num="1.4.0" edition="beta4"/>
        <vers num="1.4.0" edition="beta5"/>
        <vers num="1.4.0" edition="beta6"/>
        <vers num="1.4.0" edition="beta7"/>
        <vers num="1.4.0" edition="beta8"/>
        <vers num="1.4.0" edition="beta9"/>
        <vers num="1.4.1" edition="-"/>
        <vers num="1.4.1" edition="beta0"/>
        <vers num="1.4.1" edition="beta1"/>
        <vers num="1.4.1" edition="beta2"/>
        <vers num="1.4.2" edition="-"/>
        <vers num="1.4.2" edition="beta0"/>
        <vers num="1.4.2" edition="beta1"/>
        <vers num="1.4.3" edition="-"/>
        <vers num="1.4.3" edition="beta0"/>
        <vers num="1.4.4" edition="-"/>
        <vers num="1.4.4" edition="beta0"/>
        <vers num="1.4.5" edition="-"/>
        <vers num="1.4.5" edition="beta0"/>
        <vers num="1.4.6" edition="-"/>
        <vers num="1.4.6" edition="beta0"/>
        <vers num="1.4.7" edition="-"/>
        <vers num="1.4.7" edition="beta0"/>
        <vers num="1.4.8" edition="-"/>
        <vers num="1.4.8" edition="beta0"/>
        <vers num="1.4.9" edition="-"/>
        <vers num="1.4.9" edition="beta0"/>
        <vers num="1.4.11" edition="beta0"/>
        <vers num="1.4.12" edition="-"/>
        <vers num="1.4.12" edition="beta0"/>
        <vers num="1.5.0" edition="-"/>
        <vers num="1.5.0" edition="alpha0"/>
        <vers num="1.5.0" edition="alpha1"/>
        <vers num="1.5.0" edition="alpha2"/>
        <vers num="1.5.0" edition="beta0"/>
        <vers num="1.5.0" edition="beta1"/>
        <vers num="1.5.0" edition="beta2"/>
        <vers num="1.5.0" edition="beta3"/>
        <vers num="1.5.1" edition="-"/>
        <vers num="1.5.1" edition="beta0"/>
        <vers num="1.5.2" edition="-"/>
        <vers num="1.5.2" edition="beta0"/>
        <vers num="1.5.3" edition="-"/>
        <vers num="1.5.3" edition="beta0"/>
        <vers num="1.5.4" edition="-"/>
        <vers num="1.5.4" edition="beta0"/>
        <vers num="1.5.5" edition="-"/>
        <vers num="1.5.5" edition="beta0"/>
        <vers num="1.5.6" edition="-"/>
        <vers num="1.5.6" edition="beta0"/>
        <vers num="1.5.7" edition="-"/>
        <vers num="1.5.7" edition="beta0"/>
        <vers num="1.5.8" edition="-"/>
        <vers num="1.5.8" edition="beta0"/>
        <vers num="1.6.0" edition="-"/>
        <vers num="1.6.0" edition="alpha0"/>
        <vers num="1.6.0" edition="alpha1"/>
        <vers num="1.6.0" edition="alpha2"/>
        <vers num="1.6.0" edition="alpha3"/>
        <vers num="1.6.0" edition="beta0"/>
        <vers num="1.6.0" edition="beta1"/>
        <vers num="1.6.0" edition="beta2"/>
        <vers num="1.6.0" edition="beta3"/>
        <vers num="1.6.0" edition="beta4"/>
        <vers num="1.6.0" edition="rc1"/>
        <vers num="1.6.1" edition="-"/>
        <vers num="1.6.1" edition="beta0"/>
        <vers num="1.6.2" edition="-"/>
        <vers num="1.6.2" edition="beta0"/>
        <vers num="1.6.3" edition="-"/>
        <vers num="1.6.3" edition="beta0"/>
        <vers num="1.6.3" edition="beta1"/>
        <vers num="1.6.4" edition="-"/>
        <vers num="1.6.4" edition="beta0"/>
        <vers num="1.6.4" edition="beta1"/>
        <vers num="1.6.5" edition="-"/>
        <vers num="1.6.5" edition="beta0"/>
        <vers num="1.6.6" edition="-"/>
        <vers num="1.6.6" edition="beta0"/>
        <vers num="1.6.7" edition="-"/>
        <vers num="1.6.7" edition="beta0"/>
        <vers num="1.6.8" edition="-"/>
        <vers num="1.6.8" edition="beta0"/>
        <vers num="1.6.9" edition="-"/>
        <vers num="1.6.9" edition="beta0"/>
        <vers num="1.6.10" edition="-"/>
        <vers num="1.6.10" edition="beta0"/>
        <vers num="1.6.11" edition="-"/>
        <vers num="1.6.11" edition="beta0"/>
        <vers num="1.6.12" edition="-"/>
        <vers num="1.6.12" edition="beta0"/>
        <vers num="1.6.13" edition="-"/>
        <vers num="1.6.13" edition="beta0"/>
        <vers num="1.7.0" edition="-"/>
        <vers num="1.7.0" edition="alpha0"/>
        <vers num="1.7.0" edition="alpha1"/>
        <vers num="1.7.0" edition="alpha2"/>
        <vers num="1.7.0" edition="alpha3"/>
        <vers num="1.7.0" edition="alpha4"/>
        <vers num="1.7.0" edition="beta0"/>
        <vers num="1.7.0" edition="beta1"/>
        <vers num="1.7.0" edition="beta2"/>
        <vers num="1.7.0" edition="beta3"/>
        <vers num="1.7.0" edition="rc1"/>
        <vers num="1.7.1" edition="-"/>
        <vers num="1.7.1" edition="beta0"/>
        <vers num="1.7.2" edition="-"/>
        <vers num="1.7.2" edition="beta0"/>
        <vers num="1.7.3" edition="-"/>
        <vers num="1.7.3" edition="beta0"/>
        <vers num="1.7.4" edition="-"/>
        <vers num="1.7.4" edition="beta0"/>
        <vers num="1.7.5" edition="-"/>
        <vers num="1.7.5" edition="beta0"/>
        <vers num="1.7.6" edition="-"/>
        <vers num="1.7.6" edition="beta0"/>
        <vers num="1.7.7" edition="-"/>
        <vers num="1.7.7" edition="beta0"/>
        <vers num="1.7.8" edition="-"/>
        <vers num="1.7.8" edition="beta0"/>
        <vers num="1.7.9" edition="-"/>
        <vers num="1.7.9" edition="beta0"/>
        <vers num="1.7.10" edition="-"/>
        <vers num="1.7.10" edition="beta0"/>
        <vers num="1.7.11" edition="-"/>
        <vers num="1.7.11" edition="beta0"/>
        <vers num="1.7.12" edition="-"/>
        <vers num="1.7.12" edition="beta0"/>
        <vers num="1.7.13" edition="-"/>
        <vers num="1.7.13" edition="beta0"/>
        <vers num="1.8.0" edition="-"/>
        <vers num="1.8.0" edition="alpha0"/>
        <vers num="1.8.0" edition="alpha1"/>
        <vers num="1.8.0" edition="alpha2"/>
        <vers num="1.8.0" edition="alpha3"/>
        <vers num="1.8.0" edition="beta0"/>
        <vers num="1.8.0" edition="beta1"/>
        <vers num="1.8.0" edition="rc1"/>
        <vers num="1.8.1" edition="-"/>
        <vers num="1.8.1" edition="beta0"/>
        <vers num="1.8.2" edition="-"/>
        <vers num="1.8.2" edition="beta0"/>
        <vers num="1.8.3" edition="-"/>
        <vers num="1.8.3" edition="beta0"/>
        <vers num="1.8.4" edition="-"/>
        <vers num="1.8.4" edition="beta0"/>
        <vers num="1.8.5" edition="-"/>
        <vers num="1.8.5" edition="beta0"/>
        <vers num="1.8.6" edition="-"/>
        <vers num="1.8.6" edition="beta0"/>
        <vers num="1.8.7" edition="-"/>
        <vers num="1.8.7" edition="beta0"/>
        <vers num="1.8.8" edition="-"/>
        <vers num="1.8.8" edition="beta0"/>
        <vers num="1.9.0" edition="-"/>
        <vers num="1.9.0" edition="alpha0"/>
        <vers num="1.9.0" edition="alpha1"/>
        <vers num="1.9.0" edition="alpha2"/>
        <vers num="1.9.0" edition="alpha3"/>
        <vers num="1.9.0" edition="beta0"/>
        <vers num="1.9.0" edition="beta1"/>
        <vers num="1.9.0" edition="beta2"/>
        <vers num="1.9.1" edition="-"/>
        <vers num="1.9.1" edition="beta0"/>
        <vers num="1.9.2" edition="-"/>
        <vers num="1.9.2" edition="beta0"/>
        <vers num="1.9.3" edition="-"/>
        <vers num="1.9.3" edition="beta0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002150" seq="2017-1002150" published="2017-09-14" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929" adv="1" patch="1">https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929</ref>
      <ref source="MISC" url="https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929.patch" adv="1" patch="1">https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929.patch</ref>
    </refs>
    <vuln_soft>
      <prod name="python-fedora" vendor="fedoraproject">
        <vers num="0.8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002151" seq="2017-1002151" published="2017-09-14" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://pagure.io/pagure/c/c92108097e8ae4702c115ae4702b63d960838e75.patch" adv="1" patch="1">https://pagure.io/pagure/c/c92108097e8ae4702c115ae4702b63d960838e75.patch</ref>
      <ref source="MISC" url="https://pagure.io/pagure/pull-request/2426" adv="1">https://pagure.io/pagure/pull-request/2426</ref>
    </refs>
    <vuln_soft>
      <prod name="pagure" vendor="pagure">
        <vers num="3.3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002152" seq="2017-1002152" published="2019-01-10" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/fedora-infra/bodhi/issues/1740" adv="1">https://github.com/fedora-infra/bodhi/issues/1740</ref>
    </refs>
    <vuln_soft>
      <prod name="bodhi" vendor="redhat">
        <vers num="2.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002153" seq="2017-1002153" published="2017-10-06" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://pagure.io/koji/issue/563" patch="1">https://pagure.io/koji/issue/563</ref>
    </refs>
    <vuln_soft>
      <prod name="koji" vendor="koji_project">
        <vers num="1.13.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1002157" seq="2017-1002157" published="2019-01-10" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://pagure.io/modulemd/issue/55" adv="1">https://pagure.io/modulemd/issue/55</ref>
    </refs>
    <vuln_soft>
      <prod name="modulemd" vendor="redhat">
        <vers num="1.3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10022" seq="2017-10022" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99864" adv="1">99864</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10023" seq="2017-10023" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99816" adv="1">99816</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10024" seq="2017-10024" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Layout Tools). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99723" adv="1">99723</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10025" seq="2017-10025" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99697" adv="1">99697</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10026" seq="2017-10026" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle SOA Suite accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101318" adv="1">101318</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="soa_suite" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10027" seq="2017-10027" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage &amp; Navigation). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99803" adv="1">99803</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10028" seq="2017-10028" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99724" adv="1">99724</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10029" seq="2017-10029" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99738" adv="1">99738</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10030" seq="2017-10030" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99740" adv="1">99740</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10031" seq="2017-10031" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Communications Convergence component of Oracle Communications Applications (subcomponent: Mail Proxy (dojo)). Supported versions that are affected are 3.0 and 3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence. While the vulnerability is in Oracle Communications Convergence, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as unauthorized read access to a subset of Oracle Communications Convergence accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99720" adv="1">99720</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038945" adv="1">1038945</ref>
    </refs>
    <vuln_soft>
      <prod name="communications_convergence" vendor="oracle">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10032" seq="2017-10032" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Access Control List). Supported versions that are affected are 6.3.4.1, 6.3.5.1, 6.3.6.1, 6.3.7.1, 6.4.0, 6.4.1 and 6.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99686" adv="1">99686</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="transportation_management" vendor="oracle">
        <vers num="6.3.4.1"/>
        <vers num="6.3.5.1"/>
        <vers num="6.3.6.1"/>
        <vers num="6.3.7.1"/>
        <vers num="6.4.0"/>
        <vers num="6.4.1"/>
        <vers num="6.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10033" seq="2017-10033" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Supported versions that are affected are 11.1.1.8.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Sites executes to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data as well as unauthorized read access to a subset of Oracle WebCenter Sites accessible data. Note: Please refer to Doc ID &lt;a href="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=2318213.1">My Oracle Support Note 2318213.1 for instructions on how to address this issue. CVSS 3.0 Base Score 4.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101408" adv="1">101408</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44757/">44757</ref>
    </refs>
    <vuln_soft>
      <prod name="webcenter_sites" vendor="oracle">
        <vers num="11.1.1.8.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10034" seq="2017-10034" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Core Formatting API). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101307" adv="1">101307</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101405" adv="1">101405</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10035" seq="2017-10035" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99741" adv="1">99741</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10036" seq="2017-10036" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFSv4 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99840" adv="1">99840</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10037" seq="2017-10037" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101334" adv="1">101334</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10038" seq="2017-10038" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99751" adv="1">99751</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_p6_enterprise_project_portfolio_management" vendor="oracle">
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10039" seq="2017-10039" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Web Client). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99657" adv="1">99657</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_governance_and_compliance" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10040" seq="2017-10040" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99801" adv="1">99801</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="webcenter_content" vendor="oracle">
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10041" seq="2017-10041" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99742" adv="1">99742</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10042" seq="2017-10042" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: IKE). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via IKE to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99838" adv="1">99838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10043" seq="2017-10043" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99696" adv="1">99696</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10044" seq="2017-10044" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99714" adv="1">99714</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10045" seq="2017-10045" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99806" adv="1">99806</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10046" seq="2017-10046" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99770" adv="1">99770</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/44141/">44141</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_p6_enterprise_project_portfolio_management" vendor="oracle">
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10047" seq="2017-10047" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the MICROS BellaVita component of Oracle Hospitality Applications (subcomponent: Interface). The supported version that is affected is 2.7.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MICROS BellaVita. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MICROS BellaVita accessible data as well as unauthorized read access to a subset of MICROS BellaVita accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99661" adv="1">99661</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="micros_bellavita" vendor="oracle">
        <vers num="2.7.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10048" seq="2017-10048" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Enterprise Repository component of Oracle Fusion Middleware (subcomponent: Web Interface). Supported versions that are affected are 11.1.1.7.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Repository. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Repository, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Repository accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Repository accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99771" adv="1">99771</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_repository" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="12.1.3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10049" seq="2017-10049" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel Core CRM component of Oracle Siebel CRM (subcomponent: Search). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core CRM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core CRM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel Core CRM accessible data as well as unauthorized read access to a subset of Siebel Core CRM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99626" adv="1">99626</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038936" adv="1">1038936</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_core-server_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10050" seq="2017-10050" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101363" adv="1">101363</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10051" seq="2017-10051" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.7" CVSS_base_score="2.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 5.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101377" adv="1">101377</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="outside_in_technology" vendor="oracle">
        <vers num="8.5.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10052" seq="2017-10052" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PCMServlet). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99660" adv="1">99660</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10053" seq="2017-10053" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99842" adv="1">99842</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10054" seq="2017-10054" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Materials Management component of Oracle Hospitality Applications (subcomponent: MMS). The supported version that is affected is 7.30.564.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Cruise Materials Management executes to compromise Oracle Hospitality Cruise Materials Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Materials Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Materials Management accessible data. CVSS 3.0 Base Score 5.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101456" adv="1">101456</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_materials_management" vendor="oracle">
        <vers num="7.30.564.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10055" seq="2017-10055" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iPlanet Web Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iPlanet Web Server accessible data as well as unauthorized read access to a subset of Oracle iPlanet Web Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101374" adv="1">101374</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039605" adv="1">1039605</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="oracle">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10056" seq="2017-10056" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality 9700 component of Oracle Hospitality Applications (subcomponent: Property Management Systems). The supported version that is affected is 4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality 9700 executes to compromise Oracle Hospitality 9700. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality 9700 accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99826" adv="1">99826</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_9700" vendor="oracle">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10057" seq="2017-10057" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Discussion Forum). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99798" adv="1">99798</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10058" seq="2017-10058" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 6.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99820" adv="1">99820</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence" vendor="oracle">
        <vers num="11.1.1.9.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.1.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.2.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10059" seq="2017-10059" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Mobile Service). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99743" adv="1">99743</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10060" seq="2017-10060" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101310" adv="1">101310</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence" vendor="oracle">
        <vers num="11.1.1.7.0" edition=":~~enterprise~~~"/>
        <vers num="11.1.1.9.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.1.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.2.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10061" seq="2017-10061" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99728" adv="1">99728</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-038-directory-traversal-vulnerability-integration-gateway-psigw/">https://erpscan.io/advisories/erpscan-17-038-directory-traversal-vulnerability-integration-gateway-psigw/</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-039-file-upload-integration-gateway-psigw-peoplesoft/">https://erpscan.io/advisories/erpscan-17-039-file-upload-integration-gateway-psigw-peoplesoft/</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10062" seq="2017-10062" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Java Web Console). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data as well as unauthorized read access to a subset of Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99845" adv="1">99845</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10063" seq="2017-10063" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.0 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99653" adv="1">99653</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10064" seq="2017-10064" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hospitality WebSuite8 Cloud Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized read access to a subset of Hospitality WebSuite8 Cloud Service accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100229" adv="1">100229</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_websuite8_cloud_service" vendor="oracle">
        <vers num="8.9.6"/>
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10065" seq="2017-10065" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13.2, 13.3, 13.4, 14.0 and 14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Point-of-Service. While the vulnerability is in Oracle Retail Point-of-Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Point-of-Service accessible data as well as unauthorized read access to a subset of Oracle Retail Point-of-Service accessible data. CVSS 3.0 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101359" adv="1">101359</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_point-of-service" vendor="oracle">
        <vers num="6.0.0"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.5.0"/>
        <vers num="6.5.4"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="15.0.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0.0"/>
        <vers num="16.0.0.1"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10066" seq="2017-10066" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Applications Technology Stack component of Oracle E-Business Suite (subcomponent: Oracle Forms). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Technology Stack accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101398" adv="1">101398</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="e-business_suite_technology_stack" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10067" seq="2017-10067" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99756" adv="1">99756</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10068" seq="2017-10068" published="2018-01-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Dashboards). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102535" adv="1">102535</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040207" adv="1">1040207</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence" vendor="oracle">
        <vers num="12.2.1.3.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10069" seq="2017-10069" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Payment Interface component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 6.1.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payment Interface. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payment Interface accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99721" adv="1">99721</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="payment_gateway_services" vendor="oracle">
        <vers num="6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10070" seq="2017-10070" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Maintenance Folders). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99762" adv="1">99762</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10071" seq="2017-10071" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: All Modules). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99866" adv="1">99866</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10072" seq="2017-10072" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: All Modules). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99860" adv="1">99860</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10073" seq="2017-10073" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99850" adv="1">99850</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10074" seq="2017-10074" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99731" adv="1">99731</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10075" seq="2017-10075" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99807" adv="1">99807</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="webcenter_content" vendor="oracle">
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10076" seq="2017-10076" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition Venue Management. While the vulnerability is in Oracle Hospitality Simphony First Edition Venue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony First Edition Venue Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony First Edition Venue Management accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99666" adv="1">99666</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony_first_edition_venue_management" vendor="oracle">
        <vers num="3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10077" seq="2017-10077" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: AD Utilities). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications DBA accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101389" adv="1">101389</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="applications_dba" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10078" seq="2017-10078" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99752" adv="1">99752</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10079" seq="2017-10079" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suites Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suites Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suites Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Suites Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Suites Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99684" adv="1">99684</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suites_management" vendor="oracle">
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10080" seq="2017-10080" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99669" adv="1">99669</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10081" seq="2017-10081" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99853" adv="1">99853</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10082" seq="2017-10082" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99673" adv="1">99673</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10083" seq="2017-10083" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99844" adv="1">99844</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10084" seq="2017-10084" published="2017-08-08" modified="2017-08-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Report Generator). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99836" adv="1">99836</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10085" seq="2017-10085" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99628" adv="1">99628</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10086" seq="2017-10086" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4005">DSA-4005</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99662" adv="1">99662</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10087" seq="2017-10087" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99703" adv="1">99703</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10088" seq="2017-10088" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 3.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99698" adv="1">99698</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10089" seq="2017-10089" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99659" adv="1">99659</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10090" seq="2017-10090" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99706" adv="1">99706</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10091" seq="2017-10091" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. While the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99649" adv="1">99649</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038930" adv="1">1038930</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_manager_base_platform" vendor="oracle">
        <vers num="12.1.0"/>
        <vers num="13.1.0"/>
        <vers num="13.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10092" seq="2017-10092" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99677" adv="1">99677</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10093" seq="2017-10093" published="2017-08-08" modified="2017-08-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99692" adv="1">99692</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10094" seq="2017-10094" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99680" adv="1">99680</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038947" adv="1">1038947</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10095" seq="2017-10095" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data. CVSS 3.0 Base Score 3.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99849" adv="1">99849</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10096" seq="2017-10096" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99670" adv="1">99670</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10097" seq="2017-10097" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99679" adv="1">99679</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10098" seq="2017-10098" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99856" adv="1">99856</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3.0"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10099" seq="2017-10099" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the SPARC M7, T7, S7 based Servers component of Oracle Sun Systems Products Suite (subcomponent: Firmware). The supported version that is affected is Prior to 9.7.6.b. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where SPARC M7, T7, S7 based Servers executes to compromise SPARC M7, T7, S7 based Servers. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of SPARC M7, T7, S7 based Servers. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101442" adv="1">101442</ref>
    </refs>
    <vuln_soft>
      <prod name="sparc-sun_system_firmware" vendor="oracle">
        <vers num="9.7.5.e" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10100" seq="2017-10100" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99759" adv="1">99759</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10101" seq="2017-10101" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99674" adv="1">99674</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10102" seq="2017-10102" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99712" adv="1">99712</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10103" seq="2017-10103" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99750" adv="1">99750</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_private_banking" vendor="oracle">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.2.0"/>
        <vers num="12.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10104" seq="2017-10104" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Java Advanced Management Console. While the vulnerability is in Java Advanced Management Console, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data as well as unauthorized read access to a subset of Java Advanced Management Console accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java Advanced Management Console. CVSS 3.0 Base Score 7.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99797" adv="1">99797</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10105" seq="2017-10105" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99851" adv="1">99851</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10106" seq="2017-10106" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99777" adv="1">99777</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-037-multiple-xss-vulnerabilities-testservlet-peoplesoft/">https://erpscan.io/advisories/erpscan-17-037-multiple-xss-vulnerabilities-testservlet-peoplesoft/</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10107" seq="2017-10107" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99719" adv="1">99719</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10108" seq="2017-10108" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99846" adv="1">99846</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10109" seq="2017-10109" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99847" adv="1">99847</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10110" seq="2017-10110" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99643" adv="1">99643</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10111" seq="2017-10111" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99707" adv="1">99707</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10112" seq="2017-10112" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99663" adv="1">99663</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10113" seq="2017-10113" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99639" adv="1">99639</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="common_applications" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10114" seq="2017-10114" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4005">DSA-4005</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99726" adv="1">99726</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10115" seq="2017-10115" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99774" adv="1">99774</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10116" seq="2017-10116" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99734" adv="1">99734</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10117" seq="2017-10117" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99835" adv="1">99835</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10118" seq="2017-10118" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99782" adv="1">99782</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10119" seq="2017-10119" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: OSB Web Console Design, Admin). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Service Bus, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data as well as unauthorized update, insert or delete access to some of Oracle Service Bus accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99813" adv="1">99813</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="service_bus" vendor="oracle">
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10120" seq="2017-10120" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Difficult to exploit vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with logon to the infrastructure where RDBMS Security executes to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS Security accessible data. CVSS 3.0 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99867" adv="1">99867</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038923" adv="1">1038923</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10121" seq="2017-10121" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management Console. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java Advanced Management Console, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data as well as unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99832" adv="1">99832</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10122" seq="2017-10122" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data. CVSS 3.0 Base Score 1.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99852" adv="1">99852</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038938" adv="1">1038938</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="oracle">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10123" seq="2017-10123" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99650" adv="1">99650</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="12.1.3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10125" seq="2017-10125" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows physical access to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to deployment of Java where the Java Auto Update is enabled. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99809" adv="1">99809</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10126" seq="2017-10126" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99760" adv="1">99760</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10128" seq="2017-10128" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hospitality WebSuite8 Cloud Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized read access to a subset of Hospitality WebSuite8 Cloud Service accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99676" adv="1">99676</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_websuite8_cloud_service" vendor="oracle">
        <vers num="8.9.6"/>
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10129" seq="2017-10129" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99638" adv="1">99638</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42426/" adv="1">42426</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10130" seq="2017-10130" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Management). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99678" adv="1">99678</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10131" seq="2017-10131" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99757" adv="1">99757</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_p6_enterprise_project_portfolio_management" vendor="oracle">
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10132" seq="2017-10132" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/iOS). The supported version that is affected is 1.05. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hospitality Hotel Mobile accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99769" adv="1">99769</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10133" seq="2017-10133" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RestAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hospitality Hotel Mobile accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99763" adv="1">99763</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10134" seq="2017-10134" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: eProcurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FSCM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FSCM accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99790" adv="1">99790</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_scm_eprocurement" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10135" seq="2017-10135" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99839" adv="1">99839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10136" seq="2017-10136" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). The supported version that is affected is 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10137" seq="2017-10137" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.6.0 and 12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99634" adv="1">99634</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10140" seq="2017-10140" published="2018-04-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MLIST" url="http://seclists.org/oss-sec/2017/q3/285" adv="1">[oss-sec] 20170611 Berkeley DB reads DB_CONFIG from cwd</ref>
      <ref source="CONFIRM" url="http://www.postfix.org/announcements/postfix-3.2.2.html" adv="1">http://www.postfix.org/announcements/postfix-3.2.2.html</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:0366" adv="1">RHSA-2019:0366</ref>
    </refs>
    <vuln_soft>
      <prod name="postfix" vendor="postfix">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.6"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.12"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14"/>
        <vers num="2.6.15"/>
        <vers num="2.6.16"/>
        <vers num="2.6.17"/>
        <vers num="2.6.18"/>
        <vers num="2.6.19"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.13"/>
        <vers num="2.7.14"/>
        <vers num="2.7.15"/>
        <vers num="2.7.16"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
        <vers num="2.8.7"/>
        <vers num="2.8.8"/>
        <vers num="2.8.9"/>
        <vers num="2.8.10"/>
        <vers num="2.8.11"/>
        <vers num="2.8.12"/>
        <vers num="2.8.13"/>
        <vers num="2.8.14"/>
        <vers num="2.8.15"/>
        <vers num="2.8.16"/>
        <vers num="2.8.17"/>
        <vers num="2.8.18"/>
        <vers num="2.8.19"/>
        <vers num="2.8.20"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.6"/>
        <vers num="2.9.7"/>
        <vers num="2.9.8"/>
        <vers num="2.9.9"/>
        <vers num="2.9.10"/>
        <vers num="2.9.12"/>
        <vers num="2.9.13"/>
        <vers num="2.9.14"/>
        <vers num="2.9.15"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.6"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.10.10"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
        <vers num="2.11.4"/>
        <vers num="2.11.5"/>
        <vers num="2.11.6"/>
        <vers num="2.11.7"/>
        <vers num="2.11.8"/>
        <vers num="2.11.9"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10141" seq="2017-10141" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology as well as unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99785" adv="1">99785</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="outside_in_technology" vendor="oracle">
        <vers num="8.5.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10142" seq="2017-10142" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Mobile Apps). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99710" adv="1">99710</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10143" seq="2017-10143" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99633" adv="1">99633</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="customer_relationship_management_technical_foundation" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10144" seq="2017-10144" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Applications Manager. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99685" adv="1">99685</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="applications_manager" vendor="oracle">
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10145" seq="2017-10145" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java Advanced Management Console. While the vulnerability is in Java Advanced Management Console, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data as well as unauthorized read access to a subset of Java Advanced Management Console accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java Advanced Management Console. CVSS 3.0 Base Score 7.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99804" adv="1">99804</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10146" seq="2017-10146" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99732" adv="1">99732</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-040-anonymous-directory-traversal-vulnerability-double-encode-peoplesoft/">https://erpscan.io/advisories/erpscan-17-040-anonymous-directory-traversal-vulnerability-double-encode-peoplesoft/</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10147" seq="2017-10147" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.0 Base Score 8.6 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). NOTE: the previous information is from the July 2017 CPU. Oracle has not commented on third-party claims that this issue exists in the migrate functionality in the WebLogic/cluster/singleton/ServerMigrationCoordinator class and allows remote attackers to shutdown the server via a crafted T3 request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99651" adv="1">99651</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-041-unauthorized-container-shutdown-servermigrationcoordinator/">https://erpscan.io/advisories/erpscan-17-041-unauthorized-container-shutdown-servermigrationcoordinator/</ref>
      <ref source="MISC" url="https://github.com/vah13/OracleCVE/tree/master/CVE-2017-10147">https://github.com/vah13/OracleCVE/tree/master/CVE-2017-10147</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10148" seq="2017-10148" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N). NOTE: the previous information is from the July 2017 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to inject special data into log files via a crafted T3 request.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99652" adv="1">99652</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-042-anonymous-log-injection-in-fscm/">https://erpscan.io/advisories/erpscan-17-042-anonymous-log-injection-in-fscm/</ref>
      <ref source="MISC" url="https://github.com/vah13/OracleCVE/tree/master/CVE-2017-10148">https://github.com/vah13/OracleCVE/tree/master/CVE-2017-10148</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10149" seq="2017-10149" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99780" adv="1">99780</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_unifier" vendor="oracle">
        <vers num="9.13"/>
        <vers num="9.14"/>
        <vers num="10.1"/>
        <vers num="10.2"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10150" seq="2017-10150" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99800" adv="1">99800</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_unifier" vendor="oracle">
        <vers num="9.13"/>
        <vers num="9.14"/>
        <vers num="10.1"/>
        <vers num="10.2"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10151" seq="2017-10151" published="2017-10-30" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101619" adv="1">101619</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039690" adv="1">1039690</ref>
    </refs>
    <vuln_soft>
      <prod name="identity_manager" vendor="oracle">
        <vers num="11.1.1.7"/>
        <vers num="11.1.1.9"/>
        <vers num="11.1.2.1.0"/>
        <vers num="11.1.2.2.0"/>
        <vers num="11.1.2.3"/>
        <vers num="12.2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10152" seq="2017-10152" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101351" adv="1">101351</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039608" adv="1">1039608</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10153" seq="2017-10153" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Gson)). Supported versions that are affected are 7.0, 7.1 and 7.2. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications WebRTC Session Controller. While the vulnerability is in Oracle Communications WebRTC Session Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications WebRTC Session Controller. CVSS 3.0 Base Score 6.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101432" adv="1">101432</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039590" adv="1">1039590</ref>
    </refs>
    <vuln_soft>
      <prod name="communications_webrtc_session_controller" vendor="oracle">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10154" seq="2017-10154" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101386" adv="1">101386</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039607" adv="1">1039607</ref>
    </refs>
    <vuln_soft>
      <prod name="access_manager" vendor="oracle">
        <vers num="11.1.2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10155" seq="2017-10155" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101402" adv="1">101402</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10156" seq="2017-10156" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99682" adv="1">99682</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10157" seq="2017-10157" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher accessible data as well as unauthorized read access to a subset of BI Publisher accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99694" adv="1">99694</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence_publisher" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10158" seq="2017-10158" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Core). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101469" adv="1">101469</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10159" seq="2017-10159" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Applications (subcomponent: Portal, CMP). Supported versions that are affected are 11.5 and 12.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Policy Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101425" adv="1">101425</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039590" adv="1">1039590</ref>
    </refs>
    <vuln_soft>
      <prod name="communications_policy_management" vendor="oracle">
        <vers num="11.5"/>
        <vers num="12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10160" seq="2017-10160" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99793" adv="1">99793</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038946" adv="1">1038946</ref>
    </refs>
    <vuln_soft>
      <prod name="primavera_p6_enterprise_project_portfolio_management" vendor="oracle">
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10161" seq="2017-10161" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Engineering Data Management accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101395" adv="1">101395</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_engineering_data_management" vendor="oracle">
        <vers num="6.1.3.0"/>
        <vers num="6.2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10162" seq="2017-10162" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel Core - Server Framework accessible data as well as unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101416" adv="1">101416</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_core-server_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10163" seq="2017-10163" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. Note: Please refer to Doc ID &lt;a href="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=2310021.1">My Oracle Support Note 2310021.1 for instructions on how to address this issue. CVSS 3.0 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101357" adv="1">101357</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="business_intelligence" vendor="oracle">
        <vers num="11.1.1.7.0" edition=":~~enterprise~~~"/>
        <vers num="11.1.1.9.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.1.0" edition=":~~enterprise~~~"/>
        <vers num="12.2.1.2.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10164" seq="2017-10164" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101479" adv="1">101479</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_fin_staffing_front_office" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10165" seq="2017-10165" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101424" adv="1">101424</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10166" seq="2017-10166" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Security Service accessible data. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101412" adv="1">101412</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="security_service" vendor="oracle">
        <vers num="12.1.3.0.0"/>
      </prod>
      <prod name="security_service_fmw" vendor="oracle">
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10167" seq="2017-10167" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101433" adv="1">101433</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10168" seq="2017-10168" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Windows). The supported version that is affected is 1.1. Difficult to exploit vulnerability allows physical access to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality Hotel Mobile accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hospitality Hotel Mobile. CVSS 3.0 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99841" adv="1">99841</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10169" seq="2017-10169" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality 9700 component of Oracle Hospitality Applications (subcomponent: Operation Security). The supported version that is affected is 4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality 9700 executes to compromise Oracle Hospitality 9700. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality 9700 accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99823" adv="1">99823</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_9700" vendor="oracle">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10170" seq="2017-10170" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Field Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99647" adv="1">99647</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="field_service" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10171" seq="2017-10171" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Home Page). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99655" adv="1">99655</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="marketing" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10172" seq="2017-10172" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Framework). Supported versions that are affected are 5.0, 5.1, 5.2, 5.3, 6.0, 6.1, 15.0 and 15.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Open Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Open Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Open Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Retail Open Commerce Platform accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99737" adv="1">99737</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038944" adv="1">1038944</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_open_commerce_platform_cloud_service" vendor="oracle">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10173" seq="2017-10173" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Website). Supported versions that are affected are 5.0, 5.1, 5.2, 5.3, 6.0, 6.1, 15.0 and 15.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Open Commerce Platform. While the vulnerability is in Oracle Retail Open Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Open Commerce Platform accessible data. CVSS 3.0 Base Score 5.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99745" adv="1">99745</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038944" adv="1">1038944</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_open_commerce_platform_cloud_service" vendor="oracle">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10174" seq="2017-10174" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: Service Request). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99664" adv="1">99664</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="isupport" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10175" seq="2017-10175" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: Profiles). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99717" adv="1">99717</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="isupport" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10176" seq="2017-10176" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99788" adv="1">99788</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10177" seq="2017-10177" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Flexfields). The supported version that is affected is 12.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99672" adv="1">99672</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="application_object_library" vendor="oracle">
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10178" seq="2017-10178" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99644" adv="1">99644</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038939" adv="1">1038939</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10179" seq="2017-10179" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). Supported versions that are affected are AMP 12.1.0.4.0 and AMP 13.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Management Pack for Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Management Pack for Oracle E-Business Suite accessible data as well as unauthorized read access to a subset of Application Management Pack for Oracle E-Business Suite accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99693" adv="1">99693</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="application_management_amp" vendor="oracle">
        <vers num="12.1.0.4.0" edition=":~~~e-business_suite~~"/>
        <vers num="13.1.1.1.0" edition=":~~~e-business_suite~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10180" seq="2017-10180" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: CMRO). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99630" adv="1">99630</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="customer_relationship_management_technical_foundation" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10181" seq="2017-10181" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Forgot Password). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Direct Banking as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Direct Banking accessible data and unauthorized read access to a subset of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99648" adv="1">99648</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038934" adv="1">1038934</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_direct_banking" vendor="oracle">
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10182" seq="2017-10182" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Export Functionality). Supported versions that are affected are 5.4.0.x, 5.4.1.x and 5.4.3.x. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99725" adv="1">99725</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_opera_5_property_services" vendor="oracle">
        <vers num="5.4.0"/>
        <vers num="5.4.1"/>
        <vers num="5.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10183" seq="2017-10183" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Xstore Point of Service component of Oracle Retail Applications (subcomponent: Point of Sale). Supported versions that are affected are 6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x and 16.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. While the vulnerability is in Oracle Retail Xstore Point of Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Point of Service accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Point of Service. CVSS 3.0 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99727" adv="1">99727</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038944" adv="1">1038944</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_xstore_point_of_service" vendor="oracle">
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.5.4"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10184" seq="2017-10184" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Field Service accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99708" adv="1">99708</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="field_service" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10185" seq="2017-10185" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99636" adv="1">99636</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="customer_relationship_management_technical_foundation" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10186" seq="2017-10186" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User and Company Profile). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99715" adv="1">99715</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10187" seq="2017-10187" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99711" adv="1">99711</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10188" seq="2017-10188" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Android). The supported version that is affected is 1.01. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Hospitality Hotel Mobile executes to compromise Hospitality Hotel Mobile. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality Hotel Mobile accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99817" adv="1">99817</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10189" seq="2017-10189" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Hospitality Suite8 executes to compromise Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality Suite8 accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99821" adv="1">99821</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10190" seq="2017-10190" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java VM executes to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101335" adv="1">101335</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039591" adv="1">1039591</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="oracle">
        <vers num="11.2.0.4"/>
        <vers num="12.1.0.2"/>
        <vers num="12.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10191" seq="2017-10191" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Web Analytics component of Oracle E-Business Suite (subcomponent: Common Libraries). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Analytics accessible data as well as unauthorized update, insert or delete access to some of Oracle Web Analytics accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99658" adv="1">99658</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="web_analytics" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10192" seq="2017-10192" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99713" adv="1">99713</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10193" seq="2017-10193" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99854" adv="1">99854</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10194" seq="2017-10194" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101445" adv="1">101445</ref>
    </refs>
    <vuln_soft>
      <prod name="integrated_lights_out_manager_firmware" vendor="oracle">
        <vers num="3.2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10195" seq="2017-10195" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). The supported version that is affected is 2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99791" adv="1">99791</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10196" seq="2017-10196" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology as well as unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99794" adv="1">99794</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038940" adv="1">1038940</ref>
    </refs>
    <vuln_soft>
      <prod name="outside_in_technology" vendor="oracle">
        <vers num="8.5.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10197" seq="2017-10197" published="2017-10-19" modified="2017-10-27" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: Folios). The supported version that is affected is 5.4.2.x through 5.5.1.x. Easily exploitable vulnerability allows physical access to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101459" adv="1">101459</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_opera_5_property_services" vendor="oracle">
        <vers num="5.4.2"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10198" seq="2017-10198" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3919">DSA-3919</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99818" adv="1">99818</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="CONFIRM" url="https://cert.vde.com/en-us/advisories/vde-2017-002">https://cert.vde.com/en-us/advisories/vde-2017-002</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10199" seq="2017-10199" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iLearning, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iLearning accessible data as well as unauthorized update, insert or delete access to some of Oracle iLearning accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99637" adv="1">99637</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038949" adv="1">1038949</ref>
    </refs>
    <vuln_soft>
      <prod name="ilearning" vendor="oracle">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10200" seq="2017-10200" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality e7 component of Oracle Hospitality Applications (subcomponent: Other). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality e7 executes to compromise Oracle Hospitality e7. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality e7 accessible data as well as unauthorized read access to a subset of Oracle Hospitality e7 accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99858" adv="1">99858</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_e7" vendor="oracle">
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10201" seq="2017-10201" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality e7 component of Oracle Hospitality Applications (subcomponent: Other). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality e7 executes to compromise Oracle Hospitality e7. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality e7 accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99834" adv="1">99834</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_e7" vendor="oracle">
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10202" seq="2017-10202" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of OJVM. Note: This score is for Windows platforms. On non-Windows platforms Scope is Unchanged, giving a CVSS Base Score of 8.8. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99865" adv="1">99865</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038923" adv="1">1038923</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="oracle">
        <vers num="11.2.0.4"/>
        <vers num="12.1.0.2"/>
        <vers num="12.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10203" seq="2017-10203" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101324" adv="1">101324</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql_connector/net" vendor="oracle">
        <vers num="6.9.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10204" seq="2017-10204" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/152617/VirtualBox-COM-RPC-Interface-Code-Injection-Privilege-Escalation.html">http://packetstormsecurity.com/files/152617/VirtualBox-COM-RPC-Interface-Code-Injection-Privilege-Escalation.html</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99631" adv="1">99631</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42425/" adv="1">42425</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10205" seq="2017-10205" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Enterprise Management Console). The supported version that is affected is 2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99787" adv="1">99787</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10206" seq="2017-10206" published="2017-08-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Engagement). The supported version that is affected is 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99641" adv="1">99641</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10207" seq="2017-10207" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Utilities). The supported version that is affected is 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99718" adv="1">99718</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10208" seq="2017-10208" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality e7 component of Oracle Hospitality Applications (subcomponent: Other). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via SMTP to compromise Oracle Hospitality e7. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality e7 accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99795" adv="1">99795</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_e7" vendor="oracle">
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10209" seq="2017-10209" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99709" adv="1">99709</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10210" seq="2017-10210" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99640" adv="1">99640</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10211" seq="2017-10211" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hospitality Suite8 accessible data as well as unauthorized read access to a subset of Hospitality Suite8 accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99671" adv="1">99671</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10212" seq="2017-10212" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality Suite8 accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99656" adv="1">99656</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10213" seq="2017-10213" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Hospitality Suite8 executes to compromise Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99863" adv="1">99863</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10214" seq="2017-10214" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Xstore Point of Service component of Oracle Retail Applications (subcomponent: Xstore Office). Supported versions that are affected are 6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x and 16.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Xstore Point of Service accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99733" adv="1">99733</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038944" adv="1">1038944</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_xstore_point_of_service" vendor="oracle">
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.5.4"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10215" seq="2017-10215" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_DEFN_CATG). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99749" adv="1">99749</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10216" seq="2017-10216" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Property Interfaces. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality Property Interfaces accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99654" adv="1">99654</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8_property_interfaces" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10217" seq="2017-10217" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99776" adv="1">99776</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0.0"/>
        <vers num="4.2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10218" seq="2017-10218" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99781" adv="1">99781</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0.0"/>
        <vers num="4.2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10219" seq="2017-10219" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99831" adv="1">99831</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0.0"/>
        <vers num="4.2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10220" seq="2017-10220" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Hospitality Property Interfaces executes to compromise Hospitality Property Interfaces. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hospitality Property Interfaces accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99861" adv="1">99861</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8_property_interfaces" vendor="oracle">
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10221" seq="2017-10221" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Hospitality Applications (subcomponent: OPS Operations). The supported version that is affected is 5.5. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality RES 3700 executes to compromise Oracle Hospitality RES 3700. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality RES 3700, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality RES 3700 accessible data as well as unauthorized read access to a subset of Oracle Hospitality RES 3700 accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality RES 3700. CVSS 3.0 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99837" adv="1">99837</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_res_3700" vendor="oracle">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10222" seq="2017-10222" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Materials Control component of Oracle Hospitality Applications (subcomponent: Production Tool). Supported versions that are affected are 8.31.4 and 8.32.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Materials Control. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Materials Control accessible data as well as unauthorized read access to a subset of Oracle Hospitality Materials Control accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99701" adv="1">99701</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_materials_control" vendor="oracle">
        <vers num="8.31.4"/>
        <vers num="8.32.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10223" seq="2017-10223" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Materials Control component of Oracle Hospitality Applications (subcomponent: Purchasing). Supported versions that are affected are 8.31.4 and 8.32.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Materials Control. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Materials Control accessible data as well as unauthorized read access to a subset of Oracle Hospitality Materials Control accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99704" adv="1">99704</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_materials_control" vendor="oracle">
        <vers num="8.31.4"/>
        <vers num="8.32.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10224" seq="2017-10224" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Inventory Management. While the vulnerability is in Oracle Hospitality Inventory Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Inventory Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Inventory Management accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99665" adv="1">99665</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_inventory_management" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10225" seq="2017-10225" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Hospitality Applications (subcomponent: OPS Operations). The supported version that is affected is 5.5. Difficult to exploit vulnerability allows physical access to compromise Oracle Hospitality RES 3700. While the vulnerability is in Oracle Hospitality RES 3700, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality RES 3700 accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality RES 3700 accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality RES 3700. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99815" adv="1">99815</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_res_3700" vendor="oracle">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10226" seq="2017-10226" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Fleet Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Fleet Management accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99646" adv="1">99646</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_fleet_management" vendor="oracle">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10227" seq="2017-10227" published="2017-10-19" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101337" adv="1">101337</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265" adv="1">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442" adv="1">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/" adv="1">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0" edition=":~~enterprise~~~"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.18"/>
        <vers num="5.6.19"/>
        <vers num="5.6.20"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.24"/>
        <vers num="5.6.25"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0" edition=":~~community~~~"/>
        <vers num="5.7.0" edition=":~~enterprise~~~"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10228" seq="2017-10228" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: Module). The supported version that is affected is 8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management System. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Shipboard Property Management System accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Shipboard Property Management System accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99695" adv="1">99695</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_shipboard_property_management_system" vendor="oracle">
        <vers num="8.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10229" seq="2017-10229" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Materials Management component of Oracle Hospitality Applications (subcomponent: Event Viewer). The supported version that is affected is 7.30.562. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Materials Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Materials Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Materials Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99691" adv="1">99691</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_materials_management" vendor="oracle">
        <vers num="7.30.562"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10230" seq="2017-10230" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Dining Room Management component of Oracle Hospitality Applications (subcomponent: SilverWhere). The supported version that is affected is 8.0.75. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Dining Room Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Dining Room Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Dining Room Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99688" adv="1">99688</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_dining_room_management" vendor="oracle">
        <vers num="8.0.75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10231" seq="2017-10231" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise AffairWhere component of Oracle Hospitality Applications (subcomponent: AWExport). The supported version that is affected is 2.2.05.062. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise AffairWhere executes to compromise Oracle Hospitality Cruise AffairWhere. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise AffairWhere accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99830" adv="1">99830</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_affairwhere" vendor="oracle">
        <vers num="2.2.05.062"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10232" seq="2017-10232" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hospitality WebSuite8 Cloud Service. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038941" adv="1">1038941</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_websuite8_cloud_service" vendor="oracle">
        <vers num="8.9.6"/>
        <vers num="8.10.0"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10233" seq="2017-10233" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99642" adv="1">99642</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10234" seq="2017-10234" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Solaris Cluster. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99859" adv="1">99859</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038937" adv="1">1038937</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris_cluster" vendor="oracle">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10235" seq="2017-10235" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99705" adv="1">99705</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10236" seq="2017-10236" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99645" adv="1">99645</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10237" seq="2017-10237" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99667" adv="1">99667</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10238" seq="2017-10238" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99668" adv="1">99668</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10239" seq="2017-10239" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99681" adv="1">99681</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10240" seq="2017-10240" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99683" adv="1">99683</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10241" seq="2017-10241" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99687" adv="1">99687</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10242" seq="2017-10242" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99689" adv="1">99689</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038929" adv="1">1038929</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10243" seq="2017-10243" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3954">DSA-3954</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99827" adv="1">99827</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038931" adv="1">1038931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1789">RHSA-2017:1789</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1790">RHSA-2017:1790</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1791">RHSA-2017:1791</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1792">RHSA-2017:1792</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2424">RHSA-2017:2424</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2469">RHSA-2017:2469</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2481">RHSA-2017:2481</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2530">RHSA-2017:2530</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-22">GLSA-201709-22</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20170720-0001/">https://security.netapp.com/advisory/ntap-20170720-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_151"/>
        <vers num="1.7.0" edition="update_141"/>
        <vers num="1.8.0" edition="update_131"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10244" seq="2017-10244" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99702" adv="1">99702</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="application_object_library" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10245" seq="2017-10245" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99690" adv="1">99690</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
    </refs>
    <vuln_soft>
      <prod name="general_ledger" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10246" seq="2017-10246" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99625" adv="1">99625</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038926" adv="1">1038926</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42340/" adv="1">42340</ref>
    </refs>
    <vuln_soft>
      <prod name="application_object_library" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10247" seq="2017-10247" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99761" adv="1">99761</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10248" seq="2017-10248" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99754" adv="1">99754</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10249" seq="2017-10249" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99764" adv="1">99764</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10250" seq="2017-10250" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Tuxedo). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99824" adv="1">99824</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10251" seq="2017-10251" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Test Framework). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99822" adv="1">99822</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10252" seq="2017-10252" published="2017-08-08" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Updates Change Assistant). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99828" adv="1">99828</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10253" seq="2017-10253" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Pivot Grid). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99773" adv="1">99773</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10254" seq="2017-10254" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99814" adv="1">99814</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_staffing_front_office" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10255" seq="2017-10255" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99755" adv="1">99755</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10256" seq="2017-10256" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_HIER_TOP). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99758" adv="1">99758</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10257" seq="2017-10257" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Browse Folder Hierarchy). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99747" adv="1">99747</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10258" seq="2017-10258" published="2017-08-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Add New Image). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99739" adv="1">99739</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038932" adv="1">1038932</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10259" seq="2017-10259" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101331" adv="1">101331</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039607" adv="1">1039607</ref>
    </refs>
    <vuln_soft>
      <prod name="coreid_access" vendor="oracle">
        <vers num="11.1.2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10260" seq="2017-10260" published="2017-10-19" modified="2017-10-24" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101426" adv="1">101426</ref>
    </refs>
    <vuln_soft>
      <prod name="integrated_lights_out_manager_firmware" vendor="oracle">
        <vers num="3.2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10261" seq="2017-10261" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to compromise XML Database. While the vulnerability is in XML Database, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all XML Database accessible data. Note: This score is for Windows platform version 11.2.0.4 of Database. For Windows platform version 12.1.0.2 and Linux, the score is 5.5 with scope Unchanged. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101344" adv="1">101344</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039591" adv="1">1039591</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="oracle">
        <vers num="11.2.0.4"/>
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10262" seq="2017-10262" published="2018-01-17" modified="2018-01-25" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102562" adv="1">102562</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040211" adv="1">1040211</ref>
    </refs>
    <vuln_soft>
      <prod name="access_manager" vendor="oracle">
        <vers num="11.1.2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10263" seq="2017-10263" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel UI Framework accessible data as well as unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101421" adv="1">101421</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_ui_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10264" seq="2017-10264" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel UI Framework. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101411" adv="1">101411</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_ui_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10265" seq="2017-10265" published="2017-10-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Integrated Lights Out Manager (ILOM) accessible data as well as unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101431" adv="1">101431</ref>
    </refs>
    <vuln_soft>
      <prod name="integrated_lights_out_manager_firmware" vendor="oracle">
        <vers num="3.2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10266" seq="2017-10266" published="2017-11-14" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Tuxedo accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101852" adv="1">101852</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="oracle">
        <vers num="11.1.1"/>
        <vers num="12.1.1"/>
        <vers num="12.1.3"/>
        <vers num="12.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10267" seq="2017-10267" published="2017-11-14" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101875" adv="1">101875</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="oracle">
        <vers num="11.1.1"/>
        <vers num="12.1.1"/>
        <vers num="12.1.3"/>
        <vers num="12.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10268" seq="2017-10268" published="2017-10-19" modified="2019-05-21" severity="Low" CVSS_version="2.0" CVSS_score="1.5" CVSS_base_score="1.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="2.7" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4002">DSA-4002</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101390" adv="1">101390</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0279">RHSA-2018:0279</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0574">RHSA-2018:0574</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2439">RHSA-2018:2439</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2729">RHSA-2018:2729</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:1258">RHSA-2019:1258</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/06/msg00015.html">[debian-lts-announce] 20180629 [SECURITY] [DLA 1407-1] mariadb-10.0 security update</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4341">DSA-4341</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.32"/>
        <vers num="5.5.33"/>
        <vers num="5.5.34"/>
        <vers num="5.5.35"/>
        <vers num="5.5.36"/>
        <vers num="5.5.37"/>
        <vers num="5.5.40"/>
        <vers num="5.5.41"/>
        <vers num="5.5.42"/>
        <vers num="5.5.45"/>
        <vers num="5.5.46"/>
        <vers num="5.5.47"/>
        <vers num="5.5.48"/>
        <vers num="5.5.49"/>
        <vers num="5.5.50"/>
        <vers num="5.5.51"/>
        <vers num="5.5.52"/>
        <vers num="5.5.53"/>
        <vers num="5.5.56"/>
        <vers num="5.5.57"/>
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10269" seq="2017-10269" published="2017-11-14" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo. While the vulnerability is in Oracle Tuxedo, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Tuxedo accessible data as well as unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101841" adv="1">101841</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="oracle">
        <vers num="11.1.1"/>
        <vers num="12.1.1"/>
        <vers num="12.1.3"/>
        <vers num="12.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10270" seq="2017-10270" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101313" adv="1">101313</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="identity_manager_connector" vendor="oracle">
        <vers num="9.1.1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10271" seq="2017-10271" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101304" adv="1">101304</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039608" adv="1">1039608</ref>
      <ref source="MISC" url="https://github.com/c0mmand3rOpSec/CVE-2017-10271">https://github.com/c0mmand3rOpSec/CVE-2017-10271</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43458/" adv="1">43458</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43924/">43924</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10272" seq="2017-10272" published="2017-11-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via Jolt to compromise Oracle Tuxedo. While the vulnerability is in Oracle Tuxedo, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Tuxedo accessible data as well as unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101871" adv="1">101871</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="oracle">
        <vers num="11.1.1"/>
        <vers num="12.1.1"/>
        <vers num="12.1.3"/>
        <vers num="12.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10273" seq="2017-10273" published="2018-01-17" modified="2018-01-25" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as unauthorized read access to a subset of Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.0 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102569" adv="1">102569</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040207" adv="1">1040207</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43848/" adv="1">43848</ref>
    </refs>
    <vuln_soft>
      <prod name="jdeveloper" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.7.1"/>
        <vers num="11.1.1.9.0"/>
        <vers num="11.1.2.4.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10274" seq="2017-10274" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101333" adv="1">101333</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK">https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10275" seq="2017-10275" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: Filesystem). The supported version that is affected is AK 2013. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Sun ZFS Storage Appliance Kit (AK) executes to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101437" adv="1">101437</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris_ak" vendor="oracle">
        <vers num="2013"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10276" seq="2017-10276" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101441" adv="1">101441</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10277" seq="2017-10277" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101439" adv="1">101439</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql_connector/net" vendor="oracle">
        <vers num="6.9.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10278" seq="2017-10278" published="2017-11-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data as well as unauthorized update, insert or delete access to some of Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101870" adv="1">101870</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="oracle">
        <vers num="11.1.1"/>
        <vers num="12.1.1"/>
        <vers num="12.1.3"/>
        <vers num="12.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10279" seq="2017-10279" published="2017-10-19" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101316" adv="1">101316</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265" adv="1">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442" adv="1">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/" adv="1">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0" edition=":~~enterprise~~~"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.18"/>
        <vers num="5.6.19"/>
        <vers num="5.6.20"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.24"/>
        <vers num="5.6.25"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.7.0" edition=":~~community~~~"/>
        <vers num="5.7.0" edition=":~~enterprise~~~"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10280" seq="2017-10280" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Test Framework). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101468" adv="1">101468</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10281" seq="2017-10281" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101378" adv="1">101378</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10282" seq="2017-10282" published="2018-01-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Core RDBMS. CVSS 3.0 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102534" adv="1">102534</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040196" adv="1">1040196</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="12.1.0.2"/>
        <vers num="12.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10283" seq="2017-10283" published="2017-10-19" modified="2017-12-13" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101420" adv="1">101420</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10284" seq="2017-10284" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Stored Procedure). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101385" adv="1">101385</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10285" seq="2017-10285" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101319" adv="1">101319</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK">https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10286" seq="2017-10286" published="2017-10-19" modified="2018-03-22" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101397" adv="1">101397</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0279">RHSA-2018:0279</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0574">RHSA-2018:0574</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10287" seq="2017-10287" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101480" adv="1">101480</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_scm_strategic_sourcing" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10292" seq="2017-10292" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="1.7" CVSS_base_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to the infrastructure where RDBMS Security executes to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of RDBMS Security accessible data. CVSS 3.0 Base Score 2.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101350" adv="1">101350</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039591" adv="1">1039591</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="oracle">
        <vers num="11.2.0.4"/>
        <vers num="12.1.0.2"/>
        <vers num="12.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10293" seq="2017-10293" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101338" adv="1">101338</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10294" seq="2017-10294" published="2017-10-19" modified="2017-12-13" severity="Low" CVSS_version="2.0" CVSS_score="1.7" CVSS_base_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101444" adv="1">101444</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10295" seq="2017-10295" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE, Java SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.0 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101384" adv="1">101384</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10296" seq="2017-10296" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101373" adv="1">101373</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10299" seq="2017-10299" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101387" adv="1">101387</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10300" seq="2017-10300" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Siebel Business Service Issues). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Desktop accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101400" adv="1">101400</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_customer_relationship_management_desktop" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10301" seq="2017-10301" published="2018-01-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102599" adv="1">102599</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040204" adv="1">1040204</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="9.1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10302" seq="2017-10302" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101419" adv="1">101419</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_ui_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10303" seq="2017-10303" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Interaction Center Intelligence component of Oracle E-Business Suite (subcomponent: Setup). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Interaction Center Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Interaction Center Intelligence, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Interaction Center Intelligence accessible data as well as unauthorized update, insert or delete access to some of Oracle Interaction Center Intelligence accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101327" adv="1">101327</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="interaction_center_intelligence" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10304" seq="2017-10304" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101477" adv="1">101477</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_human_capital_management_human_resources" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10306" seq="2017-10306" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM accessible data. CVSS 3.0 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101478" adv="1">101478</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_human_capital_management_human_resources" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10308" seq="2017-10308" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Performance). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows physical access to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 3.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101379" adv="1">101379</ref>
    </refs>
    <vuln_soft>
      <prod name="agile_product_lifecycle_management_framework" vendor="oracle">
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10309" seq="2017-10309" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101328" adv="1">101328</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43103/">43103</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10310" seq="2017-10310" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101302" adv="1">101302</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039595" adv="1">1039595</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperion_financial_reporting" vendor="oracle">
        <vers num="11.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10311" seq="2017-10311" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101446" adv="1">101446</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10312" seq="2017-10312" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion BI+ accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion BI+ accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101309" adv="1">101309</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039595" adv="1">1039595</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperion_bi+" vendor="oracle">
        <vers num="11.1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10313" seq="2017-10313" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Group Replication GCS). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101448" adv="1">101448</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10314" seq="2017-10314" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101314" adv="1">101314</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10315" seq="2017-10315" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101417" adv="1">101417</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_ui_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10316" seq="2017-10316" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101346" adv="1">101346</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10317" seq="2017-10317" published="2017-10-19" modified="2017-10-24" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101454" adv="1">101454</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10318" seq="2017-10318" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101343" adv="1">101343</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10319" seq="2017-10319" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101312" adv="1">101312</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10320" seq="2017-10320" published="2017-10-19" modified="2017-12-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101410" adv="1">101410</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10321" seq="2017-10321" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Core RDBMS. Note: This score is for Windows platform version 11.2.0.4 of Database. For Windows platform version 12.1.0.2 and Linux, the score is 7.8 with scope Unchanged. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101329" adv="1">101329</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039591" adv="1">1039591</ref>
    </refs>
    <vuln_soft>
      <prod name="database" vendor="oracle">
        <vers num="11.2.0.4"/>
        <vers num="12.1.0.2"/>
        <vers num="12.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10322" seq="2017-10322" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101401" adv="1">101401</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="common_applications_calendar" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10323" seq="2017-10323" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Web Applications Desktop Integrator component of Oracle E-Business Suite (subcomponent: Application Service). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data as well as unauthorized update, insert or delete access to some of Oracle Web Applications Desktop Integrator accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101367" adv="1">101367</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="web_applications_desktop_integrator" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10324" seq="2017-10324" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Applications Technology Stack component of Oracle E-Business Suite (subcomponent: Oracle Forms). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Applications Technology Stack accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101393" adv="1">101393</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="e-business_suite_technology_stack" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10325" seq="2017-10325" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications Calendar, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101311" adv="1">101311</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="common_applications_calendar" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10326" seq="2017-10326" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications Calendar, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101325" adv="1">101325</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="common_applications_calendar" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10327" seq="2017-10327" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101472" adv="1">101472</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10328" seq="2017-10328" published="2017-10-19" modified="2017-10-24" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101372" adv="1">101372</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="application_object_library" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10329" seq="2017-10329" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Global Order Promising component of Oracle E-Business Suite (subcomponent: Reschedule Sales Orders). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Order Promising. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Order Promising accessible data as well as unauthorized access to critical data or complete access to all Oracle Global Order Promising accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101300" adv="1">101300</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="global_order_promising" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10330" seq="2017-10330" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Gantt Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101298" adv="1">101298</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="common_applications" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10331" seq="2017-10331" published="2017-10-19" modified="2017-10-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101391" adv="1">101391</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="application_object_library" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10332" seq="2017-10332" published="2017-10-19" modified="2017-10-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Universal Work Queue component of Oracle E-Business Suite (subcomponent: Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101376" adv="1">101376</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592" adv="1">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="universal_work_queue" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10333" seq="2017-10333" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. While the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as unauthorized read access to a subset of Siebel UI Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel UI Framework. CVSS 3.0 Base Score 7.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101423" adv="1">101423</ref>
    </refs>
    <vuln_soft>
      <prod name="siebel_ui_framework" vendor="oracle">
        <vers num="16.0"/>
        <vers num="17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10334" seq="2017-10334" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039608" adv="1">1039608</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10335" seq="2017-10335" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Elastic Search). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101458" adv="1">101458</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10336" seq="2017-10336" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101392" adv="1">101392</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039608" adv="1">1039608</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10337" seq="2017-10337" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Suite8. CVSS 3.0 Base Score 5.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101326" adv="1">101326</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10338" seq="2017-10338" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101464" adv="1">101464</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10339" seq="2017-10339" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101352" adv="1">101352</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10340" seq="2017-10340" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). Supported versions that are affected are 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101356" adv="1">101356</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10341" seq="2017-10341" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101451" adv="1">101451</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10342" seq="2017-10342" published="2017-10-19" modified="2017-11-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java Advanced Management Console. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101428" adv="1">101428</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10343" seq="2017-10343" published="2017-10-19" modified="2017-10-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). Supported versions that are affected are 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101409" adv="1">101409</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10344" seq="2017-10344" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). Supported versions that are affected are 2.8 and 2.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101414" adv="1">101414</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10345" seq="2017-10345" published="2017-10-19" modified="2018-02-03" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101396" adv="1">101396</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10346" seq="2017-10346" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101315" adv="1">101315</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK">https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10347" seq="2017-10347" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101382" adv="1">101382</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10348" seq="2017-10348" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101354" adv="1">101354</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10349" seq="2017-10349" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101348" adv="1">101348</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10350" seq="2017-10350" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101341" adv="1">101341</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10351" seq="2017-10351" published="2017-10-19" modified="2017-10-23" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 6.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101463" adv="1">101463</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10352" seq="2017-10352" published="2017-10-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/102442">102442</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039608" adv="1">1039608</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="oracle">
        <vers num="10.3.6.0.0"/>
        <vers num="12.1.3.0.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
        <vers num="12.2.1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10353" seq="2017-10353" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Hotel Mobile accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Hotel Mobile. CVSS 3.0 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101305" adv="1">101305</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_hotel_mobile" vendor="oracle">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10354" seq="2017-10354" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal). The supported version that is affected is 9.1.00. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101465" adv="1">101465</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_prtl_interaction_hub" vendor="oracle">
        <vers num="9.1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10355" seq="2017-10355" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101369" adv="1">101369</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jrockit" vendor="oracle">
        <vers num="r28.3.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10356" seq="2017-10356" published="2017-10-19" modified="2018-02-03" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 6.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101413" adv="1">101413</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10357" seq="2017-10357" published="2017-10-19" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101355" adv="1">101355</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10358" seq="2017-10358" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Workspace). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101306" adv="1">101306</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039595" adv="1">1039595</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperion_financial_reporting" vendor="oracle">
        <vers num="11.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10359" seq="2017-10359" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion BI+ accessible data as well as unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101317" adv="1">101317</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039595" adv="1">1039595</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperion_bi+" vendor="oracle">
        <vers num="11.1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10360" seq="2017-10360" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101322" adv="1">101322</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602" adv="1">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="webcenter_content" vendor="oracle">
        <vers num="11.1.1.9.0"/>
        <vers num="12.2.1.1.0"/>
        <vers num="12.2.1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10361" seq="2017-10361" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC DRS). The supported version that is affected is 8.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management System. While the vulnerability is in Oracle Hospitality Cruise Shipboard Property Management System, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Cruise Shipboard Property Management System accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Cruise Shipboard Property Management System. CVSS 3.0 Base Score 6.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101418" adv="1">101418</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_shipboard_property_management_system" vendor="oracle">
        <vers num="8.0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10362" seq="2017-10362" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Sawbridge). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101467" adv="1">101467</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10363" seq="2017-10363" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security). Supported versions that are affected are 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. Note: Contact Support for fixes. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101297" adv="1">101297</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039594" adv="1">1039594</ref>
    </refs>
    <vuln_soft>
      <prod name="flexcube_universal_banking" vendor="oracle">
        <vers num="11.3"/>
        <vers num="11.4.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1.0"/>
        <vers num="12.2.0"/>
        <vers num="12.3.0"/>
        <vers num="12.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10364" seq="2017-10364" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Updates Environment Mgmt). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101466" adv="1">101466</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10365" seq="2017-10365" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.0 Base Score 3.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101429" adv="1">101429</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.7.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10366" seq="2017-10366" published="2017-10-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101455" adv="1">101455</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598" adv="1">1039598</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43594/">43594</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10367" seq="2017-10367" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Engagement). Supported versions that are affected are 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101422">101422</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10368" seq="2017-10368" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise SCM eProcurement component of Oracle PeopleSoft Products (subcomponent: Manage Requisition Status). Supported versions that are affected are 9.1.00 and 9.2.00. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise SCM eProcurement, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101476">101476</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_scm_eprocurement" vendor="oracle">
        <vers num="9.1.00"/>
        <vers num="9.2.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10369" seq="2017-10369" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Virtual Directory component of Oracle Fusion Middleware (subcomponent: Virtual Directory Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Virtual Directory. Successful attacks of this vulnerability can result in takeover of Oracle Virtual Directory. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101301">101301</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039602">1039602</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_directory" vendor="oracle">
        <vers num="11.1.1.7.0"/>
        <vers num="11.1.1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10370" seq="2017-10370" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Guest Access, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Guest Access accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 6.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101430">101430</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10372" seq="2017-10372" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. While the vulnerability is in Oracle Hospitality Guest Access, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Guest Access accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Guest Access. CVSS 3.0 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101427">101427</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10373" seq="2017-10373" published="2017-10-19" modified="2017-10-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Health Center). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101460">101460</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10375" seq="2017-10375" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Guest Access accessible data as well as unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101434">101434</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10378" seq="2017-10378" published="2017-10-19" modified="2019-05-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4002">DSA-4002</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101375" adv="1">101375</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0279">RHSA-2018:0279</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0574">RHSA-2018:0574</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2439">RHSA-2018:2439</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2729">RHSA-2018:2729</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2019:1258">RHSA-2019:1258</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/06/msg00015.html">[debian-lts-announce] 20180629 [SECURITY] [DLA 1407-1] mariadb-10.0 security update</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4341">DSA-4341</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.32"/>
        <vers num="5.5.33"/>
        <vers num="5.5.34"/>
        <vers num="5.5.35"/>
        <vers num="5.5.36"/>
        <vers num="5.5.37"/>
        <vers num="5.5.40"/>
        <vers num="5.5.41"/>
        <vers num="5.5.42"/>
        <vers num="5.5.45"/>
        <vers num="5.5.46"/>
        <vers num="5.5.47"/>
        <vers num="5.5.48"/>
        <vers num="5.5.49"/>
        <vers num="5.5.50"/>
        <vers num="5.5.51"/>
        <vers num="5.5.52"/>
        <vers num="5.5.53"/>
        <vers num="5.5.56"/>
        <vers num="5.5.57"/>
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10379" seq="2017-10379" published="2017-10-19" modified="2018-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4002">DSA-4002</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101415" adv="1">101415</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0279">RHSA-2018:0279</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0574">RHSA-2018:0574</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2439">RHSA-2018:2439</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2729">RHSA-2018:2729</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.32"/>
        <vers num="5.5.33"/>
        <vers num="5.5.34"/>
        <vers num="5.5.35"/>
        <vers num="5.5.36"/>
        <vers num="5.5.37"/>
        <vers num="5.5.40"/>
        <vers num="5.5.41"/>
        <vers num="5.5.42"/>
        <vers num="5.5.45"/>
        <vers num="5.5.46"/>
        <vers num="5.5.47"/>
        <vers num="5.5.48"/>
        <vers num="5.5.49"/>
        <vers num="5.5.50"/>
        <vers num="5.5.51"/>
        <vers num="5.5.52"/>
        <vers num="5.5.53"/>
        <vers num="5.5.56"/>
        <vers num="5.5.57"/>
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10380" seq="2017-10380" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java Advanced Management Console. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java Advanced Management Console, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data as well as unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101450">101450</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596">1039596</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10381" seq="2017-10381" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101470">101470</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10382" seq="2017-10382" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101475">101475</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10383" seq="2017-10383" published="2017-10-19" modified="2017-10-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101436">101436</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_guest_access" vendor="oracle">
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10384" seq="2017-10384" published="2017-10-19" modified="2018-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-4002">DSA-4002</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101406" adv="1">101406</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597" adv="1">1039597</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3265">RHSA-2017:3265</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3442">RHSA-2017:3442</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0279">RHSA-2018:0279</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0574">RHSA-2018:0574</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2439">RHSA-2018:2439</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2729">RHSA-2018:2729</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.32"/>
        <vers num="5.5.33"/>
        <vers num="5.5.34"/>
        <vers num="5.5.35"/>
        <vers num="5.5.36"/>
        <vers num="5.5.37"/>
        <vers num="5.5.40"/>
        <vers num="5.5.41"/>
        <vers num="5.5.42"/>
        <vers num="5.5.45"/>
        <vers num="5.5.46"/>
        <vers num="5.5.47"/>
        <vers num="5.5.48"/>
        <vers num="5.5.49"/>
        <vers num="5.5.50"/>
        <vers num="5.5.51"/>
        <vers num="5.5.52"/>
        <vers num="5.5.53"/>
        <vers num="5.5.56"/>
        <vers num="5.5.57"/>
        <vers num="5.6.0"/>
        <vers num="5.6.1"/>
        <vers num="5.6.2"/>
        <vers num="5.6.3"/>
        <vers num="5.6.4"/>
        <vers num="5.6.5"/>
        <vers num="5.6.6"/>
        <vers num="5.6.7"/>
        <vers num="5.6.8"/>
        <vers num="5.6.9"/>
        <vers num="5.6.10"/>
        <vers num="5.6.11"/>
        <vers num="5.6.12"/>
        <vers num="5.6.13"/>
        <vers num="5.6.14"/>
        <vers num="5.6.15"/>
        <vers num="5.6.16"/>
        <vers num="5.6.17"/>
        <vers num="5.6.21"/>
        <vers num="5.6.22"/>
        <vers num="5.6.23"/>
        <vers num="5.6.26"/>
        <vers num="5.6.27"/>
        <vers num="5.6.28"/>
        <vers num="5.6.29"/>
        <vers num="5.6.30"/>
        <vers num="5.6.31"/>
        <vers num="5.6.32"/>
        <vers num="5.6.33"/>
        <vers num="5.6.34"/>
        <vers num="5.6.35"/>
        <vers num="5.6.36"/>
        <vers num="5.6.37"/>
        <vers num="5.7.0"/>
        <vers num="5.7.1"/>
        <vers num="5.7.2"/>
        <vers num="5.7.3"/>
        <vers num="5.7.4"/>
        <vers num="5.7.5"/>
        <vers num="5.7.6"/>
        <vers num="5.7.7"/>
        <vers num="5.7.8"/>
        <vers num="5.7.9"/>
        <vers num="5.7.10"/>
        <vers num="5.7.11"/>
        <vers num="5.7.12"/>
        <vers num="5.7.13"/>
        <vers num="5.7.14"/>
        <vers num="5.7.15"/>
        <vers num="5.7.16"/>
        <vers num="5.7.17"/>
        <vers num="5.7.18"/>
        <vers num="5.7.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10385" seq="2017-10385" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data as well as unauthorized read access to a subset of Oracle GlassFish Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101360">101360</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039606">1039606</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.0.1"/>
        <vers num="3.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10386" seq="2017-10386" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Java Advanced Management Console. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java Advanced Management Console, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data as well as unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101443">101443</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596">1039596</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="java_advanced_management_console" vendor="oracle">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10387" seq="2017-10387" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101404">101404</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="customer_relationship_management_technical_foundation" vendor="oracle">
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10388" seq="2017-10388" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: Applies to the Java SE Kerberos client. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101321" adv="1">101321</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039596" adv="1">1039596</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2998">RHSA-2017:2998</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2999">RHSA-2017:2999</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3046">RHSA-2017:3046</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3047">RHSA-2017:3047</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3264">RHSA-2017:3264</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3267">RHSA-2017:3267</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3268">RHSA-2017:3268</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3392">RHSA-2017:3392</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3453">RHSA-2017:3453</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00033.html">[debian-lts-announce] 20171123 [SECURITY] [DLA 1187-1] openjdk-7 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-31">GLSA-201710-31</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-14">GLSA-201711-14</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0001/">https://security.netapp.com/advisory/ntap-20171019-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4015">DSA-4015</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4048">DSA-4048</ref>
      <ref source="CONFIRM" url="https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK">https://www.synology.com/support/security/Synology_SA_17_66_OpenJDK</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
      <prod name="jre" vendor="oracle">
        <vers num="1.6.0" edition="update_161"/>
        <vers num="1.7.0" edition="update_151"/>
        <vers num="1.8.0" edition="update_144"/>
        <vers num="1.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10389" seq="2017-10389" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.1" CVSS_base_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: PMS). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data as well as unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Suite8. CVSS 3.0 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101457">101457</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10391" seq="2017-10391" published="2017-10-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data as well as unauthorized read access to a subset of Oracle GlassFish Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101347">101347</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039606">1039606</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.0.1"/>
        <vers num="3.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10392" seq="2017-10392" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.30. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101368">101368</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039599">1039599</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10393" seq="2017-10393" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data as well as unauthorized read access to a subset of Oracle GlassFish Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101364">101364</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039606">1039606</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.0.1"/>
        <vers num="3.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10394" seq="2017-10394" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101474">101474</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10395" seq="2017-10395" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Fleet Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Fleet Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101438">101438</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_fleet_management" vendor="oracle">
        <vers num="9.0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10396" seq="2017-10396" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise AffairWhere component of Oracle Hospitality Applications (subcomponent: AffairWhere). Supported versions that are affected are 2.2.5.0, 2.2.6.0 and 2.2.7.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise AffairWhere executes to compromise Oracle Hospitality Cruise AffairWhere. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Cruise AffairWhere, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise AffairWhere. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101440">101440</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_affairwhere" vendor="oracle">
        <vers num="2.2.5.0"/>
        <vers num="2.2.6.0"/>
        <vers num="2.2.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10397" seq="2017-10397" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: BaseMasterPage). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Cruise Fleet Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Cruise Fleet Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Fleet Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101447">101447</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_fleet_management" vendor="oracle">
        <vers num="9.0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10398" seq="2017-10398" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.2" CVSS_base_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: BaseMasterPage). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Fleet Management executes to compromise Oracle Hospitality Cruise Fleet Management. While the vulnerability is in Oracle Hospitality Cruise Fleet Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Cruise Fleet Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Fleet Management accessible data. CVSS 3.0 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101452">101452</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_fleet_management" vendor="oracle">
        <vers num="9.0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10399" seq="2017-10399" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Cruise Fleet Management. CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101449">101449</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_fleet_management" vendor="oracle">
        <vers num="9.0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10400" seq="2017-10400" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical User Interface). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data as well as unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101383">101383</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039606">1039606</ref>
    </refs>
    <vuln_soft>
      <prod name="glassfish_server" vendor="oracle">
        <vers num="3.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10401" seq="2017-10401" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Cruise Materials Management component of Oracle Hospitality Applications (subcomponent: MMSUpdater). The supported version that is affected is 7.30.564.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Materials Management executes to compromise Oracle Hospitality Cruise Materials Management. While the vulnerability is in Oracle Hospitality Cruise Materials Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Cruise Materials Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Cruise Materials Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Materials Management. CVSS 3.0 Base Score 8.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101453">101453</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_cruise_materials_management" vendor="oracle">
        <vers num="7.30.564.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10402" seq="2017-10402" published="2017-10-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. While the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101407">101407</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10403" seq="2017-10403" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: iQuery). Supported versions that are affected are 8.5.1 and 9.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101399">101399</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10404" seq="2017-10404" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: iQuery). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. While the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101403">101403</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10405" seq="2017-10405" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. While the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Reporting and Analytics. CVSS 3.0 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101394">101394</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_reporting_and_analytics" vendor="oracle">
        <vers num="8.5.1"/>
        <vers num="9.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10406" seq="2017-10406" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101471">101471</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
        <vers num="8.55"/>
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10407" seq="2017-10407" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.30. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101370">101370</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039599">1039599</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.28" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10408" seq="2017-10408" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.30. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101371">101371</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039599">1039599</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.28" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10409" seq="2017-10409" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Merchant UI). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101332">101332</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10410" seq="2017-10410" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Search). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101340">101340</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="knowledge_management" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10411" seq="2017-10411" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101345">101345</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="knowledge_management" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10412" seq="2017-10412" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101349">101349</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="knowledge_management" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10413" seq="2017-10413" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Multiplatform Based on HTML5). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Field Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Mobile Field Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Mobile Field Service accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101353">101353</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="mobile_field_service" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10414" seq="2017-10414" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Checkout and Order Placement). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101330">101330</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="istore" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10415" seq="2017-10415" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: Others). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101336">101336</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="isupport" vendor="oracle">
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10416" seq="2017-10416" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: Setup and Configuration). Supported versions that are affected are 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101303">101303</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_outbound_telephony" vendor="oracle">
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10417" seq="2017-10417" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: Setup and Configuration). Supported versions that are affected are 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101308">101308</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039592">1039592</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_outbound_telephony" vendor="oracle">
        <vers num="12.2.3"/>
        <vers num="12.2.4"/>
        <vers num="12.2.5"/>
        <vers num="12.2.6"/>
        <vers num="12.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10418" seq="2017-10418" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: PeopleSoft CDA). The supported version that is affected is 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101462">101462</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10419" seq="2017-10419" published="2017-10-19" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: PMS). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data as well as unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 5.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101461">101461</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10420" seq="2017-10420" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. While the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Suite8. CVSS 3.0 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101323">101323</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10421" seq="2017-10421" published="2017-10-19" modified="2017-10-22" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101320">101320</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_suite8" vendor="oracle">
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10422" seq="2017-10422" published="2017-10-19" modified="2017-10-22" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Updates Change Assistant). The supported version that is affected is 8.54. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101473">101473</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_peopletools" vendor="oracle">
        <vers num="8.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10423" seq="2017-10423" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Back Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13.2, 13.3, 13.4, 14.0 and 14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Back Office. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Back Office, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Back Office accessible data as well as unauthorized read access to a subset of Oracle Retail Back Office accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101342">101342</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101380">101380</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_back_office" vendor="oracle">
        <vers num="13.2"/>
        <vers num="13.3"/>
        <vers num="13.4"/>
        <vers num="14.0"/>
        <vers num="14.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10424" seq="2017-10424" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Web). Supported versions that are affected are 3.2.8.2223 and earlier, 3.3.4.3247 and earlier and 3.4.2.4181 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101381">101381</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039597">1039597</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171019-0002/">https://security.netapp.com/advisory/ntap-20171019-0002/</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql_enterprise_monitor" vendor="oracle">
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.8.2223"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.4.3247"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.2.4181"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10425" seq="2017-10425" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Service Host). Supported versions that are affected are 2.6, 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101366">101366</ref>
    </refs>
    <vuln_soft>
      <prod name="hospitality_simphony" vendor="oracle">
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10426" seq="2017-10426" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101481">101481</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039598">1039598</ref>
    </refs>
    <vuln_soft>
      <prod name="peoplesoft_enterprise_staffing_front_office" vendor="oracle">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10427" seq="2017-10427" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle Retail Xstore Point of Service component of Oracle Retail Applications (subcomponent: Point of Sale). Supported versions that are affected are 6.0.11, 6.5.11, 7.0.6, 7.1.6 and 15.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. While the vulnerability is in Oracle Retail Xstore Point of Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Point of Service accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Point of Service. CVSS 3.0 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101339">101339</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101388">101388</ref>
    </refs>
    <vuln_soft>
      <prod name="retail_xstore_point_of_service" vendor="oracle">
        <vers num="6.0.11"/>
        <vers num="6.5.11"/>
        <vers num="7.0.6"/>
        <vers num="7.1.6"/>
        <vers num="15.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10428" seq="2017-10428" published="2017-10-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.1" CVSS_base_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.30. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html" adv="1" patch="1">http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101362">101362</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039599">1039599</ref>
    </refs>
    <vuln_soft>
      <prod name="vm_virtualbox" vendor="oracle">
        <vers num="5.1.28" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10600" seq="2017-10600" published="2017-07-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the resulting image is booted, a local attacker with the same uid as the image creator has unintended access to cloud-init and snapd directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://forum.snapcraft.io/t/ownership-bug-in-ubuntu-image/1285" adv="1">https://forum.snapcraft.io/t/ownership-bug-in-ubuntu-image/1285</ref>
    </refs>
    <vuln_soft>
      <prod name="ubuntu-image" vendor="canonical">
        <vers num="1.0" edition="2017-07-06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10601" seq="2017-10601" published="2017-07-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password while trying to login through console, ssh, ftp, telnet or su, etc., This issue relies upon a device configuration precondition to occur. Typically, device configurations are the result of a trusted administrative change to the system's running configuration. The following error messages may be seen when this failure occurs: mgd: error: commit failed: (statements constraint check failed) Warning: Commit failed, activating partial configuration. Warning: Edit the router configuration to fix these errors. If the administrative changes are not made that result in such a failure, then this issue is not seen. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.3 prior to 12.3R10, 12.3R11; 12.3X48 prior to 12.3X48-D20; 13.2 prior to 13.2R8; 13.3 prior to 13.3R7; 14.1 prior to 14.1R4-S12, 14.1R5, 14.1R6; 14.1X53 prior to 14.1X53-D30; 14.2 prior to 14.2R4; 15.1 prior to 15.1F2, 15.1F3, 15.1R2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038902" adv="1">1038902</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10802" adv="1">https://kb.juniper.net/JSA10802</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.3" edition="r1"/>
        <vers num="12.3" edition="r11"/>
        <vers num="12.3" edition="r2"/>
        <vers num="12.3" edition="r3"/>
        <vers num="12.3" edition="r4"/>
        <vers num="12.3" edition="r5"/>
        <vers num="12.3" edition="r6"/>
        <vers num="12.3" edition="r7"/>
        <vers num="12.3" edition="r8"/>
        <vers num="12.3" edition="r9"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="13.2" edition="r1"/>
        <vers num="13.2" edition="r2"/>
        <vers num="13.2" edition="r3"/>
        <vers num="13.2" edition="r4"/>
        <vers num="13.2" edition="r5"/>
        <vers num="13.2" edition="r6"/>
        <vers num="13.2" edition="r7"/>
        <vers num="13.2" edition="r7-s1"/>
        <vers num="13.2" edition="r7-s2"/>
        <vers num="13.3" edition="r2"/>
        <vers num="13.3" edition="r3"/>
        <vers num="13.3" edition="r4"/>
        <vers num="13.3" edition="r5"/>
        <vers num="13.3" edition="r6"/>
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r5"/>
        <vers num="14.1" edition="r6"/>
        <vers num="14.1x53" edition="d10"/>
        <vers num="14.1x53" edition="d15"/>
        <vers num="14.1x53" edition="d16"/>
        <vers num="14.1x53" edition="d25"/>
        <vers num="14.1x53" edition="d26"/>
        <vers num="14.1x53" edition="d27"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10602" seq="2017-10602" published="2017-07-17" modified="2018-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow vulnerability in Junos OS CLI may allow a local authenticated user with read only privileges and access to Junos CLI, to execute code with root privileges. Affected releases are Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D46 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 14.1X53 versions prior to 14.1X53-D130 on QFabric System; 14.2 versions prior to 14.2R4-S9, 14.2R6; 15.1 versions prior to 15.1F5, 15.1R3; 15.1X49 versions prior to 15.1X49-D40 on SRX Series; 15.1X53 versions prior to 15.1X53-D47 on NFX150, NFX250; 15.1X53 versions prior to 15.1X53-D65 on QFX10000 Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5110, QFX5200.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100323">100323</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038900" adv="1">1038900</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10803" adv="1">https://kb.juniper.net/JSA10803</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="14.1x53"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r5"/>
        <vers num="15.1" edition="a1"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="f6"/>
        <vers num="15.1" edition="r3"/>
        <vers num="15.1x49"/>
        <vers num="15.1x49-d10"/>
        <vers num="15.1x49-d20"/>
        <vers num="15.1x49-d30"/>
        <vers num="15.1x49-d35"/>
        <vers num="15.1x53" edition="d10"/>
        <vers num="15.1x53" edition="d20"/>
        <vers num="15.1x53" edition="d21"/>
        <vers num="15.1x53" edition="d25"/>
        <vers num="15.1x53" edition="d30"/>
        <vers num="15.1x53" edition="d32"/>
        <vers num="15.1x53" edition="d33"/>
        <vers num="15.1x53" edition="d34"/>
        <vers num="15.1x53" edition="d40"/>
        <vers num="15.1x53" edition="d45"/>
        <vers num="15.1x53" edition="d70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10603" seq="2017-10603" published="2017-07-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 15.1X53 prior to 15.1X53-D47, 15.1 prior to 15.1R3. Junos versions prior to 15.1 are not affected. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038901" adv="1">1038901</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10805" adv="1">https://kb.juniper.net/JSA10805</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="15.1" edition="a1"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="f6"/>
        <vers num="15.1" edition="f7"/>
        <vers num="15.1" edition="r1"/>
        <vers num="15.1" edition="r2"/>
        <vers num="15.1x53" edition="d10"/>
        <vers num="15.1x53" edition="d20"/>
        <vers num="15.1x53" edition="d21"/>
        <vers num="15.1x53" edition="d25"/>
        <vers num="15.1x53" edition="d30"/>
        <vers num="15.1x53" edition="d32"/>
        <vers num="15.1x53" edition="d33"/>
        <vers num="15.1x53" edition="d34"/>
        <vers num="15.1x53" edition="d40"/>
        <vers num="15.1x53" edition="d45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10604" seq="2017-10604" published="2017-07-17" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device is in cluster mode, and a cluster sync or failover operation occurs, then there will be errors associated with synch or failover while the root account is locked out. Administrators can confirm if the root account is locked out via the following command root@device> show system login lockout user root User Lockout start Lockout end root 1995-01-01 01:00:01 PDT 1995-11-01 01:31:01 PDT Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D65 on SRX series; 12.3X48 prior to 12.3X48-D45 on SRX series; 15.1X49 prior to 15.1X49-D75 on SRX series.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038886" adv="1">1038886</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10806" adv="1">https://kb.juniper.net/JSA10806</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.1x46" edition="d55"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="12.3x48" edition="d35"/>
        <vers num="12.3x48" edition="d40"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x49" edition="d60"/>
        <vers num="15.1x49" edition="d65"/>
        <vers num="15.1x49" edition="d70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10605" seq="2017-10605" published="2017-07-17" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s). Repeated crashes of the flowd process may constitute an extended denial of service condition for the device(s). If the device is configured in high-availability, the RG1+ (data-plane) will fail-over to the secondary node. If the device is configured in stand-alone, there will be temporary traffic interruption until the flowd process is restored automatically. Sustained crafted packets may cause the secondary failover node to fail back, or fail completely, potentially halting flowd on both nodes of the cluster or causing flip-flop failovers to occur. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67 on vSRX or SRX Series; 12.3X48 prior to 12.3X48-D50 on vSRX or SRX Series; 15.1X49 prior to 15.1X49-D91, 15.1X49-D100 on vSRX or SRX Series.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038891" adv="1">1038891</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10789" adv="1">https://kb.juniper.net/JSA10789</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.1x46" edition="d55"/>
        <vers num="12.1x46" edition="d60"/>
        <vers num="12.1x46" edition="d65"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="12.3x48" edition="d35"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d100"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x49" edition="d60"/>
        <vers num="15.1x49" edition="d65"/>
        <vers num="15.1x49" edition="d70"/>
        <vers num="15.1x49" edition="d75"/>
        <vers num="15.1x49" edition="d80"/>
        <vers num="15.1x49" edition="d90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10606" seq="2017-10606" published="2017-10-13" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX300 Series to encrypt sensitive configuration data. While other products also ship with a TPM, no other products or platforms are affected by this vulnerability. Customers can confirm the version of TPM firmware via the 'show security tpm status' command. This issue was discovered by an external security researcher. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10809" adv="1">https://kb.juniper.net/JSA10809</ref>
    </refs>
    <vuln_soft>
      <prod name="trusted_platform_module_firmware" vendor="juniper">
        <vers num="4.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10607" seq="2017-10607" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP address of the router. Repeated crashes of the rpd daemon can result in an extended denial of service condition. This issue only affects devices running Junos OS 16.1R1 and services releases based off of 16.1R1 (e.g. 16.1R1-S1, 16.1R1-S2, 16.1R1-S3). No prior versions of Junos OS are affected by this vulnerability, and this issue was resolved in Junos OS 16.2 prior to 16.2R1. No other Juniper Networks products or platforms are affected by this issue. This issue was found during internal product security testing.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10810" adv="1">https://kb.juniper.net/JSA10810</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="16.1" edition="r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10608" seq="2017-10608" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated denial of service against the target. Repeated traffic in a cluster may cause repeated flip-flop failure operations or full failure to the flowd daemon halting traffic on all nodes. Only IPv6 traffic is affected by this issue. IPv4 traffic is unaffected. This issues is not seen with to-host traffic. This issue has no relation with HA services themselves, only the ALG service. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D55 on SRX; 12.1X47 prior to 12.1X47-D45 on SRX; 12.3X48 prior to 12.3X48-D32, 12.3X48-D35 on SRX; 15.1X49 prior to 15.1X49-D60 on SRX.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10811" adv="1">https://kb.juniper.net/JSA10811</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.1x47" edition="d10"/>
        <vers num="12.1x47" edition="d15"/>
        <vers num="12.1x47" edition="d20"/>
        <vers num="12.1x47" edition="d25"/>
        <vers num="12.1x47" edition="d30"/>
        <vers num="12.1x47" edition="d35"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10610" seq="2017-10610" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of the flowd process constitutes an extended denial of service condition for the SRX Series device. This issue only occurs if NAT64 is configured. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D71, 12.3X48 prior to 12.3X48-D55, 15.1X49 prior to 15.1X49-D100 on SRX Series. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10813" adv="1">https://kb.juniper.net/JSA10813</ref>
      <ref source="MISC" url="https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/nat-stateful-nat64-configuring.html" adv="1">https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/nat-stateful-nat64-configuring.html</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.1x46" edition="d55"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="12.3x48" edition="d35"/>
        <vers num="12.3x48" edition="d40"/>
        <vers num="12.3x48" edition="d45"/>
        <vers num="12.3x48" edition="d50"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x49" edition="d60"/>
        <vers num="15.1x49" edition="d65"/>
        <vers num="15.1x49" edition="d70"/>
        <vers num="15.1x49" edition="d75"/>
        <vers num="15.1x49" edition="d80"/>
        <vers num="15.1x49" edition="d90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10611" seq="2017-10611" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches interface statistics, including but not limited to SNMP GET requests, the pfem process or the FPC may crash and restart. Repeated crashes of PFE processing can result in an extended denial of service condition. This issue only affects the following platforms: (1) EX2200, EX3300, XRE200 (2) MX Series routers with MPC7E/8E/9E PFEs installed, and only if 'extended-statistics' are enabled under the [edit chassis] configuration. Affected releases are Juniper Networks Junos OS 14.1 prior to 14.1R8-S5, 14.1R9 on MX Series; 14.1X53 prior to 14.1X53-D46, 14.1X53-D50 on EX2200, EX3300, XRE200; 14.2 prior to 14.2R7-S9, 14.2R8 on MX Series; 15.1 prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S3, 15.1R6 on MX Series; 16.1 prior to 16.1R4-S5, 16.1R5, 16.1R6 on MX Series; 16.1X65 prior to 16.1X65-D45 on EX2200, EX3300, XRE200; 16.2 prior to 16.2R2-S1, 16.2R3 on MX Series; 17.1 prior to 17.1R2-S2, 17.1R3 on MX Series; 17.2 prior to 17.2R1-S3, 17.2R2 on MX Series; 17.2X75 prior to 17.2X75-D50 on MX Series; 17.3 prior to 17.3R1-S1, 17.3R2 on MX Series. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10814" adv="1">https://kb.juniper.net/JSA10814</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r5"/>
        <vers num="14.1" edition="r6"/>
        <vers num="14.1" edition="r7"/>
        <vers num="14.1" edition="r8"/>
        <vers num="14.1" edition="r9"/>
        <vers num="14.1x53" edition="d10"/>
        <vers num="14.1x53" edition="d15"/>
        <vers num="14.1x53" edition="d16"/>
        <vers num="14.1x53" edition="d25"/>
        <vers num="14.1x53" edition="d26"/>
        <vers num="14.1x53" edition="d27"/>
        <vers num="14.1x53" edition="d30"/>
        <vers num="14.1x53" edition="d35"/>
        <vers num="14.1x53" edition="d40"/>
        <vers num="14.1x53" edition="d45"/>
        <vers num="14.1x53" edition="d50"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r5"/>
        <vers num="14.2" edition="r6"/>
        <vers num="14.2" edition="r7"/>
        <vers num="14.2" edition="r8"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="f5"/>
        <vers num="15.1" edition="f6-s8"/>
        <vers num="15.1" edition="r1"/>
        <vers num="15.1" edition="r2"/>
        <vers num="15.1" edition="r3"/>
        <vers num="15.1" edition="r4"/>
        <vers num="15.1" edition="r5"/>
        <vers num="15.1" edition="r5-s3"/>
        <vers num="15.1" edition="r6"/>
        <vers num="16.1" edition="r1"/>
        <vers num="16.1" edition="r2"/>
        <vers num="16.1" edition="r3"/>
        <vers num="16.1" edition="r4"/>
        <vers num="16.1" edition="r5"/>
        <vers num="16.1" edition="r6"/>
        <vers num="16.1x65" edition="d30"/>
        <vers num="16.1x65" edition="d35"/>
        <vers num="16.1x65" edition="d40"/>
        <vers num="16.2" edition="r1"/>
        <vers num="16.2" edition="r2"/>
        <vers num="16.2" edition="r3"/>
        <vers num="17.1" edition="r1"/>
        <vers num="17.1" edition="r2"/>
        <vers num="17.1" edition="r3"/>
        <vers num="17.2" edition="r1"/>
        <vers num="17.2" edition="r2"/>
        <vers num="17.2x75"/>
        <vers num="17.3" edition="r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10612" seq="2017-10612" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.0" CVSS_base_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A persistent site scripting vulnerability in Juniper Networks Junos Space allows users who can change certain configuration to implant malicious Javascript or HTML which may be used to steal information or perform actions as other Junos Space users or administrators. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101256" adv="1">101256</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10826" adv="1">https://kb.juniper.net/JSA10826</ref>
    </refs>
    <vuln_soft>
      <prod name="junos_space" vendor="juniper">
        <vers num="16.1r3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10613" seq="2017-10613" published="2017-10-13" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a running configuration of Juniper Networks Junos OS, allows an attacker with CLI access and the ability to initiate remote sessions to the loopback interface with the defined action, to hang the kernel. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D55; 12.3X48 prior to 12.3X48-D35; 14.1 prior to 14.1R8-S4, 14.1R9; 14.1X53 prior to 14.1X53-D40; 14.2 prior to 14.2R4-S9, 14.2R7-S8, 14.2R8; 15.1 prior to 15.1F5-S3, 15.1F6, 15.1R4; 15.1X49 prior to 15.1X49-D60; 15.1X53 prior to 15.1X53-D47; 16.1 prior to 16.1R2. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10816" adv="1">https://kb.juniper.net/JSA10816</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r5"/>
        <vers num="14.1" edition="r6"/>
        <vers num="14.1" edition="r7"/>
        <vers num="14.1" edition="r9"/>
        <vers num="14.1x53" edition="d10"/>
        <vers num="14.1x53" edition="d15"/>
        <vers num="14.1x53" edition="d16"/>
        <vers num="14.1x53" edition="d25"/>
        <vers num="14.1x53" edition="d26"/>
        <vers num="14.1x53" edition="d27"/>
        <vers num="14.1x53" edition="d30"/>
        <vers num="14.1x53" edition="d35"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r7-s8"/>
        <vers num="14.2" edition="r8"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="f5"/>
        <vers num="15.1" edition="f6"/>
        <vers num="15.1" edition="r4"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x53" edition="d10"/>
        <vers num="15.1x53" edition="d20"/>
        <vers num="15.1x53" edition="d21"/>
        <vers num="15.1x53" edition="d25"/>
        <vers num="15.1x53" edition="d30"/>
        <vers num="15.1x53" edition="d32"/>
        <vers num="15.1x53" edition="d33"/>
        <vers num="15.1x53" edition="d34"/>
        <vers num="16.1" edition="r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10614" seq="2017-10614" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption denial of service attack. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D45; 12.3X48 prior to 12.3X48-D30; 14.1 prior to 14.1R4-S9, 14.1R8; 14.2 prior to 14.2R6; 15.1 prior to 15.1F5, 15.1R3; 15.1X49 prior to 15.1X49-D40; 15.1X53 prior to 15.1X53-D232, 15.1X53-D47.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10817" adv="1">https://kb.juniper.net/JSA10817</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r8"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r5"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="r3"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x53" edition="d20"/>
        <vers num="15.1x53" edition="d21"/>
        <vers num="15.1x53" edition="d210"/>
        <vers num="15.1x53" edition="d25"/>
        <vers num="15.1x53" edition="d30"/>
        <vers num="15.1x53" edition="d32"/>
        <vers num="15.1x53" edition="d33"/>
        <vers num="15.1x53" edition="d34"/>
        <vers num="15.1x53" edition="d60"/>
        <vers num="15.1x53" edition="d61"/>
        <vers num="15.1x53" edition="d62"/>
        <vers num="15.1x53" edition="d63"/>
        <vers num="15.1x53" edition="d70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10615" seq="2017-10615" published="2017-10-13" modified="2018-01-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to potentially execute arbitrary code or crash daemons such as telnetd or sshd that make use of PAM. Affected Juniper Networks Junos OS releases are: 14.1 from 14.1R5 prior to 14.1R8-S4, 14.1R9; 14.1X53 prior to 14.1X53-D50 on EX and QFX series; 14.2 from 14.2R3 prior to 14.2R7-S8, 14.2R8; No other Junos OS releases are affected by this issue. No other Juniper Networks products are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040039">1040039</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10818" adv="1">https://kb.juniper.net/JSA10818</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r5"/>
        <vers num="14.1" edition="r6"/>
        <vers num="14.1" edition="r7"/>
        <vers num="14.1" edition="r9"/>
        <vers num="14.1x53" edition="d10"/>
        <vers num="14.1x53" edition="d15"/>
        <vers num="14.1x53" edition="d16"/>
        <vers num="14.1x53" edition="d25"/>
        <vers num="14.1x53" edition="d26"/>
        <vers num="14.1x53" edition="d27"/>
        <vers num="14.1x53" edition="d30"/>
        <vers num="14.1x53" edition="d35"/>
        <vers num="14.1x53" edition="d40"/>
        <vers num="14.1x53" edition="d45"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r5"/>
        <vers num="14.2" edition="r6"/>
        <vers num="14.2" edition="r7"/>
        <vers num="14.2" edition="r8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10616" seq="2017-10616" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10819" adv="1">https://kb.juniper.net/JSA10819</ref>
    </refs>
    <vuln_soft>
      <prod name="contrail" vendor="juniper">
        <vers num="2.2"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10617" seq="2017-10617" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1 prior to 3.1.4.0; 3.2 prior to 3.2.5.0. CVE-2017-10616 and CVE-2017-10617 can be chained together and have a combined CVSSv3 score of 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10819" adv="1">https://kb.juniper.net/JSA10819</ref>
    </refs>
    <vuln_soft>
      <prod name="contrail" vendor="juniper">
        <vers num="2.2"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10618" seq="2017-10618" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When the 'bgp-error-tolerance' feature &amp;#xe2;&amp;#x80;" designed to help mitigate remote session resets from malformed path attributes &amp;#xe2;&amp;#x80;" is enabled, a BGP UPDATE containing a specifically crafted set of transitive attributes can cause the RPD routing process to crash and restart. Devices with BGP enabled that do not have 'bgp-error-tolerance' configured are not vulnerable to this issue. Affected releases are Juniper Networks Junos OS 13.3 prior to 13.3R10-S2; 14.1 prior to 14.1R8-S4, 14.1R9; 14.1X50 prior to 14.1X50-D185; 14.1X53 prior to 14.1X53-D45, 14.1X53-D50; 14.2 prior to 14.2R7-S7, 14.2R8; 15.1 prior to 15.1F5-S8, 15.1F6-S7, 15.1R5-S6, 15.1R6-S2, 15.1R7; 15.1X49 prior to 15.1X49-D100; 15.1X53 prior to 15.1X53-D64, 15.1X53-D70; 16.1 prior to 16.1R3-S4, 16.1R4-S3, 16.1R5; 16.2 prior to 16.2R1-S5, 16.2R2; 17.1 prior to 17.1R1-S3, 17.1R2; 17.2 prior to 17.2R1-S2, 17.2R2; 17.2X75 prior to 17.2X75-D50. No other Juniper Networks products or platforms are affected by this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10820" adv="1">https://kb.juniper.net/JSA10820</ref>
      <ref source="MISC" url="https://www.juniper.net/documentation/en_US/junos/topics/concept/bgp-error-handling-overview.html" adv="1">https://www.juniper.net/documentation/en_US/junos/topics/concept/bgp-error-handling-overview.html</ref>
      <ref source="MISC" url="https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/bgp-error-tolerance.html" adv="1">https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/bgp-error-tolerance.html</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="13.3" edition="r10"/>
        <vers num="13.3" edition="r2"/>
        <vers num="13.3" edition="r3"/>
        <vers num="13.3" edition="r4"/>
        <vers num="13.3" edition="r5"/>
        <vers num="13.3" edition="r6"/>
        <vers num="13.3" edition="r7"/>
        <vers num="13.3" edition="r8"/>
        <vers num="13.3" edition="r9"/>
        <vers num="14.1" edition="r1"/>
        <vers num="14.1" edition="r2"/>
        <vers num="14.1" edition="r3"/>
        <vers num="14.1" edition="r4"/>
        <vers num="14.1" edition="r5"/>
        <vers num="14.1" edition="r6"/>
        <vers num="14.1" edition="r7"/>
        <vers num="14.1" edition="r8"/>
        <vers num="14.1" edition="r9"/>
        <vers num="14.1x50" edition="d60"/>
        <vers num="14.1x53" edition="d10"/>
        <vers num="14.1x53" edition="d15"/>
        <vers num="14.1x53" edition="d16"/>
        <vers num="14.1x53" edition="d25"/>
        <vers num="14.1x53" edition="d26"/>
        <vers num="14.1x53" edition="d27"/>
        <vers num="14.1x53" edition="d30"/>
        <vers num="14.1x53" edition="d35"/>
        <vers num="14.1x53" edition="d40"/>
        <vers num="14.1x53" edition="d42"/>
        <vers num="14.1x53" edition="d43"/>
        <vers num="14.1x53" edition="d44"/>
        <vers num="14.1x53" edition="d50"/>
        <vers num="14.2" edition="r1"/>
        <vers num="14.2" edition="r2"/>
        <vers num="14.2" edition="r3"/>
        <vers num="14.2" edition="r4"/>
        <vers num="14.2" edition="r5"/>
        <vers num="14.2" edition="r6"/>
        <vers num="14.2" edition="r7"/>
        <vers num="14.2" edition="r8"/>
        <vers num="15.1" edition="f1"/>
        <vers num="15.1" edition="f2"/>
        <vers num="15.1" edition="f2-s1"/>
        <vers num="15.1" edition="f2-s2"/>
        <vers num="15.1" edition="f2-s3"/>
        <vers num="15.1" edition="f2-s4"/>
        <vers num="15.1" edition="f3"/>
        <vers num="15.1" edition="f4"/>
        <vers num="15.1" edition="f5"/>
        <vers num="15.1" edition="f6-s7"/>
        <vers num="15.1" edition="r1"/>
        <vers num="15.1" edition="r2"/>
        <vers num="15.1" edition="r3"/>
        <vers num="15.1" edition="r4"/>
        <vers num="15.1" edition="r5"/>
        <vers num="15.1" edition="r5-s6"/>
        <vers num="15.1" edition="r6-s2"/>
        <vers num="15.1" edition="r7"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x49" edition="d60"/>
        <vers num="15.1x49" edition="d65"/>
        <vers num="15.1x49" edition="d70"/>
        <vers num="15.1x49" edition="d75"/>
        <vers num="15.1x49" edition="d80"/>
        <vers num="15.1x49" edition="d90"/>
        <vers num="15.1x53" edition="d10"/>
        <vers num="15.1x53" edition="d20"/>
        <vers num="15.1x53" edition="d21"/>
        <vers num="15.1x53" edition="d25"/>
        <vers num="15.1x53" edition="d30"/>
        <vers num="15.1x53" edition="d32"/>
        <vers num="15.1x53" edition="d33"/>
        <vers num="15.1x53" edition="d34"/>
        <vers num="15.1x53" edition="d50"/>
        <vers num="15.1x53" edition="d51"/>
        <vers num="15.1x53" edition="d52"/>
        <vers num="15.1x53" edition="d55"/>
        <vers num="15.1x53" edition="d57"/>
        <vers num="15.1x53" edition="d60"/>
        <vers num="15.1x53" edition="d61"/>
        <vers num="15.1x53" edition="d62"/>
        <vers num="15.1x53" edition="d63"/>
        <vers num="15.1x53" edition="d70"/>
        <vers num="16.1" edition="r1"/>
        <vers num="16.1" edition="r2"/>
        <vers num="16.1" edition="r3"/>
        <vers num="16.1" edition="r4-s3"/>
        <vers num="16.1" edition="r5"/>
        <vers num="16.2" edition="r1"/>
        <vers num="16.2" edition="r2"/>
        <vers num="17.1" edition="r1"/>
        <vers num="17.1" edition="r2"/>
        <vers num="17.2" edition="r1"/>
        <vers num="17.2" edition="r2"/>
        <vers num="17.2x75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10619" seq="2017-10619" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When Express Path (formerly known as service offloading) is configured on Juniper Networks SRX1400, SRX3400, SRX3600, SRX5400, SRX5600, SRX5800 in high availability cluster configuration mode, certain multicast packets might cause the flowd process to crash, halting or interrupting traffic from flowing through the device and triggering RG1+ (data-plane) fail-over to the secondary node. Repeated crashes of the flowd process may constitute an extended denial of service condition. This service is not enabled by default and is only supported in high-end SRX platforms. Affected releases are Juniper Networks Junos OS 12.3X48 prior to 12.3X48-D45, 15.1X49 prior to 15.1X49-D80 on SRX1400, SRX3400, SRX3600, SRX5400, SRX5600, SRX5800.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10821" adv="1">https://kb.juniper.net/JSA10821</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.3x48"/>
        <vers num="15.1x49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10620" seq="2017-10620" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10822" adv="1">https://kb.juniper.net/JSA10822</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x46" edition="d10"/>
        <vers num="12.1x46" edition="d15"/>
        <vers num="12.1x46" edition="d20"/>
        <vers num="12.1x46" edition="d25"/>
        <vers num="12.1x46" edition="d30"/>
        <vers num="12.1x46" edition="d35"/>
        <vers num="12.1x46" edition="d40"/>
        <vers num="12.1x46" edition="d45"/>
        <vers num="12.1x46" edition="d50"/>
        <vers num="12.1x46" edition="d55"/>
        <vers num="12.1x46" edition="d60"/>
        <vers num="12.1x46" edition="d65"/>
        <vers num="12.3x48" edition="d10"/>
        <vers num="12.3x48" edition="d15"/>
        <vers num="12.3x48" edition="d20"/>
        <vers num="12.3x48" edition="d25"/>
        <vers num="12.3x48" edition="d30"/>
        <vers num="12.3x48" edition="d35"/>
        <vers num="12.3x48" edition="d40"/>
        <vers num="12.3x48" edition="d45"/>
        <vers num="12.3x48" edition="d50"/>
        <vers num="12.3x48" edition="d55"/>
        <vers num="15.1x49" edition="d10"/>
        <vers num="15.1x49" edition="d100"/>
        <vers num="15.1x49" edition="d20"/>
        <vers num="15.1x49" edition="d30"/>
        <vers num="15.1x49" edition="d35"/>
        <vers num="15.1x49" edition="d40"/>
        <vers num="15.1x49" edition="d45"/>
        <vers num="15.1x49" edition="d50"/>
        <vers num="15.1x49" edition="d55"/>
        <vers num="15.1x49" edition="d60"/>
        <vers num="15.1x49" edition="d65"/>
        <vers num="15.1x49" edition="d70"/>
        <vers num="15.1x49" edition="d75"/>
        <vers num="15.1x49" edition="d80"/>
        <vers num="15.1x49" edition="d90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10621" seq="2017-10621" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attackers to cause a denial of service. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D50; 14.1 prior to 14.1R8-S5, 14.1R9; 14.1X53 prior to 14.1X53-D50; 14.2 prior to 14.2R7-S9, 14.2R8; 15.1 prior to 15.1F2-S16, 15.1F5-S7, 15.1F6-S6, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D90; 15.1X53 prior to 15.1X53-D47; 16.1 prior to 16.1R4-S1, 16.1R5; 16.2 prior to 16.2R1-S3, 16.2R2;</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10817" adv="1">https://kb.juniper.net/JSA10817</ref>
    </refs>
    <vuln_soft>
      <prod name="junos" vendor="juniper">
        <vers num="12.1x45"/>
        <vers num="12.3x48"/>
        <vers num="14.1"/>
        <vers num="14.1x53"/>
        <vers num="14.2"/>
        <vers num="15.1"/>
        <vers num="15.1x49"/>
        <vers num="15.1x53"/>
        <vers num="16.1"/>
        <vers num="16.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10622" seq="2017-10622" published="2017-10-13" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 17.1R1 without Patch v1 and 16.1 releases prior to 16.1R3. This issue was found by an external security researcher.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101258" adv="1">101258</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10824" adv="1">https://kb.juniper.net/JSA10824</ref>
    </refs>
    <vuln_soft>
      <prod name="junos_space" vendor="juniper">
        <vers num="16.1" edition="r1"/>
        <vers num="16.1" edition="r2"/>
        <vers num="17.1" edition="r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10623" seq="2017-10623" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10826" adv="1">https://kb.juniper.net/JSA10826</ref>
    </refs>
    <vuln_soft>
      <prod name="junos_space" vendor="juniper">
        <vers num="16.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10624" seq="2017-10624" published="2017-10-13" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101255" adv="1">101255</ref>
      <ref source="CONFIRM" url="https://kb.juniper.net/JSA10826" adv="1">https://kb.juniper.net/JSA10826</ref>
    </refs>
    <vuln_soft>
      <prod name="junos_space" vendor="juniper">
        <vers num="16.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10651" seq="2017-10651" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10652" seq="2017-10652" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10653" seq="2017-10653" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10654" seq="2017-10654" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10655" seq="2017-10655" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10656" seq="2017-10656" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10657" seq="2017-10657" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10658" seq="2017-10658" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10659" seq="2017-10659" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10660" seq="2017-10660" published="2018-08-29" modified="2018-08-29" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10661" seq="2017-10661" published="2017-08-19" modified="2018-10-31" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e38da300e1e395a15048b0af1e5305bd91402f6</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3981">DSA-3981</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.15" adv="1">http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100215" adv="1">100215</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3083">RHSA-2018:3083</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3096">RHSA-2018:3096</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1481136">https://bugzilla.redhat.com/show_bug.cgi?id=1481136</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/1e38da300e1e395a15048b0af1e5305bd91402f6" adv="1" patch="1">https://github.com/torvalds/linux/commit/1e38da300e1e395a15048b0af1e5305bd91402f6</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-08-01</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43345/">43345</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.10.14" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10662" seq="2017-10662" published="2017-08-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9dd46188edc2f0d1f37328637860bb65a771124" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b9dd46188edc2f0d1f37328637860bb65a771124</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.1" adv="1">http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100215" adv="1">100215</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1481146" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1481146</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/b9dd46188edc2f0d1f37328637860bb65a771124" adv="1" patch="1">https://github.com/torvalds/linux/commit/b9dd46188edc2f0d1f37328637860bb65a771124</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10663" seq="2017-10663" published="2017-08-19" modified="2017-08-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82a" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=15d3042a937c13f5d9244241c7a9c8416ff6e82a</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4" adv="1">http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100215" adv="1">100215</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1481149" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1481149</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82a" adv="1" patch="1">https://github.com/torvalds/linux/commit/15d3042a937c13f5d9244241c7a9c8416ff6e82a</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-08-01" adv="1">https://source.android.com/security/bulletin/2017-08-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.12.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10664" seq="2017-10664" published="2017-08-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3920">DSA-3920</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/06/29/1" adv="1" patch="1">[oss-security] 20170629 CVE-2017-10664 Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99513" adv="1">99513</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2390">RHSA-2017:2390</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2445">RHSA-2017:2445</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3466">RHSA-2017:3466</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3470">RHSA-2017:3470</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3471">RHSA-2017:3471</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3472">RHSA-2017:3472</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3473">RHSA-2017:3473</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3474">RHSA-2017:3474</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1466190" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1466190</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html">[debian-lts-announce] 20181130 [SECURITY] [DLA 1599-1] qemu security update</ref>
      <ref source="MLIST" url="https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg02693.html" adv="1" patch="1">[qemu-devel] 20170611 [PATCH] qemu-nbd: Ignore SIGPIPE</ref>
    </refs>
    <vuln_soft>
      <prod name="qemu" vendor="qemu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10665" seq="2017-10665" published="2017-08-18" modified="2017-08-29" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://phpgrid.com/announcement/version-7-2-5/" adv="1" patch="1">https://phpgrid.com/announcement/version-7-2-5/</ref>
      <ref source="MISC" url="https://www.futureweb.at/security/CVE-2017-10665/" adv="1">https://www.futureweb.at/security/CVE-2017-10665/</ref>
    </refs>
    <vuln_soft>
      <prod name="phpgrid" vendor="phpgrid">
        <vers num="7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10667" seq="2017-10667" published="2017-06-28" modified="2017-07-03" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/zencart/zencart/issues/1443" adv="1">https://github.com/zencart/zencart/issues/1443</ref>
      <ref source="MISC" url="https://github.com/zhonghaozhao/zencart/issues/1" adv="1">https://github.com/zhonghaozhao/zencart/issues/1</ref>
    </refs>
    <vuln_soft>
      <prod name="zen_cart" vendor="zen-cart">
        <vers num="1.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10668" seq="2017-10668" published="2017-06-30" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the CBC mode padding in order to decrypt the transport encryption.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html" adv="1">http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html</ref>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jun/44" adv="1">http://seclists.org/fulldisclosure/2017/Jun/44</ref>
    </refs>
    <vuln_soft>
      <prod name="osci_transport_library" vendor="xoev">
        <vers num="1.6" edition=":~~.net~~~"/>
        <vers num="1.6.1" edition=":~~java~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10669" seq="2017-10669" published="2017-06-30" modified="2017-07-06" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html" adv="1">http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html</ref>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jun/44" adv="1">http://seclists.org/fulldisclosure/2017/Jun/44</ref>
    </refs>
    <vuln_soft>
      <prod name="osci_transport_library" vendor="xoev">
        <vers num="1.6" edition=":~~.net~~~"/>
        <vers num="1.6.1" edition=":~~java~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10670" seq="2017-10670" published="2017-06-30" modified="2017-07-06" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from within the infrastructure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html" adv="1">http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html</ref>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jun/44" adv="1">http://seclists.org/fulldisclosure/2017/Jun/44</ref>
    </refs>
    <vuln_soft>
      <prod name="osci_transport_library" vendor="xoev">
        <vers num="1.6" edition=":~~.net~~~"/>
        <vers num="1.6.1" edition=":~~java~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10671" seq="2017-10671" published="2017-06-29" modified="2017-07-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openwall.com/lists/oss-security/2017/06/15/9" adv="1" patch="1">http://www.openwall.com/lists/oss-security/2017/06/15/9</ref>
      <ref source="MISC" url="https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660" adv="1" patch="1">https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660</ref>
      <ref source="MISC" url="https://github.com/blueness/sthttpd/releases/tag/v2.27.1" adv="1" patch="1">https://github.com/blueness/sthttpd/releases/tag/v2.27.1</ref>
    </refs>
    <vuln_soft>
      <prod name="sthttpd" vendor="sthttpd_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10672" seq="2017-10672" published="2017-06-29" modified="2018-02-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00017.html">[debian-lts-announce] 20171114 [SECURITY] [DLA 1171-1] libxml-libxml-perl security update</ref>
      <ref source="MISC" url="https://rt.cpan.org/Public/Bug/Display.html?id=122246" adv="1">https://rt.cpan.org/Public/Bug/Display.html?id=122246</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4042">DSA-4042</ref>
    </refs>
    <vuln_soft>
      <prod name="xml-libxml" vendor="xml-libxml_project">
        <vers num="2.0129" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10673" seq="2017-10673" published="2017-06-29" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">admin/profile.php in GetSimple CMS 3.x has XSS in a name field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1234" adv="1" patch="1">https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1234</ref>
    </refs>
    <vuln_soft>
      <prod name="getsimple_cms" vendor="cagintranetworks">
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.3.9"/>
        <vers num="3.3.10"/>
        <vers num="3.3.11"/>
        <vers num="3.3.12"/>
        <vers num="3.3.13"/>
      </prod>
      <prod name="getsimple_cms" vendor="get-simple">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2" edition="b3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10674" seq="2017-10674" published="2017-06-30" modified="2017-07-06" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://blog.csdn.net/wdone/article/details/73958872" adv="1">http://blog.csdn.net/wdone/article/details/73958872</ref>
    </refs>
    <vuln_soft>
      <prod name="antivirus_engine" vendor="antiy">
        <vers num="5.0.0.06281654"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10676" seq="2017-10676" published="2017-07-19" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-600M/REVC/DIR-600M_REVC_FIRMWARE_PATCH_NOTES_3.05B01_EN.pdf" adv="1">ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-600M/REVC/DIR-600M_REVC_FIRMWARE_PATCH_NOTES_3.05B01_EN.pdf</ref>
      <ref source="MISC" url="https://iscouncil.blogspot.com/2017/07/stored-xss-in-d-link-dir-600m-router.html" adv="1" patch="1">https://iscouncil.blogspot.com/2017/07/stored-xss-in-d-link-dir-600m-router.html</ref>
    </refs>
    <vuln_soft>
      <prod name="dir-600m_firmware" vendor="d-link">
        <vers num="fw3.05b01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10677" seq="2017-10677" published="2017-08-06" modified="2017-08-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery.html" adv="1">https://iscouncil.blogspot.com/2017/08/cross-site-request-forgery.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ea4500_firmware" vendor="linksys">
        <vers num="2.0.36" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10678" seq="2017-10678" published="2017-06-29" modified="2017-07-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99383">99383</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0" adv="1" patch="1">https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/721" adv="1">https://github.com/Piwigo/Piwigo/issues/721</ref>
    </refs>
    <vuln_soft>
      <prod name="piwigo" vendor="piwigo">
        <vers num="2.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10679" seq="2017-10679" published="2017-06-29" modified="2017-07-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99380">99380</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/721" adv="1" patch="1">https://github.com/Piwigo/Piwigo/issues/721</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/723" adv="1" patch="1">https://github.com/Piwigo/Piwigo/issues/723</ref>
    </refs>
    <vuln_soft>
      <prod name="piwigo" vendor="piwigo">
        <vers num="2.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10680" seq="2017-10680" published="2017-06-29" modified="2017-07-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99349">99349</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0" adv="1" patch="1">https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/721" adv="1">https://github.com/Piwigo/Piwigo/issues/721</ref>
    </refs>
    <vuln_soft>
      <prod name="piwigo" vendor="piwigo">
        <vers num="2.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10681" seq="2017-10681" published="2017-06-29" modified="2017-07-04" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99362">99362</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0" adv="1" patch="1">https://github.com/Piwigo/Piwigo/commit/03a8329b89c0d196ecdb54227a8113f24555ffc0</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/721" adv="1">https://github.com/Piwigo/Piwigo/issues/721</ref>
    </refs>
    <vuln_soft>
      <prod name="piwigo" vendor="piwigo">
        <vers num="2.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10682" seq="2017-10682" published="2017-06-29" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99357">99357</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/commit/3dd6812412289a199564e63fffd0a9754010b9e0" adv="1" patch="1">https://github.com/Piwigo/Piwigo/commit/3dd6812412289a199564e63fffd0a9754010b9e0</ref>
      <ref source="CONFIRM" url="https://github.com/Piwigo/Piwigo/issues/724" adv="1">https://github.com/Piwigo/Piwigo/issues/724</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43337/">43337</ref>
    </refs>
    <vuln_soft>
      <prod name="piwigo" vendor="piwigo">
        <vers num="2.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10683" seq="2017-10683" published="2017-06-29" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1465819">https://bugzilla.redhat.com/show_bug.cgi?id=1465819</ref>
    </refs>
    <vuln_soft>
      <prod name="mpg123" vendor="mpg123_project">
        <vers num="1.25.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10684" seq="2017-10684" published="2017-06-29" modified="2018-10-21" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1464687">https://bugzilla.redhat.com/show_bug.cgi?id=1464687</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-13">GLSA-201804-13</ref>
    </refs>
    <vuln_soft>
      <prod name="ncurses" vendor="gnu">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10685" seq="2017-10685" published="2017-06-29" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1464692">https://bugzilla.redhat.com/show_bug.cgi?id=1464692</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-13">GLSA-201804-13</ref>
    </refs>
    <vuln_soft>
      <prod name="ncurses" vendor="gnu">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10686" seq="2017-10686" published="2017-06-29" modified="2019-03-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.nasm.us/show_bug.cgi?id=3392414" adv="1" patch="1">https://bugzilla.nasm.us/show_bug.cgi?id=3392414</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201903-19">GLSA-201903-19</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3694-1/" adv="1">USN-3694-1</ref>
    </refs>
    <vuln_soft>
      <prod name="netwide_assembler" vendor="nasm">
        <vers num="2.14" edition="rc0"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10687" seq="2017-10687" published="2017-06-29" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1466411">https://bugzilla.redhat.com/show_bug.cgi?id=1466411</ref>
    </refs>
    <vuln_soft>
      <prod name="libsass" vendor="libsass">
        <vers num="3.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10688" seq="2017-10688" published="2017-06-29" modified="2018-03-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugzilla.maptools.org/show_bug.cgi?id=2712">http://bugzilla.maptools.org/show_bug.cgi?id=2712</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3903">DSA-3903</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99359">99359</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3602-1/">USN-3602-1</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42299/">42299</ref>
    </refs>
    <vuln_soft>
      <prod name="libtiff" vendor="libtiff">
        <vers num="4.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10689" seq="2017-10689" published="2018-02-09" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2927" adv="1">RHSA-2018:2927</ref>
      <ref source="CONFIRM" url="https://puppet.com/security/cve/CVE-2017-10689" adv="1">https://puppet.com/security/cve/CVE-2017-10689</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3567-1/" adv="1">USN-3567-1</ref>
    </refs>
    <vuln_soft>
      <prod name="puppet" vendor="puppet">
        <vers num="0.9.0"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.11.0"/>
        <vers num="0.11.1"/>
        <vers num="0.11.2"/>
        <vers num="0.12.0"/>
        <vers num="0.13.0"/>
        <vers num="0.13.1"/>
        <vers num="0.13.2"/>
        <vers num="0.13.3"/>
        <vers num="0.13.4"/>
        <vers num="0.13.5"/>
        <vers num="0.13.6"/>
        <vers num="0.14.0"/>
        <vers num="0.14.1"/>
        <vers num="0.15.0"/>
        <vers num="0.15.1"/>
        <vers num="0.15.2"/>
        <vers num="0.16.0"/>
        <vers num="0.16.1"/>
        <vers num="0.16.2"/>
        <vers num="0.16.3"/>
        <vers num="0.16.4"/>
        <vers num="0.16.5"/>
        <vers num="0.17.0"/>
        <vers num="0.17.1"/>
        <vers num="0.17.2"/>
        <vers num="0.18.0"/>
        <vers num="0.18.1"/>
        <vers num="0.18.2"/>
        <vers num="0.18.3"/>
        <vers num="0.18.4"/>
        <vers num="0.19.1"/>
        <vers num="0.19.2"/>
        <vers num="0.19.3"/>
        <vers num="0.20.0"/>
        <vers num="0.20.1"/>
        <vers num="0.22.0"/>
        <vers num="0.22.1"/>
        <vers num="0.22.2"/>
        <vers num="0.22.3"/>
        <vers num="0.22.4"/>
        <vers num="0.23.0"/>
        <vers num="0.23.1"/>
        <vers num="0.23.2"/>
        <vers num="0.24.0"/>
        <vers num="0.24.1"/>
        <vers num="0.24.2"/>
        <vers num="0.24.3"/>
        <vers num="0.24.4"/>
        <vers num="0.24.5"/>
        <vers num="0.24.6"/>
        <vers num="0.24.7"/>
        <vers num="0.24.8"/>
        <vers num="0.24.9"/>
        <vers num="0.25.0"/>
        <vers num="0.25.1"/>
        <vers num="0.25.2"/>
        <vers num="0.25.3"/>
        <vers num="0.25.4"/>
        <vers num="0.25.5"/>
        <vers num="0.25.6"/>
        <vers num="1.2.7" edition=":~~enterprise~~~"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.12"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14"/>
        <vers num="2.6.15"/>
        <vers num="2.6.16"/>
        <vers num="2.6.17"/>
        <vers num="2.6.18"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.12"/>
        <vers num="2.7.13"/>
        <vers num="2.7.14"/>
        <vers num="2.7.15" edition="rc1"/>
        <vers num="2.7.15" edition="rc2"/>
        <vers num="2.7.15" edition="rc3"/>
        <vers num="2.7.15" edition="rc4"/>
        <vers num="2.7.16" edition="rc1"/>
        <vers num="2.7.17"/>
        <vers num="2.7.18"/>
        <vers num="2.7.19" edition="rc1"/>
        <vers num="2.7.19" edition="rc2"/>
        <vers num="2.7.19" edition="rc3"/>
        <vers num="2.7.20" edition="rc1"/>
        <vers num="2.7.21"/>
        <vers num="2.7.22"/>
        <vers num="2.7.23"/>
        <vers num="2.7.26"/>
        <vers num="3.0.0" edition=":~~enterprise~~~"/>
        <vers num="3.0.0" edition="rc1"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.0" edition="rc3"/>
        <vers num="3.0.0" edition="rc4"/>
        <vers num="3.0.0" edition="rc5"/>
        <vers num="3.0.0" edition="rc6"/>
        <vers num="3.0.0" edition="rc7"/>
        <vers num="3.0.0" edition="rc8"/>
        <vers num="3.0.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.2" edition="rc1"/>
        <vers num="3.0.2" edition="rc2"/>
        <vers num="3.0.2" edition="rc3"/>
        <vers num="3.1.0" edition=":~~enterprise~~~"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.1.1" edition=":~~enterprise~~~"/>
        <vers num="3.1.2" edition=":~~enterprise~~~"/>
        <vers num="3.1.3" edition=":~~enterprise~~~"/>
        <vers num="3.2.0" edition=":~~enterprise~~~"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1" edition=":~~enterprise~~~"/>
        <vers num="3.2.2" edition=":~~enterprise~~~"/>
        <vers num="3.2.3" edition=":~~enterprise~~~"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.4"/>
        <vers num="3.2.4-1"/>
        <vers num="3.3.0" edition=":~~enterprise~~~"/>
        <vers num="3.3.0" edition="rc2"/>
        <vers num="3.3.0" edition="rc3"/>
        <vers num="3.3.1" edition=":~~enterprise~~~"/>
        <vers num="3.3.1" edition="rc1"/>
        <vers num="3.3.1" edition="rc2"/>
        <vers num="3.3.1" edition="rc3"/>
        <vers num="3.3.2" edition=":~~enterprise~~~"/>
        <vers num="3.4.0" edition="rc1"/>
        <vers num="3.4.0" edition="rc2"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.5.0" edition="rc1"/>
        <vers num="3.5.0" edition="rc2"/>
        <vers num="3.5.0" edition="rc3"/>
        <vers num="3.5.1" edition="rc1"/>
        <vers num="3.6.0" edition="rc1"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.7.0" edition=":~~enterprise~~~"/>
        <vers num="3.7.1" edition=":~~enterprise~~~"/>
        <vers num="3.7.2" edition=":~~enterprise~~~"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.8.0" edition=":~~enterprise~~~"/>
        <vers num="3.8.1" edition=":~~enterprise~~~"/>
        <vers num="3.8.2" edition=":~~enterprise~~~"/>
        <vers num="3.8.3" edition=":~~enterprise~~~"/>
        <vers num="3.8.4" edition=":~~enterprise~~~"/>
        <vers num="3.8.5" edition=":~~enterprise~~~"/>
        <vers num="3.8.5-1"/>
        <vers num="3.8.6" edition=":~~enterprise~~~"/>
        <vers num="3.8.6-1"/>
        <vers num="3.8.7."/>
        <vers num="4.10.0"/>
      </prod>
      <prod name="puppet_enterprise" vendor="puppet">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
        <vers num="2.8.7"/>
        <vers num="2.8.8"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.7.0"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="2015.2.0"/>
        <vers num="2015.2.1"/>
        <vers num="2015.2.2"/>
        <vers num="2015.2.3"/>
        <vers num="2015.3.0"/>
        <vers num="2015.3.1"/>
        <vers num="2015.3.2"/>
        <vers num="2015.3.3"/>
        <vers num="2016.1.1"/>
        <vers num="2016.1.2"/>
        <vers num="2016.2.0"/>
        <vers num="2016.2.1"/>
        <vers num="2016.4.0"/>
        <vers num="2016.4.2"/>
        <vers num="2016.4.3"/>
        <vers num="2016.4.5"/>
        <vers num="2016.4.6"/>
        <vers num="2016.4.7"/>
        <vers num="2016.4.8"/>
        <vers num="2016.4.9"/>
        <vers num="2017.1.0"/>
        <vers num="2017.1.1"/>
        <vers num="2017.2.1"/>
        <vers num="2017.2.2"/>
        <vers num="2017.2.3"/>
        <vers num="2017.2.4"/>
        <vers num="2017.2.5"/>
        <vers num="2017.3.0"/>
        <vers num="2017.3.1"/>
        <vers num="2017.3.2"/>
      </prod>
      <prod name="satellite" vendor="redhat">
        <vers num="6.4"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10690" seq="2017-10690" published="2018-02-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2927" adv="1">RHSA-2018:2927</ref>
      <ref source="CONFIRM" url="https://puppet.com/security/cve/CVE-2017-10690" adv="1">https://puppet.com/security/cve/CVE-2017-10690</ref>
    </refs>
    <vuln_soft>
      <prod name="puppet" vendor="puppet">
        <vers num="0.9.0"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.11.0"/>
        <vers num="0.11.1"/>
        <vers num="0.11.2"/>
        <vers num="0.12.0"/>
        <vers num="0.13.0"/>
        <vers num="0.13.1"/>
        <vers num="0.13.2"/>
        <vers num="0.13.3"/>
        <vers num="0.13.4"/>
        <vers num="0.13.5"/>
        <vers num="0.13.6"/>
        <vers num="0.14.0"/>
        <vers num="0.14.1"/>
        <vers num="0.15.0"/>
        <vers num="0.15.1"/>
        <vers num="0.15.2"/>
        <vers num="0.16.0"/>
        <vers num="0.16.1"/>
        <vers num="0.16.2"/>
        <vers num="0.16.3"/>
        <vers num="0.16.4"/>
        <vers num="0.16.5"/>
        <vers num="0.17.0"/>
        <vers num="0.17.1"/>
        <vers num="0.17.2"/>
        <vers num="0.18.0"/>
        <vers num="0.18.1"/>
        <vers num="0.18.2"/>
        <vers num="0.18.3"/>
        <vers num="0.18.4"/>
        <vers num="0.19.1"/>
        <vers num="0.19.2"/>
        <vers num="0.19.3"/>
        <vers num="0.20.0"/>
        <vers num="0.20.1"/>
        <vers num="0.22.0"/>
        <vers num="0.22.1"/>
        <vers num="0.22.2"/>
        <vers num="0.22.3"/>
        <vers num="0.22.4"/>
        <vers num="0.23.0"/>
        <vers num="0.23.1"/>
        <vers num="0.23.2"/>
        <vers num="0.24.0"/>
        <vers num="0.24.1"/>
        <vers num="0.24.2"/>
        <vers num="0.24.3"/>
        <vers num="0.24.4"/>
        <vers num="0.24.5"/>
        <vers num="0.24.6"/>
        <vers num="0.24.7"/>
        <vers num="0.24.8"/>
        <vers num="0.24.9"/>
        <vers num="0.25.0"/>
        <vers num="0.25.1"/>
        <vers num="0.25.2"/>
        <vers num="0.25.3"/>
        <vers num="0.25.4"/>
        <vers num="0.25.5"/>
        <vers num="0.25.6"/>
        <vers num="1.2.7" edition=":~~enterprise~~~"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.12"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14"/>
        <vers num="2.6.15"/>
        <vers num="2.6.16"/>
        <vers num="2.6.17"/>
        <vers num="2.6.18"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.12"/>
        <vers num="2.7.13"/>
        <vers num="2.7.14"/>
        <vers num="2.7.15" edition="rc1"/>
        <vers num="2.7.15" edition="rc2"/>
        <vers num="2.7.15" edition="rc3"/>
        <vers num="2.7.15" edition="rc4"/>
        <vers num="2.7.16" edition="rc1"/>
        <vers num="2.7.17"/>
        <vers num="2.7.18"/>
        <vers num="2.7.19" edition="rc1"/>
        <vers num="2.7.19" edition="rc2"/>
        <vers num="2.7.19" edition="rc3"/>
        <vers num="2.7.20" edition="rc1"/>
        <vers num="2.7.21"/>
        <vers num="2.7.22"/>
        <vers num="2.7.23"/>
        <vers num="2.7.26"/>
        <vers num="3.0.0" edition=":~~enterprise~~~"/>
        <vers num="3.0.0" edition="rc1"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.0" edition="rc3"/>
        <vers num="3.0.0" edition="rc4"/>
        <vers num="3.0.0" edition="rc5"/>
        <vers num="3.0.0" edition="rc6"/>
        <vers num="3.0.0" edition="rc7"/>
        <vers num="3.0.0" edition="rc8"/>
        <vers num="3.0.1" edition=":~~enterprise~~~"/>
        <vers num="3.0.1" edition="rc1"/>
        <vers num="3.0.2" edition="rc1"/>
        <vers num="3.0.2" edition="rc2"/>
        <vers num="3.0.2" edition="rc3"/>
        <vers num="3.1.0" edition=":~~enterprise~~~"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.1.1" edition=":~~enterprise~~~"/>
        <vers num="3.1.2" edition=":~~enterprise~~~"/>
        <vers num="3.1.3" edition=":~~enterprise~~~"/>
        <vers num="3.2.0" edition=":~~enterprise~~~"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1" edition=":~~enterprise~~~"/>
        <vers num="3.2.2" edition=":~~enterprise~~~"/>
        <vers num="3.2.3" edition=":~~enterprise~~~"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.4"/>
        <vers num="3.2.4-1"/>
        <vers num="3.3.0" edition=":~~enterprise~~~"/>
        <vers num="3.3.0" edition="rc2"/>
        <vers num="3.3.0" edition="rc3"/>
        <vers num="3.3.1" edition=":~~enterprise~~~"/>
        <vers num="3.3.1" edition="rc1"/>
        <vers num="3.3.1" edition="rc2"/>
        <vers num="3.3.1" edition="rc3"/>
        <vers num="3.3.2" edition=":~~enterprise~~~"/>
        <vers num="3.4.0" edition="rc1"/>
        <vers num="3.4.0" edition="rc2"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.5.0" edition="rc1"/>
        <vers num="3.5.0" edition="rc2"/>
        <vers num="3.5.0" edition="rc3"/>
        <vers num="3.5.1" edition="rc1"/>
        <vers num="3.6.0" edition="rc1"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.7.0" edition=":~~enterprise~~~"/>
        <vers num="3.7.1" edition=":~~enterprise~~~"/>
        <vers num="3.7.2" edition=":~~enterprise~~~"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.8.0" edition=":~~enterprise~~~"/>
        <vers num="3.8.1" edition=":~~enterprise~~~"/>
        <vers num="3.8.2" edition=":~~enterprise~~~"/>
        <vers num="3.8.3" edition=":~~enterprise~~~"/>
        <vers num="3.8.4" edition=":~~enterprise~~~"/>
        <vers num="3.8.5" edition=":~~enterprise~~~"/>
        <vers num="3.8.5-1"/>
        <vers num="3.8.6" edition=":~~enterprise~~~"/>
        <vers num="3.8.6-1"/>
        <vers num="3.8.7."/>
        <vers num="4.10.0"/>
        <vers num="2015.2.0" edition=":~~enterprise~~~"/>
        <vers num="2015.2.1" edition=":~~enterprise~~~"/>
        <vers num="2015.2.2" edition=":~~enterprise~~~"/>
        <vers num="2015.2.3" edition=":~~enterprise~~~"/>
        <vers num="2015.3.0" edition=":~~enterprise~~~"/>
        <vers num="2015.3.1" edition=":~~enterprise~~~"/>
        <vers num="2015.3.2" edition=":~~enterprise~~~"/>
        <vers num="2015.3.3" edition=":~~enterprise~~~"/>
        <vers num="2016.1.1" edition=":~~enterprise~~~"/>
        <vers num="2016.1.2" edition=":~~enterprise~~~"/>
        <vers num="2016.2.0" edition=":~~enterprise~~~"/>
        <vers num="2016.2.1" edition=":~~enterprise~~~"/>
        <vers num="2016.4.0" edition=":~~enterprise~~~"/>
        <vers num="2016.4.2" edition=":~~enterprise~~~"/>
        <vers num="2016.4.3" edition=":~~enterprise~~~"/>
        <vers num="2016.4.5" edition=":~~enterprise~~~"/>
        <vers num="2016.4.6" edition=":~~enterprise~~~"/>
        <vers num="2016.4.7" edition=":~~enterprise~~~"/>
        <vers num="2016.4.8" edition=":~~enterprise~~~"/>
        <vers num="2016.4.9" edition=":~~enterprise~~~"/>
        <vers num="2016.4.10" edition=":~~enterprise~~~"/>
        <vers num="2016.4.11" edition=":~~enterprise~~~"/>
        <vers num="2016.4.12" edition=":~~enterprise~~~"/>
        <vers num="2016.4.13" edition=":~~enterprise~~~"/>
        <vers num="2016.4.14" edition=":~~enterprise~~~"/>
        <vers num="2016.5.1" edition=":~~enterprise~~~"/>
        <vers num="2016.5.2" edition=":~~enterprise~~~"/>
        <vers num="2017.1.0" edition=":~~enterprise~~~"/>
        <vers num="2017.1.1" edition=":~~enterprise~~~"/>
        <vers num="2017.2.1" edition=":~~enterprise~~~"/>
        <vers num="2017.2.2" edition=":~~enterprise~~~"/>
        <vers num="2017.2.3" edition=":~~enterprise~~~"/>
        <vers num="2017.2.4" edition=":~~enterprise~~~"/>
        <vers num="2017.2.5" edition=":~~enterprise~~~"/>
        <vers num="2017.3.0" edition=":~~enterprise~~~"/>
        <vers num="2017.3.1" edition=":~~enterprise~~~"/>
        <vers num="2017.3.2" edition=":~~enterprise~~~"/>
      </prod>
      <prod name="satellite" vendor="redhat">
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10699" seq="2017-10699" published="2017-06-30" modified="2017-11-22" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038816">1038816</ref>
      <ref source="CONFIRM" url="https://trac.videolan.org/vlc/ticket/18467" adv="1">https://trac.videolan.org/vlc/ticket/18467</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4045">DSA-4045</ref>
    </refs>
    <vuln_soft>
      <prod name="vlc_media_player" vendor="videolan">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.5.1"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10700" seq="2017-10700" published="2017-09-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.lateralsecurity.com/downloads/Lateral_Security-Advisory-QNAP_QTS_CVE-2017-10700.pdf" adv="1">https://www.lateralsecurity.com/downloads/Lateral_Security-Advisory-QNAP_QTS_CVE-2017-10700.pdf</ref>
      <ref source="CONFIRM" url="https://www.qnap.com/en/support/con_show.php?cid=128" adv="1">https://www.qnap.com/en/support/con_show.php?cid=128</ref>
    </refs>
    <vuln_soft>
      <prod name="qts" vendor="qnap">
        <vers num="4.3.3.0229"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10701" seq="2017-10701" published="2017-09-28" modified="2017-10-06" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Security Notes 2469860, 2471209, and 2488516.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100786" adv="1">100786</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100788" adv="1">100788</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100805" adv="1">100805</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101068" adv="1">101068</ref>
      <ref source="MISC" url="https://cxsecurity.com/issue/WLB-2017090219" adv="1">https://cxsecurity.com/issue/WLB-2017090219</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_portal" vendor="sap">
        <vers num="7.50" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10706" seq="2017-10706" published="2017-07-02" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer overflow because a fixed path length is used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.lofter.com/lpost/1d52afc9_105e13e5" adv="1">http://www.lofter.com/lpost/1d52afc9_105e13e5</ref>
    </refs>
    <vuln_soft>
      <prod name="antivirus_engine" vendor="antiy">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10708" seq="2017-10708" published="2017-07-18" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://launchpad.net/bugs/1700573" adv="1">https://launchpad.net/bugs/1700573</ref>
      <ref source="CONFIRM" url="https://launchpad.net/ubuntu/+source/apport/+changelog" adv="1">https://launchpad.net/ubuntu/+source/apport/+changelog</ref>
    </refs>
    <vuln_soft>
      <prod name="apport" vendor="apport_project">
        <vers num="2.20.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10709" seq="2017-10709" published="2017-06-30" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.reddit.com/r/netsec/comments/6kajkc/elephone_p9000_lock_screen_lockout_bypass_with/" adv="1">https://www.reddit.com/r/netsec/comments/6kajkc/elephone_p9000_lock_screen_lockout_bypass_with/</ref>
      <ref source="MISC" url="https://www.security.nl/posting/522081/Schermvergrendeling+Elephone+P9000+door+lek+te+omzeilen" adv="1">https://www.security.nl/posting/522081/Schermvergrendeling+Elephone+P9000+door+lek+te+omzeilen</ref>
      <ref source="MISC" url="https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-011/?fid=9707" adv="1">https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-011/?fid=9707</ref>
      <ref source="MISC" url="https://www.trustwave.com/Resources/SpiderLabs-Blog/Elephone-P9000-Lock-Screen-Lockout-Bypass/?page=1&amp;year=0&amp;month=0" adv="1">https://www.trustwave.com/Resources/SpiderLabs-Blog/Elephone-P9000-Lock-Screen-Lockout-Bypass/?page=1&amp;year=0&amp;month=0</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=dwyzonP2eZw" adv="1">https://www.youtube.com/watch?v=dwyzonP2eZw</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10711" seq="2017-10711" published="2017-07-24" modified="2017-08-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.seekurity.com/blog/general/reflected-xss-vulnerability-in-simplerisk/" adv="1">https://www.seekurity.com/blog/general/reflected-xss-vulnerability-in-simplerisk/</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=jOUKEYW0RQw" adv="1">https://www.youtube.com/watch?v=jOUKEYW0RQw</ref>
    </refs>
    <vuln_soft>
      <prod name="simplerisk" vendor="simplerisk">
        <vers num="20170614-001"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10718" seq="2017-10718" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and password thereby denying the owner an access to his/her own device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10719" seq="2017-10719" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10720" seq="2017-10720" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed on the device and an attacker who can provide the right payload can execute code on the user's system directly. Any breach of this system can allow an attacker to get access to all the data that the user has access too. The application uses a dynamic link library(DLL) called "avilib.dll" which is used by the application to send binary packets to the device that allow to control the device. One such action that the DLL provides is change password in the function "sendchangename" which allows a user to change the Wi-Fi name on the device. This function calls a sub function "sub_75876EA0" at address 0x758784F8. The function determines which action to execute based on the parameters sent to it. The "sendchangename" passes the datastring as the second argument which is the name we enter in the textbox and integer 1 as first argument. The rest of the 3 arguments are set to 0. The function "sub_75876EA0" at address 0x75876F19 uses the first argument received and to determine which block to jump to. Since the argument passed is 1, it jumps to 0x75876F20 and proceeds from there to address 0x75876F56 which calculates the length of the data string passed as the first parameter. This length and the first argument are then passed to the address 0x75877001 which calls the memmove function which uses a stack address as the destination where the password typed by us is passed as the source and length calculated above is passed as the number of bytes to copy which leads to a stack overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10721" seq="2017-10721" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10722" seq="2017-10722" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is installed on the device and an attacker who can provide the right payload can execute code on the user's system directly. Any breach of this system can allow an attacker to get access to all the data that the user has access too. The application uses a dynamic link library(DLL) called "avilib.dll" which is used by the application to send binary packets to the device that allow to control the device. One such action that the DLL provides is change password in the function "sendchangepass" which allows a user to change the Wi-Fi password on the device. This function calls a sub function "sub_75876EA0" at address 0x7587857C. The function determines which action to execute based on the parameters sent to it. The "sendchangepass" passes the datastring as the second argument which is the password we enter in the textbox and integer 2 as first argument. The rest of the 3 arguments are set to 0. The function "sub_75876EA0" at address 0x75876F19 uses the first argument received and to determine which block to jump to. Since the argument passed is 2, it jumps to 0x7587718C and proceeds from there to address 0x758771C2 which calculates the length of the data string passed as the first parameter.This length and the first argument are then passed to the address 0x7587726F which calls a memmove function which uses a stack address as the destination where the password typed by us is passed as the source and length calculated above is passed as the number of bytes to copy which leads to a stack overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10723" seq="2017-10723" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries. The firmware contains binary uvc_stream that is the UDP daemon which is responsible for handling all the UDP requests that the device receives. The client application sends a UDP request to change the Wi-Fi name which contains the following format: "SETCMD0001+0001+[2 byte length of wifiname]+[Wifiname]. This request is handled by "control_Dev_thread" function which at address "0x00409AE0" compares the incoming request and determines if the 10th byte is 01 and if it is then it redirects to 0x0040A74C which calls the function "setwifiname". The function "setwifiname" uses a memcpy function but uses the length of the payload obtained by using strlen function as the third parameter which is the number of bytes to copy and this allows an attacker to overflow the function and control the $PC value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10724" seq="2017-10724" published="2019-06-17" modified="2019-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries. The firmware contains binary uvc_stream that is the UDP daemon which is responsible for handling all the UDP requests that the device receives. The client application sends a UDP request to change the Wi-Fi name which contains the following format: "SETCMD0001+0002+[2 byte length of wifipassword]+[Wifipassword]. This request is handled by "control_Dev_thread" function which at address "0x00409AE4" compares the incoming request and determines if the 10th byte is 02 and if it is then it redirects to 0x0040A7D8, which calls the function "setwifipassword". The function "setwifipassword" uses a memcpy function but uses the length of the payload obtained by using strlen function as the third parameter which is the number of bytes to copy and this allows an attacker to overflow the function and control the $PC value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html" adv="1">http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.html</ref>
      <ref source="MISC" url="https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf" adv="1">https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdf</ref>
      <ref source="BUGTRAQ" url="https://seclists.org/bugtraq/2019/Jun/8" adv="1">20190609 Newly releases IoT security issues</ref>
    </refs>
    <vuln_soft>
      <prod name="endoscope_camera_firmware" vendor="ishekar">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10725" seq="2017-10725" published="2017-07-05" modified="2017-07-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Winamp 5.666 Build 3516(x86) allows attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls Code Flow starting at in_flv!winampGetInModule2+0x00000000000009a8."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10725" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10725</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="winamp">
        <vers num="5.666"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10726" seq="2017-10726" published="2017-07-05" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address may be used as a return value starting at f263!GetWinamp5SystemComponent+0x0000000000001951."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10726" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10726</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="winamp">
        <vers num="5.666"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10727" seq="2017-10727" published="2017-07-05" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls Branch Selection starting at in_mp3!DeleteAudioDecoder+0x000000000000762f."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10727" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10727</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="winamp">
        <vers num="5.666"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10728" seq="2017-10728" published="2017-07-05" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10728" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10728</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="winamp">
        <vers num="5.666"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10729" seq="2017-10729" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10729" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10729</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10730" seq="2017-10730" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d96."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10730" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10730</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10731" seq="2017-10731" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d80."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10731" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10731</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10732" seq="2017-10732" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10732" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10732</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10733" seq="2017-10733" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10733" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10733</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10734" seq="2017-10734" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10734" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10734</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10735" seq="2017-10735" published="2017-07-05" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.com/plugins.htm" adv="1">http://www.irfanview.com/plugins.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10735" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10735</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44" edition=":~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10736" seq="2017-10736" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!_VEC_memzero+0x000000000000006a."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10736" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10736</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10737" seq="2017-10737" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000002e6."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10737" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10737</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10738" seq="2017-10738" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000002f32332f called from KERNELBASE!CompareStringW+0x0000000000000082."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10738" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10738</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10739" seq="2017-10739" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000000c1b541c called from xnview+0x00000000003826ec."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10739" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10739</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10740" seq="2017-10740" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10740" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10740</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10741" seq="2017-10741" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10741" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10741</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10742" seq="2017-10742" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x00000000380a0500 called from ntdll_77df0000!LdrxCallInitRoutine+0x0000000000000016."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10742" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10742</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10743" seq="2017-10743" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!LdrpInitializeNode+0x000000000000015b."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10743" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10743</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10744" seq="2017-10744" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Read Access Violation on Control Flow starting at COMCTL32!CToolTipsMgr::s_ToolTipsWndProc+0x0000000000000032."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10744" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10744</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10745" seq="2017-10745" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!RtlProcessFlsData+0x00000000000000b0."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10745" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10745</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10746" seq="2017-10746" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10746" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10746</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10747" seq="2017-10747" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10747" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10747</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10748" seq="2017-10748" published="2017-07-05" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10748" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10748</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10749" seq="2017-10749" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10749" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10749</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10750" seq="2017-10750" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10750" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10750</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10751" seq="2017-10751" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!GenericEngineGetGlyphs+0x0000000000000133."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10751" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10751</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10752" seq="2017-10752" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10752" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10752</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10753" seq="2017-10753" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByMapping+0x0000000000000046."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10753" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10753</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10754" seq="2017-10754" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10754" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10754</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10755" seq="2017-10755" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInitializeThread+0x000000000000010b."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10755" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10755</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10756" seq="2017-10756" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpRemoveUCRBlock+0x0000000000000046."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10756" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10756</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10757" seq="2017-10757" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10757" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10757</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10758" seq="2017-10758" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000004b4."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10758" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10758</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10759" seq="2017-10759" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInsertDependencyRecord+0x0000000000000039."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10759" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10759</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10760" seq="2017-10760" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!SetStatusText+0x0000000000000029."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10760" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10760</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10761" seq="2017-10761" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10761" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10761</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10762" seq="2017-10762" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x000000000000042f."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10762" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10762</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10763" seq="2017-10763" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByHandle+0x0000000000000031."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10763" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10763</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10764" seq="2017-10764" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!Tab_OnGetItem+0x000000000000002f."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10764" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10764</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10765" seq="2017-10765" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10765" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10765</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10766" seq="2017-10766" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!ScriptStringAnalyse+0x00000000000001c8."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10766" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10766</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10767" seq="2017-10767" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!StateObjectListFind+0x0000000000000005."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10767" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10767</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10768" seq="2017-10768" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpInsertFreeBlock+0x00000000000001ca."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10768" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10768</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10769" seq="2017-10769" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (without RPC initialization).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10769" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10769</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10770" seq="2017-10770" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x000000000000053a."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10770" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10770</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10771" seq="2017-10771" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x0000000000000510."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10771" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10771</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10772" seq="2017-10772" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (with RPC initialization).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10772" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10772</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10773" seq="2017-10773" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at MSCTF!_CtfImeCreateThreadMgr+0x00000000000000a8."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10773" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10773</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10774" seq="2017-10774" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!FindSortHashNode+0x0000000000000040."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10774" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10774</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10775" seq="2017-10775" published="2017-07-05" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at GDI32!ScriptGetCMapWithSurrogate+0x00000000000001cb."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10775" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10775</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10776" seq="2017-10776" published="2017-07-05" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at ntdll_77df0000!LdrShutdownProcess+0x0000000000000130."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10776" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10776</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10777" seq="2017-10777" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b24."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10777" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10777</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10778" seq="2017-10778" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000233125."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10778" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10778</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10779" seq="2017-10779" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10779" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10779</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10780" seq="2017-10780" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b4a."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10780" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10780</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10781" seq="2017-10781" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByName+0x00000000000000a5."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10781" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10781</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10782" seq="2017-10782" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10782" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10782</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10783" seq="2017-10783" published="2017-07-05" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10783" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10783</ref>
    </refs>
    <vuln_soft>
      <prod name="xnview" vendor="xnview">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10784" seq="2017-10784" published="2017-09-19" modified="2018-10-31" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100853" adv="1">100853</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039363" adv="1">1039363</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1042004">1042004</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3485">RHSA-2017:3485</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0378">RHSA-2018:0378</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0583">RHSA-2018:0583</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0585">RHSA-2018:0585</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html">[debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-18">GLSA-201710-18</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3528-1/">USN-3528-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3685-1/">USN-3685-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4031">DSA-4031</ref>
      <ref source="CONFIRM" url="https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/" adv="1" patch="1">https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/</ref>
      <ref source="CONFIRM" url="https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/" adv="1" patch="1">https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/</ref>
      <ref source="CONFIRM" url="https://www.ruby-lang.org/en/news/2017/09/14/webrick-basic-auth-escape-sequence-injection-cve-2017-10784/" adv="1">https://www.ruby-lang.org/en/news/2017/09/14/webrick-basic-auth-escape-sequence-injection-cve-2017-10784/</ref>
    </refs>
    <vuln_soft>
      <prod name="ruby" vendor="ruby-lang">
        <vers num="2.2.7" prev="1"/>
        <vers num="2.3.0" edition="preview1"/>
        <vers num="2.3.0" edition="preview2"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.4.0" edition="preview1"/>
        <vers num="2.4.0" edition="preview2"/>
        <vers num="2.4.0" edition="preview3"/>
        <vers num="2.4.0" edition="rc1"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10788" seq="2017-10788" published="2017-07-01" modified="2017-07-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/oss-sec/2017/q2/443">http://seclists.org/oss-sec/2017/q2/443</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99374" adv="1">99374</ref>
      <ref source="MISC" url="https://github.com/perl5-dbi/DBD-mysql/issues/120" adv="1">https://github.com/perl5-dbi/DBD-mysql/issues/120</ref>
    </refs>
    <vuln_soft>
      <prod name="dbd-mysql" vendor="dbd-mysql_project">
        <vers num="4.043" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10789" seq="2017-10789" published="2017-07-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99364" adv="1">99364</ref>
      <ref source="MISC" url="https://github.com/perl5-dbi/DBD-mysql/issues/110" adv="1">https://github.com/perl5-dbi/DBD-mysql/issues/110</ref>
      <ref source="MISC" url="https://github.com/perl5-dbi/DBD-mysql/issues/140">https://github.com/perl5-dbi/DBD-mysql/issues/140</ref>
      <ref source="MISC" url="https://github.com/perl5-dbi/DBD-mysql/pull/114" adv="1">https://github.com/perl5-dbi/DBD-mysql/pull/114</ref>
    </refs>
    <vuln_soft>
      <prod name="dbd-mysql" vendor="dbd-mysql_project">
        <vers num="4.043" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10790" seq="2017-10790" published="2017-07-01" modified="2018-03-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1464141" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1464141</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-11">GLSA-201710-11</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3547-1/">USN-3547-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4106">DSA-4106</ref>
    </refs>
    <vuln_soft>
      <prod name="libtasn1" vendor="gnu">
        <vers num="4.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10791" seq="2017-10791" published="2017-07-01" modified="2017-09-01" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://lists.gnu.org/archive/html/pspp-announce/2017-08/msg00000.html">[pspp-announce] 20170812 pspp-0.11.0 released [stable]</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1467004" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1467004</ref>
    </refs>
    <vuln_soft>
      <prod name="pspp" vendor="gnu">
        <vers num="0.10.5-pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10792" seq="2017-10792" published="2017-07-01" modified="2017-09-01" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://lists.gnu.org/archive/html/pspp-announce/2017-08/msg00000.html">[pspp-announce] 20170812 pspp-0.11.0 released [stable]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99385" adv="1">99385</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1467005" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1467005</ref>
    </refs>
    <vuln_soft>
      <prod name="pspp" vendor="gnu">
        <vers num="0.10.5-pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10793" seq="2017-10793" published="2017-09-03" modified="2017-09-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The AT&amp;T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows remote attackers to obtain sensitive information (such as the Wi-Fi password) by leveraging knowledge of a hardware identifier, related to the Bulk Data Collection (BDC) mechanism defined in Broadband Forum technical reports.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100585" adv="1">100585</ref>
      <ref source="MISC" url="https://threatpost.com/bugs-in-arris-modems-distributed-by-att-vulnerable-to-trivial-attacks/127753/" adv="1">https://threatpost.com/bugs-in-arris-modems-distributed-by-att-vulnerable-to-trivial-attacks/127753/</ref>
      <ref source="MISC" url="https://www.nomotion.net/blog/sharknatto/" adv="1">https://www.nomotion.net/blog/sharknatto/</ref>
    </refs>
    <vuln_soft>
      <prod name="u-verse_firmware" vendor="att">
        <vers num="9.2.2h0d83"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10794" seq="2017-10794" published="2017-07-02" modified="2018-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99355" adv="1">99355</ref>
      <ref source="CONFIRM" url="https://sourceforge.net/p/graphicsmagick/code/ci/a20bee0a0ad216aa11a2be3de63b60ca6bef4106/" adv="1" patch="1">https://sourceforge.net/p/graphicsmagick/code/ci/a20bee0a0ad216aa11a2be3de63b60ca6bef4106/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10795" seq="2017-10795" published="2017-07-02" modified="2018-11-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99378" adv="1">99378</ref>
      <ref source="MISC" url="https://github.com/intelliants/subrion/issues/467" adv="1">https://github.com/intelliants/subrion/issues/467</ref>
    </refs>
    <vuln_soft>
      <prod name="subrion" vendor="intelliants">
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10796" seq="2017-10796" published="2017-07-02" modified="2017-07-19" severity="Low" CVSS_version="2.0" CVSS_score="3.3" CVSS_base_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="MISC" url="https://gist.github.com/elbauldelgeek/8f0f24c582f43f51a34b34420a385d75" adv="1">https://gist.github.com/elbauldelgeek/8f0f24c582f43f51a34b34420a385d75</ref>
    </refs>
    <vuln_soft>
      <prod name="nc250_v1_firmware" vendor="tp-link">
        <vers num="1.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10798" seq="2017-10798" published="2017-07-02" modified="2017-07-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In ObjectPlanet Opinio before 7.6.4, there is XSS.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.objectplanet.com/opinio/changelog.html" adv="1">http://www.objectplanet.com/opinio/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod name="opinio" vendor="objectplanet">
        <vers num="7.6.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10799" seq="2017-10799" published="2017-07-02" modified="2019-04-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/f10b9bb3ca62" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/f10b9bb3ca62</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99358" adv="1">99358</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/04/msg00015.html">[debian-lts-announce] 20190413 [SECURITY] [DLA 1755-1] graphicsmagick security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10800" seq="2017-10800" published="2017-07-02" modified="2018-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/e5761e3a2012" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/e5761e3a2012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99356" adv="1">99356</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10801" seq="2017-10801" published="2017-07-19" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://phpsocial.com/page/changelog" adv="1">https://phpsocial.com/page/changelog</ref>
      <ref source="MISC" url="https://www.seekurity.com/blog/advisories/cross-sitescripting-vulnerability-in-phpsocial-aka-phpdolphin-social-network-script/" adv="1">https://www.seekurity.com/blog/advisories/cross-sitescripting-vulnerability-in-phpsocial-aka-phpdolphin-social-network-script/</ref>
    </refs>
    <vuln_soft>
      <prod name="phpsocial" vendor="phpsocial">
        <vers num="3.0.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10803" seq="2017-10803" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="8.5" CVSS_base_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/odoo/odoo/issues/17898" adv="1" patch="1">https://github.com/odoo/odoo/issues/17898</ref>
    </refs>
    <vuln_soft>
      <prod name="odoo" vendor="odoo">
        <vers num="8.0"/>
        <vers num="9.0" edition=":~~community~~~"/>
        <vers num="9.0" edition=":~~enterprise~~~"/>
        <vers num="10.0" edition=":~~community~~~"/>
        <vers num="10.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10804" seq="2017-10804" published="2017-07-04" modified="2017-07-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3">http://initd.org/psycopg/docs/news.html#what-s-new-in-psycopg-2-6-3</ref>
      <ref source="CONFIRM" url="https://github.com/odoo/odoo/issues/17914" adv="1" patch="1">https://github.com/odoo/odoo/issues/17914</ref>
      <ref source="CONFIRM" url="https://github.com/psycopg/psycopg2/issues/420" adv="1">https://github.com/psycopg/psycopg2/issues/420</ref>
    </refs>
    <vuln_soft>
      <prod name="odoo" vendor="odoo">
        <vers num="8.0"/>
        <vers num="9.0" edition=":~~community~~~"/>
        <vers num="9.0" edition=":~~enterprise~~~"/>
        <vers num="10.0" edition=":~~community~~~"/>
        <vers num="10.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10805" seq="2017-10805" published="2017-07-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/odoo/odoo/issues/17921" adv="1" patch="1">https://github.com/odoo/odoo/issues/17921</ref>
    </refs>
    <vuln_soft>
      <prod name="odoo" vendor="odoo">
        <vers num="8.0"/>
        <vers num="9.0" edition=":~~community~~~"/>
        <vers num="9.0" edition=":~~enterprise~~~"/>
        <vers num="10.0" edition=":~~community~~~"/>
        <vers num="10.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10806" seq="2017-10806" published="2017-08-02" modified="2018-09-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3925">DSA-3925</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/07/07/1" adv="1" patch="1">[oss-security] 20170707 CVE-2017-10806 Qemu: usb-redirect: stack buffer overflow in debug logging</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99475" adv="1">99475</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1468496" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1468496</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html">[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update</ref>
      <ref source="MLIST" url="https://lists.nongnu.org/archive/html/qemu-devel/2017-05/msg03087.html" adv="1" patch="1">[qemu-devel] 20170512 [PULL 2/6] usb-redir: fix stack overflow in usbredir_log_data</ref>
    </refs>
    <vuln_soft>
      <prod name="qemu" vendor="qemu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10807" seq="2017-10807" published="2017-07-04" modified="2017-11-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3902">DSA-3902</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99511" adv="1">99511</ref>
      <ref source="CONFIRM" url="https://bugs.debian.org/867032" adv="1">https://bugs.debian.org/867032</ref>
      <ref source="CONFIRM" url="https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16" adv="1">https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16</ref>
      <ref source="CONFIRM" url="https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1" adv="1">https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1</ref>
    </refs>
    <vuln_soft>
      <prod name="jabberd2" vendor="jabberd2">
        <vers num="2.6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1081" seq="2017-1081" published="2018-04-10" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially crafted packet fragments due to incorrect memory handling.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/98089" adv="1">98089</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038369" adv="1">1038369</ref>
      <ref source="FREEBSD" url="https://www.freebsd.org/security/advisories/FreeBSD-SA-17:04.ipfilter.asc" adv="1">FreeBSD-SA-17:04</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="10.3" edition="p19"/>
        <vers num="11.0" prev="1" edition="p10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10810" seq="2017-10810" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=385aee965b4e4c36551c362a334378d2985b722a" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=385aee965b4e4c36551c362a334378d2985b722a</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3927">DSA-3927</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99433" adv="1">99433</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/385aee965b4e4c36551c362a334378d2985b722a" adv="1" patch="1">https://github.com/torvalds/linux/commit/385aee965b4e4c36551c362a334378d2985b722a</ref>
      <ref source="CONFIRM" url="https://lkml.org/lkml/2017/4/6/668" adv="1" patch="1">https://lkml.org/lkml/2017/4/6/668</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10811" seq="2017-10811" published="2017-08-18" modified="2017-08-25" severity="High" CVSS_version="2.0" CVSS_score="7.7" CVSS_base_score="7.7" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffalo WCR-1166DS devices with firmware 1.30 and earlier allow an attacker to execute arbitrary OS commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://buffalo.jp/support_s/s20170804_1.html" adv="1">http://buffalo.jp/support_s/s20170804_1.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN05340005/index.html" adv="1">JVN#05340005</ref>
    </refs>
    <vuln_soft>
      <prod name="wcr-1166ds_firmware" vendor="buffalo">
        <vers num="1.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10812" seq="2017-10812" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Photo Collection PC Software Ver.4.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN67954465/index.html" adv="1">JVN#67954465</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_collection_pc_software" vendor="nttdocomo">
        <vers num="4.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10813" seq="2017-10813" published="2017-09-15" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.7" CVSS_base_score="7.7" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.corega.jp/support/security/20170908_wlr300nm.htm" adv="1">http://www.corega.jp/support/security/20170908_wlr300nm.htm</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN00719891/index.html" adv="1">JVN#00719891</ref>
    </refs>
    <vuln_soft>
      <prod name="wlr_300_nm_firmware" vendor="corega">
        <vers num="1.90" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10814" seq="2017-10814" published="2017-09-15" modified="2017-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.7" CVSS_base_score="7.7" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.corega.jp/support/security/20170908_wlr300nm.htm" adv="1">http://www.corega.jp/support/security/20170908_wlr300nm.htm</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN00719891/index.html" adv="1">JVN#00719891</ref>
    </refs>
    <vuln_soft>
      <prod name="wlr_300_nm_firmware" vendor="corega">
        <vers num="1.90" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10815" seq="2017-10815" published="2017-08-04" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control" is installed) allow remote attackers to bypass authentication to execute arbitrary commands or operations on Terminal Agent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.intercom.co.jp/information/2017/0801.html" adv="1">http://www.intercom.co.jp/information/2017/0801.html</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU91587298/index.html" adv="1">https://jvn.jp/en/vu/JVNVU91587298/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="malion" vendor="intercom">
        <vers num="5.2.1" prev="1" edition=":~~~mac_os_x~~"/>
        <vers num="5.2.1" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10816" seq="2017-10816" published="2017-08-04" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.intercom.co.jp/information/2017/0801.html" adv="1">http://www.intercom.co.jp/information/2017/0801.html</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU91587298/index.html" adv="1">https://jvn.jp/en/vu/JVNVU91587298/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="malion" vendor="intercom">
        <vers num="5.2.1" prev="1" edition=":~~~mac~~"/>
        <vers num="5.2.1" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10817" seq="2017-10817" published="2017-08-04" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.intercom.co.jp/information/2017/0801.html" adv="1">http://www.intercom.co.jp/information/2017/0801.html</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU91587298/index.html" adv="1">https://jvn.jp/en/vu/JVNVU91587298/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="malion" vendor="intercom">
        <vers num="5.2.1" prev="1" edition=":~~~mac~~"/>
        <vers num="5.2.1" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10818" seq="2017-10818" published="2017-08-04" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.intercom.co.jp/information/2017/0801.html" adv="1">http://www.intercom.co.jp/information/2017/0801.html</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU91587298/index.html" adv="1">https://jvn.jp/en/vu/JVNVU91587298/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="malion" vendor="intercom">
        <vers num="5.2.1" prev="1" edition=":~~~mac~~"/>
        <vers num="5.2.1" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10819" seq="2017-10819" published="2017-08-04" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.intercom.co.jp/information/2017/0801.html" adv="1">http://www.intercom.co.jp/information/2017/0801.html</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU91587298/index.html" adv="1">https://jvn.jp/en/vu/JVNVU91587298/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="malion" vendor="intercom">
        <vers num="5.2.1" prev="1" edition=":~~~mac~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1082" seq="2017-1082" published="2018-09-12" modified="2018-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential overflow. Applications that use qsort to handle large data set may crash if the input follows the pathological pattern.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="p1"/>
        <vers num="10.0" edition="p10"/>
        <vers num="10.0" edition="p12"/>
        <vers num="10.0" edition="p13"/>
        <vers num="10.0" edition="p14"/>
        <vers num="10.0" edition="p15"/>
        <vers num="10.0" edition="p16"/>
        <vers num="10.0" edition="p17"/>
        <vers num="10.0" edition="p2"/>
        <vers num="10.0" edition="p3"/>
        <vers num="10.0" edition="p4"/>
        <vers num="10.0" edition="p5"/>
        <vers num="10.0" edition="p6"/>
        <vers num="10.0" edition="p7"/>
        <vers num="10.0" edition="p8"/>
        <vers num="10.0" edition="p9"/>
        <vers num="10.1" edition="-"/>
        <vers num="10.1" edition="p1"/>
        <vers num="10.1" edition="p10"/>
        <vers num="10.1" edition="p12"/>
        <vers num="10.1" edition="p15"/>
        <vers num="10.1" edition="p16"/>
        <vers num="10.1" edition="p17"/>
        <vers num="10.1" edition="p18"/>
        <vers num="10.1" edition="p19"/>
        <vers num="10.1" edition="p2"/>
        <vers num="10.1" edition="p22"/>
        <vers num="10.1" edition="p24"/>
        <vers num="10.1" edition="p25"/>
        <vers num="10.1" edition="p26"/>
        <vers num="10.1" edition="p27"/>
        <vers num="10.1" edition="p28"/>
        <vers num="10.1" edition="p29"/>
        <vers num="10.1" edition="p3"/>
        <vers num="10.1" edition="p30"/>
        <vers num="10.1" edition="p31"/>
        <vers num="10.1" edition="p32"/>
        <vers num="10.1" edition="p33"/>
        <vers num="10.1" edition="p34"/>
        <vers num="10.1" edition="p35"/>
        <vers num="10.1" edition="p36"/>
        <vers num="10.1" edition="p37"/>
        <vers num="10.1" edition="p39"/>
        <vers num="10.1" edition="p4"/>
        <vers num="10.1" edition="p40"/>
        <vers num="10.1" edition="p41"/>
        <vers num="10.1" edition="p42"/>
        <vers num="10.1" edition="p43"/>
        <vers num="10.1" edition="p44"/>
        <vers num="10.1" edition="p45"/>
        <vers num="10.1" edition="p5"/>
        <vers num="10.1" edition="p6"/>
        <vers num="10.1" edition="p7"/>
        <vers num="10.1" edition="p8"/>
        <vers num="10.1" edition="p9"/>
        <vers num="10.2" edition="-"/>
        <vers num="10.2" edition="p1"/>
        <vers num="10.2" edition="p10"/>
        <vers num="10.2" edition="p11"/>
        <vers num="10.2" edition="p12"/>
        <vers num="10.2" edition="p13"/>
        <vers num="10.2" edition="p14"/>
        <vers num="10.2" edition="p15"/>
        <vers num="10.2" edition="p16"/>
        <vers num="10.2" edition="p17"/>
        <vers num="10.2" edition="p18"/>
        <vers num="10.2" edition="p19"/>
        <vers num="10.2" edition="p2"/>
        <vers num="10.2" edition="p20"/>
        <vers num="10.2" edition="p22"/>
        <vers num="10.2" edition="p23"/>
        <vers num="10.2" edition="p24"/>
        <vers num="10.2" edition="p25"/>
        <vers num="10.2" edition="p26"/>
        <vers num="10.2" edition="p27"/>
        <vers num="10.2" edition="p28"/>
        <vers num="10.2" edition="p5"/>
        <vers num="10.2" edition="p7"/>
        <vers num="10.2" edition="p8"/>
        <vers num="10.2" edition="p9"/>
        <vers num="10.3" edition="-"/>
        <vers num="10.3" edition="p1"/>
        <vers num="10.3" edition="p10"/>
        <vers num="10.3" edition="p11"/>
        <vers num="10.3" edition="p12"/>
        <vers num="10.3" edition="p13"/>
        <vers num="10.3" edition="p14"/>
        <vers num="10.3" edition="p15"/>
        <vers num="10.3" edition="p16"/>
        <vers num="10.3" edition="p17"/>
        <vers num="10.3" edition="p18"/>
        <vers num="10.3" edition="p19"/>
        <vers num="10.3" edition="p2"/>
        <vers num="10.3" edition="p20"/>
        <vers num="10.3" edition="p21"/>
        <vers num="10.3" edition="p22"/>
        <vers num="10.3" edition="p24"/>
        <vers num="10.3" edition="p25"/>
        <vers num="10.3" edition="p26"/>
        <vers num="10.3" edition="p27"/>
        <vers num="10.3" edition="p28"/>
        <vers num="10.3" edition="p29"/>
        <vers num="10.3" edition="p3"/>
        <vers num="10.3" edition="p4"/>
        <vers num="10.3" edition="p5"/>
        <vers num="10.3" edition="p6"/>
        <vers num="10.3" edition="p9"/>
        <vers num="10.3" edition="rc2"/>
        <vers num="10.4" edition="-"/>
        <vers num="10.4" edition="p1"/>
        <vers num="10.4" edition="p11"/>
        <vers num="10.4" edition="p12"/>
        <vers num="10.4" edition="p13"/>
        <vers num="10.4" edition="p3"/>
        <vers num="10.4" edition="p4"/>
        <vers num="10.4" edition="p5"/>
        <vers num="10.4" edition="p6"/>
        <vers num="10.4" edition="p7"/>
        <vers num="10.4" edition="p8"/>
        <vers num="10.4" edition="p9"/>
        <vers num="11.0" edition="-"/>
        <vers num="11.0" edition="p1"/>
        <vers num="11.0" edition="p10"/>
        <vers num="11.0" edition="p11"/>
        <vers num="11.0" edition="p12"/>
        <vers num="11.0" edition="p13"/>
        <vers num="11.0" edition="p15"/>
        <vers num="11.0" edition="p16"/>
        <vers num="11.0" edition="p2"/>
        <vers num="11.0" edition="p3"/>
        <vers num="11.0" edition="p4"/>
        <vers num="11.0" edition="p5"/>
        <vers num="11.0" edition="p6"/>
        <vers num="11.0" edition="p7"/>
        <vers num="11.0" edition="p8"/>
        <vers num="11.0" edition="p9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10820" seq="2017-10820" published="2017-08-04" modified="2017-08-23" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer of IP Messenger for Win 4.60 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://ipmsg.org/ipmsg_dll_vulnerability.html.en" adv="1">https://ipmsg.org/ipmsg_dll_vulnerability.html.en</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN86724730/index.html" adv="1">JVN#86724730</ref>
    </refs>
    <vuln_soft>
      <prod name="ip_messenger" vendor="ipa">
        <vers num="4.60" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10821" seq="2017-10821" published="2017-08-18" modified="2017-08-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN73559859/index.html" adv="1">JVN#73559859</ref>
    </refs>
    <vuln_soft>
      <prod name="shin_kikan_toukei_houkoku_data_nyuryokuyou_program" vendor="enecho.meti">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10822" seq="2017-10822" published="2017-08-18" modified="2017-08-22" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN71104430/index.html" adv="1">JVN#71104430</ref>
    </refs>
    <vuln_soft>
      <prod name="shin_sekiyu_yunyu_chousa_houkoku_data_nyuryoku_program" vendor="enecho.meti">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10823" seq="2017-10823" published="2017-08-18" modified="2017-08-22" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website till 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN23546631/index.html" adv="1">JVN#23546631</ref>
    </refs>
    <vuln_soft>
      <prod name="shin_kinkyuji_houkoku_data_nyuryoku_program" vendor="enecho.meti">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10824" seq="2017-10824" published="2017-08-18" modified="2017-08-24" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in TDB CA TypeA use software Version 5.2 and earlier, distributed until 10 August 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN18641169/index.html" adv="1">JVN#18641169</ref>
    </refs>
    <vuln_soft>
      <prod name="type_a" vendor="teikoku_databank">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10825" seq="2017-10825" published="2017-11-02" modified="2017-11-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer of Flets Easy Setup Tool Ver1.2.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://flets-w.com/topics/setup_tool_vulnerability/" adv="1">http://flets-w.com/topics/setup_tool_vulnerability/</ref>
      <ref source="MISC" url="https://jvn.jp/en/jp/JVN97243511/278948/index.html" adv="1">https://jvn.jp/en/jp/JVN97243511/278948/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="flets_easy_setup_tool" vendor="flets-w">
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10826" seq="2017-10826" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Security Kinou Mihariban v1.0.21 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://flets-w.com/topics/mihariban_vulnerability/" adv="1">http://flets-w.com/topics/mihariban_vulnerability/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN11601216/index.html" adv="1">JVN#11601216</ref>
    </refs>
    <vuln_soft>
      <prod name="security_kinou_mihariban" vendor="ntt">
        <vers num="1.0.21" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10827" seq="2017-10827" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Flets Azukeru for Windows Auto Backup Tool v1.0.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://flets-w.com/topics/azukeru_vulnerability/" adv="1">http://flets-w.com/topics/azukeru_vulnerability/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN14658714/index.html" adv="1">JVN#14658714</ref>
    </refs>
    <vuln_soft>
      <prod name="flets_azukuu_pc_automatic_backup_tool" vendor="ntt">
        <vers num="1.0.3.0" prev="1" edition=":~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10828" seq="2017-10828" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Flets Install Tool all versions distributed through the website till 2017 August 8 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://flets-w.com/topics/inst_tool_vulnerability/" adv="1">http://flets-w.com/topics/inst_tool_vulnerability/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN14926025/index.html" adv="1">JVN#14926025</ref>
    </refs>
    <vuln_soft>
      <prod name="flets_install_tool" vendor="ntt">
        <vers num="12.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10829" seq="2017-10829" published="2017-09-01" modified="2017-09-05" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Remote Support Tool (Enkaku Support Tool) All versions distributed through the website till 2017 August 10 allow an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://flets-w.com/topics/remote_support_vulnerability/" adv="1">http://flets-w.com/topics/remote_support_vulnerability/</ref>
      <ref source="MISC" url="https://flets.com/osa/remote/pc_tool.html" adv="1">https://flets.com/osa/remote/pc_tool.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN26115441/index.html" adv="1">JVN#26115441</ref>
    </refs>
    <vuln_soft>
      <prod name="enkaku_support_tool" vendor="ntt">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1083" seq="2017-1083" published="2018-09-12" modified="2018-11-23" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process could be cause a stack overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
        <vers num="0.4_1"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5.1"/>
        <vers num="1.2"/>
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3" edition="-"/>
        <vers num="3.3" edition="rc"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3" edition="-"/>
        <vers num="4.3" edition="p24"/>
        <vers num="4.3" edition="p37"/>
        <vers num="4.3" edition="p38"/>
        <vers num="4.3" edition="p40"/>
        <vers num="4.3" edition="p41"/>
        <vers num="4.3" edition="p42"/>
        <vers num="4.3" edition="rc"/>
        <vers num="4.4" edition="-"/>
        <vers num="4.4" edition="p27"/>
        <vers num="4.4" edition="p4"/>
        <vers num="4.4" edition="p41"/>
        <vers num="4.4" edition="p42"/>
        <vers num="4.4" edition="p44"/>
        <vers num="4.4" edition="p45"/>
        <vers num="4.4" edition="p46"/>
        <vers num="4.4" edition="p47"/>
        <vers num="4.4" edition="p8"/>
        <vers num="4.5" edition="-"/>
        <vers num="4.5" edition="p1"/>
        <vers num="4.5" edition="p20"/>
        <vers num="4.5" edition="p31"/>
        <vers num="4.5" edition="p32"/>
        <vers num="4.5" edition="p34"/>
        <vers num="4.5" edition="p35"/>
        <vers num="4.5" edition="p36"/>
        <vers num="4.5" edition="p37"/>
        <vers num="4.6" edition="-"/>
        <vers num="4.6" edition="p11"/>
        <vers num="4.6" edition="p12"/>
        <vers num="4.6" edition="p16"/>
        <vers num="4.6" edition="p19"/>
        <vers num="4.6" edition="p20"/>
        <vers num="4.6" edition="p23"/>
        <vers num="4.6" edition="p24"/>
        <vers num="4.6" edition="p25"/>
        <vers num="4.6" edition="p7"/>
        <vers num="4.6.1" edition="-"/>
        <vers num="4.6.1" edition="p1"/>
        <vers num="4.6.1" edition="p10"/>
        <vers num="4.6.1" edition="p4"/>
        <vers num="4.6.1" edition="p5"/>
        <vers num="4.6.1" edition="p7"/>
        <vers num="4.6.1" edition="p9"/>
        <vers num="4.6.2" edition="-"/>
        <vers num="4.6.2" edition="p2"/>
        <vers num="4.6.2" edition="p22"/>
        <vers num="4.6.2" edition="p26"/>
        <vers num="4.6.2" edition="p27"/>
        <vers num="4.6.2" edition="p8"/>
        <vers num="4.6.2" edition="p9"/>
        <vers num="4.7" edition="-"/>
        <vers num="4.7" edition="p13"/>
        <vers num="4.7" edition="p16"/>
        <vers num="4.7" edition="p17"/>
        <vers num="4.7" edition="p19"/>
        <vers num="4.7" edition="p20"/>
        <vers num="4.7" edition="p21"/>
        <vers num="4.7" edition="p22"/>
        <vers num="4.7" edition="p23"/>
        <vers num="4.7" edition="p24"/>
        <vers num="4.7" edition="p25"/>
        <vers num="4.7" edition="p26"/>
        <vers num="4.7" edition="p27"/>
        <vers num="4.7" edition="p28"/>
        <vers num="4.7" edition="p4"/>
        <vers num="4.7" edition="p5"/>
        <vers num="4.7" edition="p6"/>
        <vers num="4.7" edition="p8"/>
        <vers num="4.7" edition="p9"/>
        <vers num="4.8" edition="-"/>
        <vers num="4.8" edition="p1"/>
        <vers num="4.8" edition="p10"/>
        <vers num="4.8" edition="p11"/>
        <vers num="4.8" edition="p12"/>
        <vers num="4.8" edition="p13"/>
        <vers num="4.8" edition="p14"/>
        <vers num="4.8" edition="p15"/>
        <vers num="4.8" edition="p16"/>
        <vers num="4.8" edition="p17"/>
        <vers num="4.8" edition="p18"/>
        <vers num="4.8" edition="p19"/>
        <vers num="4.8" edition="p2"/>
        <vers num="4.8" edition="p20"/>
        <vers num="4.8" edition="p21"/>
        <vers num="4.8" edition="p22"/>
        <vers num="4.8" edition="p23"/>
        <vers num="4.8" edition="p24"/>
        <vers num="4.8" edition="p25"/>
        <vers num="4.8" edition="p26"/>
        <vers num="4.8" edition="p27"/>
        <vers num="4.8" edition="p28"/>
        <vers num="4.8" edition="p29"/>
        <vers num="4.8" edition="p3"/>
        <vers num="4.8" edition="p6"/>
        <vers num="4.8" edition="p7"/>
        <vers num="4.8" edition="p9"/>
        <vers num="4.9" edition="-"/>
        <vers num="4.9" edition="p1"/>
        <vers num="4.9" edition="p10"/>
        <vers num="4.9" edition="p11"/>
        <vers num="4.9" edition="p12"/>
        <vers num="4.9" edition="p13"/>
        <vers num="4.9" edition="p2"/>
        <vers num="4.9" edition="p3"/>
        <vers num="4.9" edition="p4"/>
        <vers num="4.9" edition="p5"/>
        <vers num="4.9" edition="p6"/>
        <vers num="4.9" edition="p7"/>
        <vers num="4.9" edition="p8"/>
        <vers num="4.9" edition="p9"/>
        <vers num="4.9" edition="rc"/>
        <vers num="4.10" edition="-"/>
        <vers num="4.10" edition="p10"/>
        <vers num="4.10" edition="p11"/>
        <vers num="4.10" edition="p13"/>
        <vers num="4.10" edition="p14"/>
        <vers num="4.10" edition="p15"/>
        <vers num="4.10" edition="p16"/>
        <vers num="4.10" edition="p18"/>
        <vers num="4.10" edition="p19"/>
        <vers num="4.10" edition="p2"/>
        <vers num="4.10" edition="p20"/>
        <vers num="4.10" edition="p21"/>
        <vers num="4.10" edition="p22"/>
        <vers num="4.10" edition="p23"/>
        <vers num="4.10" edition="p24"/>
        <vers num="4.10" edition="p3"/>
        <vers num="4.10" edition="p4"/>
        <vers num="4.10" edition="p5"/>
        <vers num="4.10" edition="p7"/>
        <vers num="4.10" edition="p8"/>
        <vers num="4.10" edition="p9"/>
        <vers num="4.10" edition="rc"/>
        <vers num="4.11" edition="-"/>
        <vers num="4.11" edition="p1"/>
        <vers num="4.11" edition="p10"/>
        <vers num="4.11" edition="p11"/>
        <vers num="4.11" edition="p12"/>
        <vers num="4.11" edition="p13"/>
        <vers num="4.11" edition="p14"/>
        <vers num="4.11" edition="p15"/>
        <vers num="4.11" edition="p16"/>
        <vers num="4.11" edition="p17"/>
        <vers num="4.11" edition="p18"/>
        <vers num="4.11" edition="p19"/>
        <vers num="4.11" edition="p2"/>
        <vers num="4.11" edition="p20"/>
        <vers num="4.11" edition="p21"/>
        <vers num="4.11" edition="p22"/>
        <vers num="4.11" edition="p24"/>
        <vers num="4.11" edition="p25"/>
        <vers num="4.11" edition="p26"/>
        <vers num="4.11" edition="p3"/>
        <vers num="4.11" edition="p4"/>
        <vers num="4.11" edition="p5"/>
        <vers num="4.11" edition="p6"/>
        <vers num="4.11" edition="p8"/>
        <vers num="4.11" edition="p9"/>
        <vers num="5.0" edition="-"/>
        <vers num="5.0" edition="p1"/>
        <vers num="5.0" edition="p11"/>
        <vers num="5.0" edition="p13"/>
        <vers num="5.0" edition="p14"/>
        <vers num="5.0" edition="p16"/>
        <vers num="5.0" edition="p17"/>
        <vers num="5.0" edition="p18"/>
        <vers num="5.0" edition="p19"/>
        <vers num="5.0" edition="p2"/>
        <vers num="5.0" edition="p20"/>
        <vers num="5.0" edition="p21"/>
        <vers num="5.0" edition="p22"/>
        <vers num="5.0" edition="p3"/>
        <vers num="5.0" edition="p4"/>
        <vers num="5.0" edition="p5"/>
        <vers num="5.0" edition="p6"/>
        <vers num="5.0" edition="p7"/>
        <vers num="5.1" edition="-"/>
        <vers num="5.1" edition="p1"/>
        <vers num="5.1" edition="p10"/>
        <vers num="5.1" edition="p11"/>
        <vers num="5.1" edition="p12"/>
        <vers num="5.1" edition="p14"/>
        <vers num="5.1" edition="p15"/>
        <vers num="5.1" edition="p16"/>
        <vers num="5.1" edition="p17"/>
        <vers num="5.1" edition="p18"/>
        <vers num="5.1" edition="p4"/>
        <vers num="5.1" edition="p5"/>
        <vers num="5.1" edition="p7"/>
        <vers num="5.1" edition="p8"/>
        <vers num="5.1" edition="p9"/>
        <vers num="5.2" edition="-"/>
        <vers num="5.2" edition="p1"/>
        <vers num="5.2" edition="p2"/>
        <vers num="5.2.1" edition="-"/>
        <vers num="5.2.1" edition="p10"/>
        <vers num="5.2.1" edition="p11"/>
        <vers num="5.2.1" edition="p12"/>
        <vers num="5.2.1" edition="p13"/>
        <vers num="5.2.1" edition="p2"/>
        <vers num="5.2.1" edition="p3"/>
        <vers num="5.2.1" edition="p4"/>
        <vers num="5.2.1" edition="p5"/>
        <vers num="5.2.1" edition="p6"/>
        <vers num="5.2.1" edition="p7"/>
        <vers num="5.2.1" edition="p8"/>
        <vers num="5.2.1" edition="p9"/>
        <vers num="5.2.1" edition="rc2"/>
        <vers num="5.3" edition="-"/>
        <vers num="5.3" edition="beta6"/>
        <vers num="5.3" edition="p1"/>
        <vers num="5.3" edition="p10"/>
        <vers num="5.3" edition="p11"/>
        <vers num="5.3" edition="p12"/>
        <vers num="5.3" edition="p14"/>
        <vers num="5.3" edition="p15"/>
        <vers num="5.3" edition="p16"/>
        <vers num="5.3" edition="p17"/>
        <vers num="5.3" edition="p18"/>
        <vers num="5.3" edition="p19"/>
        <vers num="5.3" edition="p2"/>
        <vers num="5.3" edition="p22"/>
        <vers num="5.3" edition="p23"/>
        <vers num="5.3" edition="p24"/>
        <vers num="5.3" edition="p25"/>
        <vers num="5.3" edition="p26"/>
        <vers num="5.3" edition="p27"/>
        <vers num="5.3" edition="p28"/>
        <vers num="5.3" edition="p29"/>
        <vers num="5.3" edition="p30"/>
        <vers num="5.3" edition="p31"/>
        <vers num="5.3" edition="p32"/>
        <vers num="5.3" edition="p33"/>
        <vers num="5.3" edition="p34"/>
        <vers num="5.3" edition="p36"/>
        <vers num="5.3" edition="p37"/>
        <vers num="5.3" edition="p6"/>
        <vers num="5.3" edition="p7"/>
        <vers num="5.3" edition="p8"/>
        <vers num="5.3" edition="p9"/>
        <vers num="5.4" edition="-"/>
        <vers num="5.4" edition="p1"/>
        <vers num="5.4" edition="p10"/>
        <vers num="5.4" edition="p11"/>
        <vers num="5.4" edition="p12"/>
        <vers num="5.4" edition="p13"/>
        <vers num="5.4" edition="p14"/>
        <vers num="5.4" edition="p15"/>
        <vers num="5.4" edition="p16"/>
        <vers num="5.4" edition="p17"/>
        <vers num="5.4" edition="p18"/>
        <vers num="5.4" edition="p19"/>
        <vers num="5.4" edition="p2"/>
        <vers num="5.4" edition="p21"/>
        <vers num="5.4" edition="p22"/>
        <vers num="5.4" edition="p3"/>
        <vers num="5.4" edition="p4"/>
        <vers num="5.4" edition="p5"/>
        <vers num="5.4" edition="p7"/>
        <vers num="5.4" edition="p8"/>
        <vers num="5.4" edition="p9"/>
        <vers num="5.5" edition="-"/>
        <vers num="5.5" edition="p1"/>
        <vers num="5.5" edition="p11"/>
        <vers num="5.5" edition="p12"/>
        <vers num="5.5" edition="p13"/>
        <vers num="5.5" edition="p14"/>
        <vers num="5.5" edition="p15"/>
        <vers num="5.5" edition="p16"/>
        <vers num="5.5" edition="p17"/>
        <vers num="5.5" edition="p18"/>
        <vers num="5.5" edition="p19"/>
        <vers num="5.5" edition="p2"/>
        <vers num="5.5" edition="p20"/>
        <vers num="5.5" edition="p3"/>
        <vers num="5.5" edition="p4"/>
        <vers num="5.5" edition="p5"/>
        <vers num="5.5" edition="p7"/>
        <vers num="5.5" edition="p8"/>
        <vers num="5.5" edition="p9"/>
        <vers num="6.0" edition="-"/>
        <vers num="6.0" edition="beta5"/>
        <vers num="6.0" edition="p10"/>
        <vers num="6.0" edition="p11"/>
        <vers num="6.0" edition="p12"/>
        <vers num="6.0" edition="p14"/>
        <vers num="6.0" edition="p15"/>
        <vers num="6.0" edition="p16"/>
        <vers num="6.0" edition="p17"/>
        <vers num="6.0" edition="p2"/>
        <vers num="6.0" edition="p3"/>
        <vers num="6.0" edition="p4"/>
        <vers num="6.0" edition="p5"/>
        <vers num="6.0" edition="p6"/>
        <vers num="6.0" edition="p7"/>
        <vers num="6.0" edition="p8"/>
        <vers num="6.0" edition="p9"/>
        <vers num="6.1" edition="-"/>
        <vers num="6.1" edition="p1"/>
        <vers num="6.1" edition="p10"/>
        <vers num="6.1" edition="p11"/>
        <vers num="6.1" edition="p12"/>
        <vers num="6.1" edition="p13"/>
        <vers num="6.1" edition="p16"/>
        <vers num="6.1" edition="p17"/>
        <vers num="6.1" edition="p18"/>
        <vers num="6.1" edition="p19"/>
        <vers num="6.1" edition="p2"/>
        <vers num="6.1" edition="p20"/>
        <vers num="6.1" edition="p21"/>
        <vers num="6.1" edition="p22"/>
        <vers num="6.1" edition="p23"/>
        <vers num="6.1" edition="p24"/>
        <vers num="6.1" edition="p4"/>
        <vers num="6.1" edition="p6"/>
        <vers num="6.1" edition="p7"/>
        <vers num="6.1" edition="p9"/>
        <vers num="6.2" edition="-"/>
        <vers num="6.2" edition="p1"/>
        <vers num="6.2" edition="p10"/>
        <vers num="6.2" edition="p11"/>
        <vers num="6.2" edition="p12"/>
        <vers num="6.2" edition="p4"/>
        <vers num="6.2" edition="p5"/>
        <vers num="6.2" edition="p6"/>
        <vers num="6.2" edition="p7"/>
        <vers num="6.2" edition="p8"/>
        <vers num="6.2" edition="p9"/>
        <vers num="6.2" edition="rc1"/>
        <vers num="6.2" edition="rc2"/>
        <vers num="6.3" edition="-"/>
        <vers num="6.3" edition="p1"/>
        <vers num="6.3" edition="p10"/>
        <vers num="6.3" edition="p11"/>
        <vers num="6.3" edition="p12"/>
        <vers num="6.3" edition="p13"/>
        <vers num="6.3" edition="p14"/>
        <vers num="6.3" edition="p15"/>
        <vers num="6.3" edition="p2"/>
        <vers num="6.3" edition="p3"/>
        <vers num="6.3" edition="p4"/>
        <vers num="6.3" edition="p5"/>
        <vers num="6.3" edition="p6"/>
        <vers num="6.3" edition="p7"/>
        <vers num="6.3" edition="p8"/>
        <vers num="6.3" edition="p9"/>
        <vers num="6.3" edition="rc2"/>
        <vers num="6.4" edition="-"/>
        <vers num="6.4" edition="p1"/>
        <vers num="6.4" edition="p10"/>
        <vers num="6.4" edition="p11"/>
        <vers num="6.4" edition="p2"/>
        <vers num="6.4" edition="p3"/>
        <vers num="6.4" edition="p4"/>
        <vers num="6.4" edition="p5"/>
        <vers num="6.4" edition="p6"/>
        <vers num="6.4" edition="p7"/>
        <vers num="6.4" edition="p8"/>
        <vers num="6.4" edition="p9"/>
        <vers num="7.0" edition="-"/>
        <vers num="7.0" edition="beta4"/>
        <vers num="7.0" edition="p1"/>
        <vers num="7.0" edition="p10"/>
        <vers num="7.0" edition="p11"/>
        <vers num="7.0" edition="p12"/>
        <vers num="7.0" edition="p3"/>
        <vers num="7.0" edition="p4"/>
        <vers num="7.0" edition="p5"/>
        <vers num="7.0" edition="p6"/>
        <vers num="7.0" edition="p7"/>
        <vers num="7.0" edition="p8"/>
        <vers num="7.0" edition="p9"/>
        <vers num="7.0" edition="rc2"/>
        <vers num="7.1" edition="-"/>
        <vers num="7.1" edition="p1"/>
        <vers num="7.1" edition="p10"/>
        <vers num="7.1" edition="p12"/>
        <vers num="7.1" edition="p13"/>
        <vers num="7.1" edition="p14"/>
        <vers num="7.1" edition="p15"/>
        <vers num="7.1" edition="p16"/>
        <vers num="7.1" edition="p2"/>
        <vers num="7.1" edition="p3"/>
        <vers num="7.1" edition="p4"/>
        <vers num="7.1" edition="p5"/>
        <vers num="7.1" edition="p6"/>
        <vers num="7.1" edition="p7"/>
        <vers num="7.1" edition="p8"/>
        <vers num="7.1" edition="p9"/>
        <vers num="7.1" edition="rc1"/>
        <vers num="7.1" edition="rc2"/>
        <vers num="7.2" edition="-"/>
        <vers num="7.2" edition="p1"/>
        <vers num="7.2" edition="p3"/>
        <vers num="7.2" edition="p4"/>
        <vers num="7.2" edition="p5"/>
        <vers num="7.2" edition="p6"/>
        <vers num="7.2" edition="p8"/>
        <vers num="7.2" edition="rc2"/>
        <vers num="7.3" edition="-"/>
        <vers num="7.3" edition="p1"/>
        <vers num="7.3" edition="p2"/>
        <vers num="7.3" edition="p3"/>
        <vers num="7.3" edition="p4"/>
        <vers num="7.3" edition="p5"/>
        <vers num="7.3" edition="p6"/>
        <vers num="7.3" edition="p7"/>
        <vers num="7.3" edition="p8"/>
        <vers num="7.3" edition="p9"/>
        <vers num="7.4" edition="-"/>
        <vers num="7.4" edition="p1"/>
        <vers num="7.4" edition="p10"/>
        <vers num="7.4" edition="p11"/>
        <vers num="7.4" edition="p12"/>
        <vers num="7.4" edition="p2"/>
        <vers num="7.4" edition="p3"/>
        <vers num="7.4" edition="p4"/>
        <vers num="7.4" edition="p5"/>
        <vers num="7.4" edition="p8"/>
        <vers num="7.4" edition="p9"/>
        <vers num="8.0" edition="-"/>
        <vers num="8.0" edition="p1"/>
        <vers num="8.0" edition="p2"/>
        <vers num="8.0" edition="p3"/>
        <vers num="8.0" edition="p4"/>
        <vers num="8.0" edition="p5"/>
        <vers num="8.0" edition="p6"/>
        <vers num="8.0" edition="rc1"/>
        <vers num="8.1" edition="-"/>
        <vers num="8.1" edition="p1"/>
        <vers num="8.1" edition="p10"/>
        <vers num="8.1" edition="p11"/>
        <vers num="8.1" edition="p12"/>
        <vers num="8.1" edition="p13"/>
        <vers num="8.1" edition="p2"/>
        <vers num="8.1" edition="p3"/>
        <vers num="8.1" edition="p4"/>
        <vers num="8.1" edition="p5"/>
        <vers num="8.1" edition="p6"/>
        <vers num="8.1" edition="p7"/>
        <vers num="8.2" edition="-"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2" edition="p10"/>
        <vers num="8.2" edition="p2"/>
        <vers num="8.2" edition="p3"/>
        <vers num="8.2" edition="p4"/>
        <vers num="8.2" edition="p5"/>
        <vers num="8.2" edition="p8"/>
        <vers num="8.2" edition="p9"/>
        <vers num="8.3" edition="-"/>
        <vers num="8.3" edition="p10"/>
        <vers num="8.3" edition="p11"/>
        <vers num="8.3" edition="p14"/>
        <vers num="8.3" edition="p15"/>
        <vers num="8.3" edition="p16"/>
        <vers num="8.3" edition="p2"/>
        <vers num="8.3" edition="p3"/>
        <vers num="8.3" edition="p4"/>
        <vers num="8.3" edition="p5"/>
        <vers num="8.3" edition="p6"/>
        <vers num="8.3" edition="p7"/>
        <vers num="8.3" edition="p8"/>
        <vers num="8.3" edition="p9"/>
        <vers num="8.4" edition="-"/>
        <vers num="8.4" edition="beta1"/>
        <vers num="8.4" edition="p11"/>
        <vers num="8.4" edition="p12"/>
        <vers num="8.4" edition="p13"/>
        <vers num="8.4" edition="p14"/>
        <vers num="8.4" edition="p15"/>
        <vers num="8.4" edition="p16"/>
        <vers num="8.4" edition="p17"/>
        <vers num="8.4" edition="p19"/>
        <vers num="8.4" edition="p2"/>
        <vers num="8.4" edition="p20"/>
        <vers num="8.4" edition="p21"/>
        <vers num="8.4" edition="p22"/>
        <vers num="8.4" edition="p23"/>
        <vers num="8.4" edition="p24"/>
        <vers num="8.4" edition="p26"/>
        <vers num="8.4" edition="p27"/>
        <vers num="8.4" edition="p3"/>
        <vers num="8.4" edition="p30"/>
        <vers num="8.4" edition="p33"/>
        <vers num="8.4" edition="p34"/>
        <vers num="8.4" edition="p35"/>
        <vers num="8.4" edition="p36"/>
        <vers num="8.4" edition="p4"/>
        <vers num="8.4" edition="p7"/>
        <vers num="8.4" edition="p8"/>
        <vers num="8.4" edition="p9"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="p2"/>
        <vers num="9.0" edition="p3"/>
        <vers num="9.0" edition="p4"/>
        <vers num="9.0" edition="p5"/>
        <vers num="9.0" edition="p6"/>
        <vers num="9.0" edition="p7"/>
        <vers num="9.0" edition="rc1"/>
        <vers num="9.0" edition="rc3"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="p1"/>
        <vers num="9.1" edition="p10"/>
        <vers num="9.1" edition="p11"/>
        <vers num="9.1" edition="p12"/>
        <vers num="9.1" edition="p14"/>
        <vers num="9.1" edition="p15"/>
        <vers num="9.1" edition="p16"/>
        <vers num="9.1" edition="p17"/>
        <vers num="9.1" edition="p18"/>
        <vers num="9.1" edition="p19"/>
        <vers num="9.1" edition="p2"/>
        <vers num="9.1" edition="p20"/>
        <vers num="9.1" edition="p22"/>
        <vers num="9.1" edition="p23"/>
        <vers num="9.1" edition="p24"/>
        <vers num="9.1" edition="p3"/>
        <vers num="9.1" edition="p4"/>
        <vers num="9.1" edition="p5"/>
        <vers num="9.1" edition="p6"/>
        <vers num="9.1" edition="p7"/>
        <vers num="9.1" edition="rc2"/>
        <vers num="9.1" edition="release-p4"/>
        <vers num="9.1" edition="release-p5"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.2" edition="beta2"/>
        <vers num="9.2" edition="p10"/>
        <vers num="9.2" edition="p11"/>
        <vers num="9.2" edition="p12"/>
        <vers num="9.2" edition="p13"/>
        <vers num="9.2" edition="p15"/>
        <vers num="9.2" edition="p16"/>
        <vers num="9.2" edition="p17"/>
        <vers num="9.2" edition="p3"/>
        <vers num="9.2" edition="p4"/>
        <vers num="9.2" edition="p5"/>
        <vers num="9.2" edition="p7"/>
        <vers num="9.2" edition="p8"/>
        <vers num="9.2" edition="p9"/>
        <vers num="9.2" edition="prerelease"/>
        <vers num="9.2" edition="rc1"/>
        <vers num="9.2" edition="rc2"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="p1"/>
        <vers num="9.3" edition="p10"/>
        <vers num="9.3" edition="p12"/>
        <vers num="9.3" edition="p13"/>
        <vers num="9.3" edition="p16"/>
        <vers num="9.3" edition="p19"/>
        <vers num="9.3" edition="p2"/>
        <vers num="9.3" edition="p20"/>
        <vers num="9.3" edition="p21"/>
        <vers num="9.3" edition="p22"/>
        <vers num="9.3" edition="p23"/>
        <vers num="9.3" edition="p24"/>
        <vers num="9.3" edition="p25"/>
        <vers num="9.3" edition="p28"/>
        <vers num="9.3" edition="p3"/>
        <vers num="9.3" edition="p30"/>
        <vers num="9.3" edition="p31"/>
        <vers num="9.3" edition="p32"/>
        <vers num="9.3" edition="p33"/>
        <vers num="9.3" edition="p34"/>
        <vers num="9.3" edition="p35"/>
        <vers num="9.3" edition="p36"/>
        <vers num="9.3" edition="p38"/>
        <vers num="9.3" edition="p39"/>
        <vers num="9.3" edition="p40"/>
        <vers num="9.3" edition="p41"/>
        <vers num="9.3" edition="p42"/>
        <vers num="9.3" edition="p43"/>
        <vers num="9.3" edition="p44"/>
        <vers num="9.3" edition="p45"/>
        <vers num="9.3" edition="p47"/>
        <vers num="9.3" edition="p48"/>
        <vers num="9.3" edition="p49"/>
        <vers num="9.3" edition="p5"/>
        <vers num="9.3" edition="p50"/>
        <vers num="9.3" edition="p51"/>
        <vers num="9.3" edition="p52"/>
        <vers num="9.3" edition="p53"/>
        <vers num="9.3" edition="p6"/>
        <vers num="9.3" edition="p7"/>
        <vers num="9.3" edition="p8"/>
        <vers num="9.3" edition="p9"/>
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="p1"/>
        <vers num="10.0" edition="p10"/>
        <vers num="10.0" edition="p12"/>
        <vers num="10.0" edition="p13"/>
        <vers num="10.0" edition="p14"/>
        <vers num="10.0" edition="p15"/>
        <vers num="10.0" edition="p16"/>
        <vers num="10.0" edition="p17"/>
        <vers num="10.0" edition="p2"/>
        <vers num="10.0" edition="p3"/>
        <vers num="10.0" edition="p4"/>
        <vers num="10.0" edition="p5"/>
        <vers num="10.0" edition="p6"/>
        <vers num="10.0" edition="p7"/>
        <vers num="10.0" edition="p8"/>
        <vers num="10.0" edition="p9"/>
        <vers num="10.1" edition="-"/>
        <vers num="10.1" edition="p1"/>
        <vers num="10.1" edition="p10"/>
        <vers num="10.1" edition="p12"/>
        <vers num="10.1" edition="p15"/>
        <vers num="10.1" edition="p16"/>
        <vers num="10.1" edition="p17"/>
        <vers num="10.1" edition="p18"/>
        <vers num="10.1" edition="p19"/>
        <vers num="10.1" edition="p2"/>
        <vers num="10.1" edition="p22"/>
        <vers num="10.1" edition="p24"/>
        <vers num="10.1" edition="p25"/>
        <vers num="10.1" edition="p26"/>
        <vers num="10.1" edition="p27"/>
        <vers num="10.1" edition="p28"/>
        <vers num="10.1" edition="p29"/>
        <vers num="10.1" edition="p3"/>
        <vers num="10.1" edition="p30"/>
        <vers num="10.1" edition="p31"/>
        <vers num="10.1" edition="p32"/>
        <vers num="10.1" edition="p33"/>
        <vers num="10.1" edition="p34"/>
        <vers num="10.1" edition="p35"/>
        <vers num="10.1" edition="p36"/>
        <vers num="10.1" edition="p37"/>
        <vers num="10.1" edition="p39"/>
        <vers num="10.1" edition="p4"/>
        <vers num="10.1" edition="p40"/>
        <vers num="10.1" edition="p41"/>
        <vers num="10.1" edition="p42"/>
        <vers num="10.1" edition="p43"/>
        <vers num="10.1" edition="p44"/>
        <vers num="10.1" edition="p45"/>
        <vers num="10.1" edition="p5"/>
        <vers num="10.1" edition="p6"/>
        <vers num="10.1" edition="p7"/>
        <vers num="10.1" edition="p8"/>
        <vers num="10.1" edition="p9"/>
        <vers num="10.2" edition="-"/>
        <vers num="10.2" edition="p1"/>
        <vers num="10.2" edition="p10"/>
        <vers num="10.2" edition="p11"/>
        <vers num="10.2" edition="p12"/>
        <vers num="10.2" edition="p13"/>
        <vers num="10.2" edition="p14"/>
        <vers num="10.2" edition="p15"/>
        <vers num="10.2" edition="p16"/>
        <vers num="10.2" edition="p17"/>
        <vers num="10.2" edition="p18"/>
        <vers num="10.2" edition="p19"/>
        <vers num="10.2" edition="p2"/>
        <vers num="10.2" edition="p20"/>
        <vers num="10.2" edition="p22"/>
        <vers num="10.2" edition="p23"/>
        <vers num="10.2" edition="p24"/>
        <vers num="10.2" edition="p25"/>
        <vers num="10.2" edition="p26"/>
        <vers num="10.2" edition="p27"/>
        <vers num="10.2" edition="p28"/>
        <vers num="10.2" edition="p5"/>
        <vers num="10.2" edition="p7"/>
        <vers num="10.2" edition="p8"/>
        <vers num="10.2" edition="p9"/>
        <vers num="10.3" edition="-"/>
        <vers num="10.3" edition="p1"/>
        <vers num="10.3" edition="p10"/>
        <vers num="10.3" edition="p11"/>
        <vers num="10.3" edition="p12"/>
        <vers num="10.3" edition="p13"/>
        <vers num="10.3" edition="p14"/>
        <vers num="10.3" edition="p15"/>
        <vers num="10.3" edition="p16"/>
        <vers num="10.3" edition="p17"/>
        <vers num="10.3" edition="p18"/>
        <vers num="10.3" edition="p19"/>
        <vers num="10.3" edition="p2"/>
        <vers num="10.3" edition="p20"/>
        <vers num="10.3" edition="p21"/>
        <vers num="10.3" edition="p22"/>
        <vers num="10.3" edition="p24"/>
        <vers num="10.3" edition="p25"/>
        <vers num="10.3" edition="p26"/>
        <vers num="10.3" edition="p27"/>
        <vers num="10.3" edition="p28"/>
        <vers num="10.3" edition="p29"/>
        <vers num="10.3" edition="p3"/>
        <vers num="10.3" edition="p4"/>
        <vers num="10.3" edition="p5"/>
        <vers num="10.3" edition="p6"/>
        <vers num="10.3" edition="p9"/>
        <vers num="10.3" edition="rc2"/>
        <vers num="10.4" edition="-"/>
        <vers num="10.4" edition="p1"/>
        <vers num="10.4" edition="p11"/>
        <vers num="10.4" edition="p12"/>
        <vers num="10.4" edition="p13"/>
        <vers num="10.4" edition="p3"/>
        <vers num="10.4" edition="p4"/>
        <vers num="10.4" edition="p5"/>
        <vers num="10.4" edition="p6"/>
        <vers num="10.4" edition="p7"/>
        <vers num="10.4" edition="p8"/>
        <vers num="10.4" edition="p9"/>
        <vers num="11.0" edition="-"/>
        <vers num="11.0" edition="p1"/>
        <vers num="11.0" edition="p10"/>
        <vers num="11.0" edition="p11"/>
        <vers num="11.0" edition="p12"/>
        <vers num="11.0" edition="p13"/>
        <vers num="11.0" edition="p15"/>
        <vers num="11.0" edition="p16"/>
        <vers num="11.0" edition="p2"/>
        <vers num="11.0" edition="p3"/>
        <vers num="11.0" edition="p4"/>
        <vers num="11.0" edition="p5"/>
        <vers num="11.0" edition="p6"/>
        <vers num="11.0" edition="p7"/>
        <vers num="11.0" edition="p8"/>
        <vers num="11.0" edition="p9"/>
        <vers num="11.1" edition="-"/>
        <vers num="11.1" edition="p1"/>
        <vers num="11.1" edition="p11"/>
        <vers num="11.1" edition="p13"/>
        <vers num="11.1" edition="p14"/>
        <vers num="11.1" edition="p15"/>
        <vers num="11.1" edition="p2"/>
        <vers num="11.1" edition="p4"/>
        <vers num="11.1" edition="p5"/>
        <vers num="11.1" edition="p6"/>
        <vers num="11.1" edition="p7"/>
        <vers num="11.1" edition="p9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10830" seq="2017-10830" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Security Setup Tool all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://f-security.jp/v6/support/information/100161.html" adv="1">http://f-security.jp/v6/support/information/100161.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN36303528/index.html" adv="1">JVN#36303528</ref>
    </refs>
    <vuln_soft>
      <prod name="security_setup_tool" vendor="ntt">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10831" seq="2017-10831" published="2017-08-28" modified="2017-08-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.moj.go.jp/MINJI/minji06_00027.html" adv="1" patch="1">http://www.moj.go.jp/MINJI/minji06_00027.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN30866130/index.html" adv="1">JVN#30866130</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_registration_electronic_authentication_software" vendor="moj.go">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10832" seq="2017-10832" published="2017-08-28" modified="2017-08-31" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf" adv="1">http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN87410770/index.html" adv="1">JVN#87410770</ref>
    </refs>
    <vuln_soft>
      <prod name="scr02hd_firmware" vendor="nippon-antenna">
        <vers num="1.0.3.1000" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10833" seq="2017-10833" published="2017-08-28" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf" adv="1">http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN87410770/index.html" adv="1">JVN#87410770</ref>
    </refs>
    <vuln_soft>
      <prod name="scr02hd_firmware" vendor="nippon-antenna">
        <vers num="1.0.3.1000" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10834" seq="2017-10834" published="2017-08-28" modified="2017-08-31" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf" adv="1">http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN87410770/index.html" adv="1">JVN#87410770</ref>
    </refs>
    <vuln_soft>
      <prod name="scr02hd_firmware" vendor="nippon-antenna">
        <vers num="1.0.3.1000" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10835" seq="2017-10835" published="2017-08-28" modified="2017-08-31" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf" adv="1">http://www.nippon-antenna.co.jp/product/ine/pdf/scr02hd_about_security.pdf</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN87410770/index.html" adv="1">JVN#87410770</ref>
    </refs>
    <vuln_soft>
      <prod name="scr02hd_firmware" vendor="nippon-antenna">
        <vers num="1.0.3.1000" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10836" seq="2017-10836" published="2017-08-28" modified="2017-09-01" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Optimal Guard 1.1.21 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN87540575/index.html" adv="1">JVN#87540575</ref>
      <ref source="MISC" url="https://www.optim.co.jp/contents/23246" adv="1">https://www.optim.co.jp/contents/23246</ref>
    </refs>
    <vuln_soft>
      <prod name="optimal_guard" vendor="optim">
        <vers num="1.1.21" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10837" seq="2017-10837" published="2017-08-28" modified="2017-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN58559719/index.html" adv="1">JVN#58559719</ref>
      <ref source="MISC" url="https://wordpress.org/plugins/backup/#developers" adv="1">https://wordpress.org/plugins/backup/#developers</ref>
    </refs>
    <vuln_soft>
      <prod name="backupguard" vendor="backup-guard">
        <vers num="1.1.46" prev="1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10838" seq="2017-10838" published="2017-08-28" modified="2017-09-01" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN39628662/index.html" adv="1">JVN#39628662</ref>
    </refs>
    <vuln_soft>
      <prod name="seo_panel" vendor="seopanel">
        <vers num="3.10.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10839" seq="2017-10839" published="2017-08-28" modified="2017-09-01" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN39628662/index.html" adv="1">JVN#39628662</ref>
    </refs>
    <vuln_soft>
      <prod name="seo_panel" vendor="seopanel">
        <vers num="3.10.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1084" seq="2017-1084" published="2018-09-12" modified="2018-11-23" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42277/" adv="1">42277</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42278/" adv="1">42278</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
        <vers num="0.4_1"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5.1"/>
        <vers num="1.2"/>
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3" edition="-"/>
        <vers num="3.3" edition="rc"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3" edition="-"/>
        <vers num="4.3" edition="p24"/>
        <vers num="4.3" edition="p37"/>
        <vers num="4.3" edition="p38"/>
        <vers num="4.3" edition="p40"/>
        <vers num="4.3" edition="p41"/>
        <vers num="4.3" edition="p42"/>
        <vers num="4.3" edition="rc"/>
        <vers num="4.4" edition="-"/>
        <vers num="4.4" edition="p27"/>
        <vers num="4.4" edition="p4"/>
        <vers num="4.4" edition="p41"/>
        <vers num="4.4" edition="p42"/>
        <vers num="4.4" edition="p44"/>
        <vers num="4.4" edition="p45"/>
        <vers num="4.4" edition="p46"/>
        <vers num="4.4" edition="p47"/>
        <vers num="4.4" edition="p8"/>
        <vers num="4.5" edition="-"/>
        <vers num="4.5" edition="p1"/>
        <vers num="4.5" edition="p20"/>
        <vers num="4.5" edition="p31"/>
        <vers num="4.5" edition="p32"/>
        <vers num="4.5" edition="p34"/>
        <vers num="4.5" edition="p35"/>
        <vers num="4.5" edition="p36"/>
        <vers num="4.5" edition="p37"/>
        <vers num="4.6" edition="-"/>
        <vers num="4.6" edition="p11"/>
        <vers num="4.6" edition="p12"/>
        <vers num="4.6" edition="p16"/>
        <vers num="4.6" edition="p19"/>
        <vers num="4.6" edition="p20"/>
        <vers num="4.6" edition="p23"/>
        <vers num="4.6" edition="p24"/>
        <vers num="4.6" edition="p25"/>
        <vers num="4.6" edition="p7"/>
        <vers num="4.6.1" edition="-"/>
        <vers num="4.6.1" edition="p1"/>
        <vers num="4.6.1" edition="p10"/>
        <vers num="4.6.1" edition="p4"/>
        <vers num="4.6.1" edition="p5"/>
        <vers num="4.6.1" edition="p7"/>
        <vers num="4.6.1" edition="p9"/>
        <vers num="4.6.2" edition="-"/>
        <vers num="4.6.2" edition="p2"/>
        <vers num="4.6.2" edition="p22"/>
        <vers num="4.6.2" edition="p26"/>
        <vers num="4.6.2" edition="p27"/>
        <vers num="4.6.2" edition="p8"/>
        <vers num="4.6.2" edition="p9"/>
        <vers num="4.7" edition="-"/>
        <vers num="4.7" edition="p13"/>
        <vers num="4.7" edition="p16"/>
        <vers num="4.7" edition="p17"/>
        <vers num="4.7" edition="p19"/>
        <vers num="4.7" edition="p20"/>
        <vers num="4.7" edition="p21"/>
        <vers num="4.7" edition="p22"/>
        <vers num="4.7" edition="p23"/>
        <vers num="4.7" edition="p24"/>
        <vers num="4.7" edition="p25"/>
        <vers num="4.7" edition="p26"/>
        <vers num="4.7" edition="p27"/>
        <vers num="4.7" edition="p28"/>
        <vers num="4.7" edition="p4"/>
        <vers num="4.7" edition="p5"/>
        <vers num="4.7" edition="p6"/>
        <vers num="4.7" edition="p8"/>
        <vers num="4.7" edition="p9"/>
        <vers num="4.8" edition="-"/>
        <vers num="4.8" edition="p1"/>
        <vers num="4.8" edition="p10"/>
        <vers num="4.8" edition="p11"/>
        <vers num="4.8" edition="p12"/>
        <vers num="4.8" edition="p13"/>
        <vers num="4.8" edition="p14"/>
        <vers num="4.8" edition="p15"/>
        <vers num="4.8" edition="p16"/>
        <vers num="4.8" edition="p17"/>
        <vers num="4.8" edition="p18"/>
        <vers num="4.8" edition="p19"/>
        <vers num="4.8" edition="p2"/>
        <vers num="4.8" edition="p20"/>
        <vers num="4.8" edition="p21"/>
        <vers num="4.8" edition="p22"/>
        <vers num="4.8" edition="p23"/>
        <vers num="4.8" edition="p24"/>
        <vers num="4.8" edition="p25"/>
        <vers num="4.8" edition="p26"/>
        <vers num="4.8" edition="p27"/>
        <vers num="4.8" edition="p28"/>
        <vers num="4.8" edition="p29"/>
        <vers num="4.8" edition="p3"/>
        <vers num="4.8" edition="p6"/>
        <vers num="4.8" edition="p7"/>
        <vers num="4.8" edition="p9"/>
        <vers num="4.9" edition="-"/>
        <vers num="4.9" edition="p1"/>
        <vers num="4.9" edition="p10"/>
        <vers num="4.9" edition="p11"/>
        <vers num="4.9" edition="p12"/>
        <vers num="4.9" edition="p13"/>
        <vers num="4.9" edition="p2"/>
        <vers num="4.9" edition="p3"/>
        <vers num="4.9" edition="p4"/>
        <vers num="4.9" edition="p5"/>
        <vers num="4.9" edition="p6"/>
        <vers num="4.9" edition="p7"/>
        <vers num="4.9" edition="p8"/>
        <vers num="4.9" edition="p9"/>
        <vers num="4.9" edition="rc"/>
        <vers num="4.10" edition="-"/>
        <vers num="4.10" edition="p10"/>
        <vers num="4.10" edition="p11"/>
        <vers num="4.10" edition="p13"/>
        <vers num="4.10" edition="p14"/>
        <vers num="4.10" edition="p15"/>
        <vers num="4.10" edition="p16"/>
        <vers num="4.10" edition="p18"/>
        <vers num="4.10" edition="p19"/>
        <vers num="4.10" edition="p2"/>
        <vers num="4.10" edition="p20"/>
        <vers num="4.10" edition="p21"/>
        <vers num="4.10" edition="p22"/>
        <vers num="4.10" edition="p23"/>
        <vers num="4.10" edition="p24"/>
        <vers num="4.10" edition="p3"/>
        <vers num="4.10" edition="p4"/>
        <vers num="4.10" edition="p5"/>
        <vers num="4.10" edition="p7"/>
        <vers num="4.10" edition="p8"/>
        <vers num="4.10" edition="p9"/>
        <vers num="4.10" edition="rc"/>
        <vers num="4.11" edition="-"/>
        <vers num="4.11" edition="p1"/>
        <vers num="4.11" edition="p10"/>
        <vers num="4.11" edition="p11"/>
        <vers num="4.11" edition="p12"/>
        <vers num="4.11" edition="p13"/>
        <vers num="4.11" edition="p14"/>
        <vers num="4.11" edition="p15"/>
        <vers num="4.11" edition="p16"/>
        <vers num="4.11" edition="p17"/>
        <vers num="4.11" edition="p18"/>
        <vers num="4.11" edition="p19"/>
        <vers num="4.11" edition="p2"/>
        <vers num="4.11" edition="p20"/>
        <vers num="4.11" edition="p21"/>
        <vers num="4.11" edition="p22"/>
        <vers num="4.11" edition="p24"/>
        <vers num="4.11" edition="p25"/>
        <vers num="4.11" edition="p26"/>
        <vers num="4.11" edition="p3"/>
        <vers num="4.11" edition="p4"/>
        <vers num="4.11" edition="p5"/>
        <vers num="4.11" edition="p6"/>
        <vers num="4.11" edition="p8"/>
        <vers num="4.11" edition="p9"/>
        <vers num="5.0" edition="-"/>
        <vers num="5.0" edition="p1"/>
        <vers num="5.0" edition="p11"/>
        <vers num="5.0" edition="p13"/>
        <vers num="5.0" edition="p14"/>
        <vers num="5.0" edition="p16"/>
        <vers num="5.0" edition="p17"/>
        <vers num="5.0" edition="p18"/>
        <vers num="5.0" edition="p19"/>
        <vers num="5.0" edition="p2"/>
        <vers num="5.0" edition="p20"/>
        <vers num="5.0" edition="p21"/>
        <vers num="5.0" edition="p22"/>
        <vers num="5.0" edition="p3"/>
        <vers num="5.0" edition="p4"/>
        <vers num="5.0" edition="p5"/>
        <vers num="5.0" edition="p6"/>
        <vers num="5.0" edition="p7"/>
        <vers num="5.1" edition="-"/>
        <vers num="5.1" edition="p1"/>
        <vers num="5.1" edition="p10"/>
        <vers num="5.1" edition="p11"/>
        <vers num="5.1" edition="p12"/>
        <vers num="5.1" edition="p14"/>
        <vers num="5.1" edition="p15"/>
        <vers num="5.1" edition="p16"/>
        <vers num="5.1" edition="p17"/>
        <vers num="5.1" edition="p18"/>
        <vers num="5.1" edition="p4"/>
        <vers num="5.1" edition="p5"/>
        <vers num="5.1" edition="p7"/>
        <vers num="5.1" edition="p8"/>
        <vers num="5.1" edition="p9"/>
        <vers num="5.2" edition="-"/>
        <vers num="5.2" edition="p1"/>
        <vers num="5.2" edition="p2"/>
        <vers num="5.2.1" edition="-"/>
        <vers num="5.2.1" edition="p10"/>
        <vers num="5.2.1" edition="p11"/>
        <vers num="5.2.1" edition="p12"/>
        <vers num="5.2.1" edition="p13"/>
        <vers num="5.2.1" edition="p2"/>
        <vers num="5.2.1" edition="p3"/>
        <vers num="5.2.1" edition="p4"/>
        <vers num="5.2.1" edition="p5"/>
        <vers num="5.2.1" edition="p6"/>
        <vers num="5.2.1" edition="p7"/>
        <vers num="5.2.1" edition="p8"/>
        <vers num="5.2.1" edition="p9"/>
        <vers num="5.2.1" edition="rc2"/>
        <vers num="5.3" edition="-"/>
        <vers num="5.3" edition="beta6"/>
        <vers num="5.3" edition="p1"/>
        <vers num="5.3" edition="p10"/>
        <vers num="5.3" edition="p11"/>
        <vers num="5.3" edition="p12"/>
        <vers num="5.3" edition="p14"/>
        <vers num="5.3" edition="p15"/>
        <vers num="5.3" edition="p16"/>
        <vers num="5.3" edition="p17"/>
        <vers num="5.3" edition="p18"/>
        <vers num="5.3" edition="p19"/>
        <vers num="5.3" edition="p2"/>
        <vers num="5.3" edition="p22"/>
        <vers num="5.3" edition="p23"/>
        <vers num="5.3" edition="p24"/>
        <vers num="5.3" edition="p25"/>
        <vers num="5.3" edition="p26"/>
        <vers num="5.3" edition="p27"/>
        <vers num="5.3" edition="p28"/>
        <vers num="5.3" edition="p29"/>
        <vers num="5.3" edition="p30"/>
        <vers num="5.3" edition="p31"/>
        <vers num="5.3" edition="p32"/>
        <vers num="5.3" edition="p33"/>
        <vers num="5.3" edition="p34"/>
        <vers num="5.3" edition="p36"/>
        <vers num="5.3" edition="p37"/>
        <vers num="5.3" edition="p6"/>
        <vers num="5.3" edition="p7"/>
        <vers num="5.3" edition="p8"/>
        <vers num="5.3" edition="p9"/>
        <vers num="5.4" edition="-"/>
        <vers num="5.4" edition="p1"/>
        <vers num="5.4" edition="p10"/>
        <vers num="5.4" edition="p11"/>
        <vers num="5.4" edition="p12"/>
        <vers num="5.4" edition="p13"/>
        <vers num="5.4" edition="p14"/>
        <vers num="5.4" edition="p15"/>
        <vers num="5.4" edition="p16"/>
        <vers num="5.4" edition="p17"/>
        <vers num="5.4" edition="p18"/>
        <vers num="5.4" edition="p19"/>
        <vers num="5.4" edition="p2"/>
        <vers num="5.4" edition="p21"/>
        <vers num="5.4" edition="p22"/>
        <vers num="5.4" edition="p3"/>
        <vers num="5.4" edition="p4"/>
        <vers num="5.4" edition="p5"/>
        <vers num="5.4" edition="p7"/>
        <vers num="5.4" edition="p8"/>
        <vers num="5.4" edition="p9"/>
        <vers num="5.5" edition="-"/>
        <vers num="5.5" edition="p1"/>
        <vers num="5.5" edition="p11"/>
        <vers num="5.5" edition="p12"/>
        <vers num="5.5" edition="p13"/>
        <vers num="5.5" edition="p14"/>
        <vers num="5.5" edition="p15"/>
        <vers num="5.5" edition="p16"/>
        <vers num="5.5" edition="p17"/>
        <vers num="5.5" edition="p18"/>
        <vers num="5.5" edition="p19"/>
        <vers num="5.5" edition="p2"/>
        <vers num="5.5" edition="p20"/>
        <vers num="5.5" edition="p3"/>
        <vers num="5.5" edition="p4"/>
        <vers num="5.5" edition="p5"/>
        <vers num="5.5" edition="p7"/>
        <vers num="5.5" edition="p8"/>
        <vers num="5.5" edition="p9"/>
        <vers num="6.0" edition="-"/>
        <vers num="6.0" edition="beta5"/>
        <vers num="6.0" edition="p10"/>
        <vers num="6.0" edition="p11"/>
        <vers num="6.0" edition="p12"/>
        <vers num="6.0" edition="p14"/>
        <vers num="6.0" edition="p15"/>
        <vers num="6.0" edition="p16"/>
        <vers num="6.0" edition="p17"/>
        <vers num="6.0" edition="p2"/>
        <vers num="6.0" edition="p3"/>
        <vers num="6.0" edition="p4"/>
        <vers num="6.0" edition="p5"/>
        <vers num="6.0" edition="p6"/>
        <vers num="6.0" edition="p7"/>
        <vers num="6.0" edition="p8"/>
        <vers num="6.0" edition="p9"/>
        <vers num="6.1" edition="-"/>
        <vers num="6.1" edition="p1"/>
        <vers num="6.1" edition="p10"/>
        <vers num="6.1" edition="p11"/>
        <vers num="6.1" edition="p12"/>
        <vers num="6.1" edition="p13"/>
        <vers num="6.1" edition="p16"/>
        <vers num="6.1" edition="p17"/>
        <vers num="6.1" edition="p18"/>
        <vers num="6.1" edition="p19"/>
        <vers num="6.1" edition="p2"/>
        <vers num="6.1" edition="p20"/>
        <vers num="6.1" edition="p21"/>
        <vers num="6.1" edition="p22"/>
        <vers num="6.1" edition="p23"/>
        <vers num="6.1" edition="p24"/>
        <vers num="6.1" edition="p4"/>
        <vers num="6.1" edition="p6"/>
        <vers num="6.1" edition="p7"/>
        <vers num="6.1" edition="p9"/>
        <vers num="6.2" edition="-"/>
        <vers num="6.2" edition="p1"/>
        <vers num="6.2" edition="p10"/>
        <vers num="6.2" edition="p11"/>
        <vers num="6.2" edition="p12"/>
        <vers num="6.2" edition="p4"/>
        <vers num="6.2" edition="p5"/>
        <vers num="6.2" edition="p6"/>
        <vers num="6.2" edition="p7"/>
        <vers num="6.2" edition="p8"/>
        <vers num="6.2" edition="p9"/>
        <vers num="6.2" edition="rc1"/>
        <vers num="6.2" edition="rc2"/>
        <vers num="6.3" edition="-"/>
        <vers num="6.3" edition="p1"/>
        <vers num="6.3" edition="p10"/>
        <vers num="6.3" edition="p11"/>
        <vers num="6.3" edition="p12"/>
        <vers num="6.3" edition="p13"/>
        <vers num="6.3" edition="p14"/>
        <vers num="6.3" edition="p15"/>
        <vers num="6.3" edition="p2"/>
        <vers num="6.3" edition="p3"/>
        <vers num="6.3" edition="p4"/>
        <vers num="6.3" edition="p5"/>
        <vers num="6.3" edition="p6"/>
        <vers num="6.3" edition="p7"/>
        <vers num="6.3" edition="p8"/>
        <vers num="6.3" edition="p9"/>
        <vers num="6.3" edition="rc2"/>
        <vers num="6.4" edition="-"/>
        <vers num="6.4" edition="p1"/>
        <vers num="6.4" edition="p10"/>
        <vers num="6.4" edition="p11"/>
        <vers num="6.4" edition="p2"/>
        <vers num="6.4" edition="p3"/>
        <vers num="6.4" edition="p4"/>
        <vers num="6.4" edition="p5"/>
        <vers num="6.4" edition="p6"/>
        <vers num="6.4" edition="p7"/>
        <vers num="6.4" edition="p8"/>
        <vers num="6.4" edition="p9"/>
        <vers num="7.0" edition="-"/>
        <vers num="7.0" edition="beta4"/>
        <vers num="7.0" edition="p1"/>
        <vers num="7.0" edition="p10"/>
        <vers num="7.0" edition="p11"/>
        <vers num="7.0" edition="p12"/>
        <vers num="7.0" edition="p3"/>
        <vers num="7.0" edition="p4"/>
        <vers num="7.0" edition="p5"/>
        <vers num="7.0" edition="p6"/>
        <vers num="7.0" edition="p7"/>
        <vers num="7.0" edition="p8"/>
        <vers num="7.0" edition="p9"/>
        <vers num="7.0" edition="rc2"/>
        <vers num="7.1" edition="-"/>
        <vers num="7.1" edition="p1"/>
        <vers num="7.1" edition="p10"/>
        <vers num="7.1" edition="p12"/>
        <vers num="7.1" edition="p13"/>
        <vers num="7.1" edition="p14"/>
        <vers num="7.1" edition="p15"/>
        <vers num="7.1" edition="p16"/>
        <vers num="7.1" edition="p2"/>
        <vers num="7.1" edition="p3"/>
        <vers num="7.1" edition="p4"/>
        <vers num="7.1" edition="p5"/>
        <vers num="7.1" edition="p6"/>
        <vers num="7.1" edition="p7"/>
        <vers num="7.1" edition="p8"/>
        <vers num="7.1" edition="p9"/>
        <vers num="7.1" edition="rc1"/>
        <vers num="7.1" edition="rc2"/>
        <vers num="7.2" edition="-"/>
        <vers num="7.2" edition="p1"/>
        <vers num="7.2" edition="p3"/>
        <vers num="7.2" edition="p4"/>
        <vers num="7.2" edition="p5"/>
        <vers num="7.2" edition="p6"/>
        <vers num="7.2" edition="p8"/>
        <vers num="7.2" edition="rc2"/>
        <vers num="7.3" edition="-"/>
        <vers num="7.3" edition="p1"/>
        <vers num="7.3" edition="p2"/>
        <vers num="7.3" edition="p3"/>
        <vers num="7.3" edition="p4"/>
        <vers num="7.3" edition="p5"/>
        <vers num="7.3" edition="p6"/>
        <vers num="7.3" edition="p7"/>
        <vers num="7.3" edition="p8"/>
        <vers num="7.3" edition="p9"/>
        <vers num="7.4" edition="-"/>
        <vers num="7.4" edition="p1"/>
        <vers num="7.4" edition="p10"/>
        <vers num="7.4" edition="p11"/>
        <vers num="7.4" edition="p12"/>
        <vers num="7.4" edition="p2"/>
        <vers num="7.4" edition="p3"/>
        <vers num="7.4" edition="p4"/>
        <vers num="7.4" edition="p5"/>
        <vers num="7.4" edition="p8"/>
        <vers num="7.4" edition="p9"/>
        <vers num="8.0" edition="-"/>
        <vers num="8.0" edition="p1"/>
        <vers num="8.0" edition="p2"/>
        <vers num="8.0" edition="p3"/>
        <vers num="8.0" edition="p4"/>
        <vers num="8.0" edition="p5"/>
        <vers num="8.0" edition="p6"/>
        <vers num="8.0" edition="rc1"/>
        <vers num="8.1" edition="-"/>
        <vers num="8.1" edition="p1"/>
        <vers num="8.1" edition="p10"/>
        <vers num="8.1" edition="p11"/>
        <vers num="8.1" edition="p12"/>
        <vers num="8.1" edition="p13"/>
        <vers num="8.1" edition="p2"/>
        <vers num="8.1" edition="p3"/>
        <vers num="8.1" edition="p4"/>
        <vers num="8.1" edition="p5"/>
        <vers num="8.1" edition="p6"/>
        <vers num="8.1" edition="p7"/>
        <vers num="8.2" edition="-"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2" edition="p10"/>
        <vers num="8.2" edition="p2"/>
        <vers num="8.2" edition="p3"/>
        <vers num="8.2" edition="p4"/>
        <vers num="8.2" edition="p5"/>
        <vers num="8.2" edition="p8"/>
        <vers num="8.2" edition="p9"/>
        <vers num="8.3" edition="-"/>
        <vers num="8.3" edition="p10"/>
        <vers num="8.3" edition="p11"/>
        <vers num="8.3" edition="p14"/>
        <vers num="8.3" edition="p15"/>
        <vers num="8.3" edition="p16"/>
        <vers num="8.3" edition="p2"/>
        <vers num="8.3" edition="p3"/>
        <vers num="8.3" edition="p4"/>
        <vers num="8.3" edition="p5"/>
        <vers num="8.3" edition="p6"/>
        <vers num="8.3" edition="p7"/>
        <vers num="8.3" edition="p8"/>
        <vers num="8.3" edition="p9"/>
        <vers num="8.4" edition="-"/>
        <vers num="8.4" edition="beta1"/>
        <vers num="8.4" edition="p11"/>
        <vers num="8.4" edition="p12"/>
        <vers num="8.4" edition="p13"/>
        <vers num="8.4" edition="p14"/>
        <vers num="8.4" edition="p15"/>
        <vers num="8.4" edition="p16"/>
        <vers num="8.4" edition="p17"/>
        <vers num="8.4" edition="p19"/>
        <vers num="8.4" edition="p2"/>
        <vers num="8.4" edition="p20"/>
        <vers num="8.4" edition="p21"/>
        <vers num="8.4" edition="p22"/>
        <vers num="8.4" edition="p23"/>
        <vers num="8.4" edition="p24"/>
        <vers num="8.4" edition="p26"/>
        <vers num="8.4" edition="p27"/>
        <vers num="8.4" edition="p3"/>
        <vers num="8.4" edition="p30"/>
        <vers num="8.4" edition="p33"/>
        <vers num="8.4" edition="p34"/>
        <vers num="8.4" edition="p35"/>
        <vers num="8.4" edition="p36"/>
        <vers num="8.4" edition="p4"/>
        <vers num="8.4" edition="p7"/>
        <vers num="8.4" edition="p8"/>
        <vers num="8.4" edition="p9"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="p2"/>
        <vers num="9.0" edition="p3"/>
        <vers num="9.0" edition="p4"/>
        <vers num="9.0" edition="p5"/>
        <vers num="9.0" edition="p6"/>
        <vers num="9.0" edition="p7"/>
        <vers num="9.0" edition="rc1"/>
        <vers num="9.0" edition="rc3"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="p1"/>
        <vers num="9.1" edition="p10"/>
        <vers num="9.1" edition="p11"/>
        <vers num="9.1" edition="p12"/>
        <vers num="9.1" edition="p14"/>
        <vers num="9.1" edition="p15"/>
        <vers num="9.1" edition="p16"/>
        <vers num="9.1" edition="p17"/>
        <vers num="9.1" edition="p18"/>
        <vers num="9.1" edition="p19"/>
        <vers num="9.1" edition="p2"/>
        <vers num="9.1" edition="p20"/>
        <vers num="9.1" edition="p22"/>
        <vers num="9.1" edition="p23"/>
        <vers num="9.1" edition="p24"/>
        <vers num="9.1" edition="p3"/>
        <vers num="9.1" edition="p4"/>
        <vers num="9.1" edition="p5"/>
        <vers num="9.1" edition="p6"/>
        <vers num="9.1" edition="p7"/>
        <vers num="9.1" edition="rc2"/>
        <vers num="9.1" edition="release-p4"/>
        <vers num="9.1" edition="release-p5"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.2" edition="beta2"/>
        <vers num="9.2" edition="p10"/>
        <vers num="9.2" edition="p11"/>
        <vers num="9.2" edition="p12"/>
        <vers num="9.2" edition="p13"/>
        <vers num="9.2" edition="p15"/>
        <vers num="9.2" edition="p16"/>
        <vers num="9.2" edition="p17"/>
        <vers num="9.2" edition="p3"/>
        <vers num="9.2" edition="p4"/>
        <vers num="9.2" edition="p5"/>
        <vers num="9.2" edition="p7"/>
        <vers num="9.2" edition="p8"/>
        <vers num="9.2" edition="p9"/>
        <vers num="9.2" edition="prerelease"/>
        <vers num="9.2" edition="rc1"/>
        <vers num="9.2" edition="rc2"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="p1"/>
        <vers num="9.3" edition="p10"/>
        <vers num="9.3" edition="p12"/>
        <vers num="9.3" edition="p13"/>
        <vers num="9.3" edition="p16"/>
        <vers num="9.3" edition="p19"/>
        <vers num="9.3" edition="p2"/>
        <vers num="9.3" edition="p20"/>
        <vers num="9.3" edition="p21"/>
        <vers num="9.3" edition="p22"/>
        <vers num="9.3" edition="p23"/>
        <vers num="9.3" edition="p24"/>
        <vers num="9.3" edition="p25"/>
        <vers num="9.3" edition="p28"/>
        <vers num="9.3" edition="p3"/>
        <vers num="9.3" edition="p30"/>
        <vers num="9.3" edition="p31"/>
        <vers num="9.3" edition="p32"/>
        <vers num="9.3" edition="p33"/>
        <vers num="9.3" edition="p34"/>
        <vers num="9.3" edition="p35"/>
        <vers num="9.3" edition="p36"/>
        <vers num="9.3" edition="p38"/>
        <vers num="9.3" edition="p39"/>
        <vers num="9.3" edition="p40"/>
        <vers num="9.3" edition="p41"/>
        <vers num="9.3" edition="p42"/>
        <vers num="9.3" edition="p43"/>
        <vers num="9.3" edition="p44"/>
        <vers num="9.3" edition="p45"/>
        <vers num="9.3" edition="p47"/>
        <vers num="9.3" edition="p48"/>
        <vers num="9.3" edition="p49"/>
        <vers num="9.3" edition="p5"/>
        <vers num="9.3" edition="p50"/>
        <vers num="9.3" edition="p51"/>
        <vers num="9.3" edition="p52"/>
        <vers num="9.3" edition="p53"/>
        <vers num="9.3" edition="p6"/>
        <vers num="9.3" edition="p7"/>
        <vers num="9.3" edition="p8"/>
        <vers num="9.3" edition="p9"/>
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="p1"/>
        <vers num="10.0" edition="p10"/>
        <vers num="10.0" edition="p12"/>
        <vers num="10.0" edition="p13"/>
        <vers num="10.0" edition="p14"/>
        <vers num="10.0" edition="p15"/>
        <vers num="10.0" edition="p16"/>
        <vers num="10.0" edition="p17"/>
        <vers num="10.0" edition="p2"/>
        <vers num="10.0" edition="p3"/>
        <vers num="10.0" edition="p4"/>
        <vers num="10.0" edition="p5"/>
        <vers num="10.0" edition="p6"/>
        <vers num="10.0" edition="p7"/>
        <vers num="10.0" edition="p8"/>
        <vers num="10.0" edition="p9"/>
        <vers num="10.1" edition="-"/>
        <vers num="10.1" edition="p1"/>
        <vers num="10.1" edition="p10"/>
        <vers num="10.1" edition="p12"/>
        <vers num="10.1" edition="p15"/>
        <vers num="10.1" edition="p16"/>
        <vers num="10.1" edition="p17"/>
        <vers num="10.1" edition="p18"/>
        <vers num="10.1" edition="p19"/>
        <vers num="10.1" edition="p2"/>
        <vers num="10.1" edition="p22"/>
        <vers num="10.1" edition="p24"/>
        <vers num="10.1" edition="p25"/>
        <vers num="10.1" edition="p26"/>
        <vers num="10.1" edition="p27"/>
        <vers num="10.1" edition="p28"/>
        <vers num="10.1" edition="p29"/>
        <vers num="10.1" edition="p3"/>
        <vers num="10.1" edition="p30"/>
        <vers num="10.1" edition="p31"/>
        <vers num="10.1" edition="p32"/>
        <vers num="10.1" edition="p33"/>
        <vers num="10.1" edition="p34"/>
        <vers num="10.1" edition="p35"/>
        <vers num="10.1" edition="p36"/>
        <vers num="10.1" edition="p37"/>
        <vers num="10.1" edition="p39"/>
        <vers num="10.1" edition="p4"/>
        <vers num="10.1" edition="p40"/>
        <vers num="10.1" edition="p41"/>
        <vers num="10.1" edition="p42"/>
        <vers num="10.1" edition="p43"/>
        <vers num="10.1" edition="p44"/>
        <vers num="10.1" edition="p45"/>
        <vers num="10.1" edition="p5"/>
        <vers num="10.1" edition="p6"/>
        <vers num="10.1" edition="p7"/>
        <vers num="10.1" edition="p8"/>
        <vers num="10.1" edition="p9"/>
        <vers num="10.2" edition="-"/>
        <vers num="10.2" edition="p1"/>
        <vers num="10.2" edition="p10"/>
        <vers num="10.2" edition="p11"/>
        <vers num="10.2" edition="p12"/>
        <vers num="10.2" edition="p13"/>
        <vers num="10.2" edition="p14"/>
        <vers num="10.2" edition="p15"/>
        <vers num="10.2" edition="p16"/>
        <vers num="10.2" edition="p17"/>
        <vers num="10.2" edition="p18"/>
        <vers num="10.2" edition="p19"/>
        <vers num="10.2" edition="p2"/>
        <vers num="10.2" edition="p20"/>
        <vers num="10.2" edition="p22"/>
        <vers num="10.2" edition="p23"/>
        <vers num="10.2" edition="p24"/>
        <vers num="10.2" edition="p25"/>
        <vers num="10.2" edition="p26"/>
        <vers num="10.2" edition="p27"/>
        <vers num="10.2" edition="p28"/>
        <vers num="10.2" edition="p5"/>
        <vers num="10.2" edition="p7"/>
        <vers num="10.2" edition="p8"/>
        <vers num="10.2" edition="p9"/>
        <vers num="10.3" edition="-"/>
        <vers num="10.3" edition="p1"/>
        <vers num="10.3" edition="p10"/>
        <vers num="10.3" edition="p11"/>
        <vers num="10.3" edition="p12"/>
        <vers num="10.3" edition="p13"/>
        <vers num="10.3" edition="p14"/>
        <vers num="10.3" edition="p15"/>
        <vers num="10.3" edition="p16"/>
        <vers num="10.3" edition="p17"/>
        <vers num="10.3" edition="p18"/>
        <vers num="10.3" edition="p19"/>
        <vers num="10.3" edition="p2"/>
        <vers num="10.3" edition="p20"/>
        <vers num="10.3" edition="p21"/>
        <vers num="10.3" edition="p22"/>
        <vers num="10.3" edition="p24"/>
        <vers num="10.3" edition="p25"/>
        <vers num="10.3" edition="p26"/>
        <vers num="10.3" edition="p27"/>
        <vers num="10.3" edition="p28"/>
        <vers num="10.3" edition="p29"/>
        <vers num="10.3" edition="p3"/>
        <vers num="10.3" edition="p4"/>
        <vers num="10.3" edition="p5"/>
        <vers num="10.3" edition="p6"/>
        <vers num="10.3" edition="p9"/>
        <vers num="10.3" edition="rc2"/>
        <vers num="10.4" edition="-"/>
        <vers num="10.4" edition="p1"/>
        <vers num="10.4" edition="p11"/>
        <vers num="10.4" edition="p12"/>
        <vers num="10.4" edition="p13"/>
        <vers num="10.4" edition="p3"/>
        <vers num="10.4" edition="p4"/>
        <vers num="10.4" edition="p5"/>
        <vers num="10.4" edition="p6"/>
        <vers num="10.4" edition="p7"/>
        <vers num="10.4" edition="p8"/>
        <vers num="10.4" edition="p9"/>
        <vers num="11.0" edition="-"/>
        <vers num="11.0" edition="p1"/>
        <vers num="11.0" edition="p10"/>
        <vers num="11.0" edition="p11"/>
        <vers num="11.0" edition="p12"/>
        <vers num="11.0" edition="p13"/>
        <vers num="11.0" edition="p15"/>
        <vers num="11.0" edition="p16"/>
        <vers num="11.0" edition="p2"/>
        <vers num="11.0" edition="p3"/>
        <vers num="11.0" edition="p4"/>
        <vers num="11.0" edition="p5"/>
        <vers num="11.0" edition="p6"/>
        <vers num="11.0" edition="p7"/>
        <vers num="11.0" edition="p8"/>
        <vers num="11.0" edition="p9"/>
        <vers num="11.1" edition="-"/>
        <vers num="11.1" edition="p1"/>
        <vers num="11.1" edition="p11"/>
        <vers num="11.1" edition="p13"/>
        <vers num="11.1" edition="p14"/>
        <vers num="11.1" edition="p15"/>
        <vers num="11.1" edition="p2"/>
        <vers num="11.1" edition="p4"/>
        <vers num="11.1" edition="p5"/>
        <vers num="11.1" edition="p6"/>
        <vers num="11.1" edition="p7"/>
        <vers num="11.1" edition="p9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10840" seq="2017-10840" published="2017-08-28" modified="2017-08-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/craigk5n/webcalendar/releases/tag/v1.2.8" adv="1" patch="1">https://github.com/craigk5n/webcalendar/releases/tag/v1.2.8</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN23340457/index.html" adv="1">JVN#23340457</ref>
    </refs>
    <vuln_soft>
      <prod name="webcalendar" vendor="webcalendar_project">
        <vers num="1.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10841" seq="2017-10841" published="2017-08-28" modified="2017-08-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/craigk5n/webcalendar/releases/tag/v1.2.8" adv="1" patch="1">https://github.com/craigk5n/webcalendar/releases/tag/v1.2.8</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN23340457/index.html" adv="1">JVN#23340457</ref>
    </refs>
    <vuln_soft>
      <prod name="webcalendar" vendor="webcalendar_project">
        <vers num="1.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10842" seq="2017-10842" published="2017-08-28" modified="2019-03-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN78151490/index.html" adv="1">JVN#78151490</ref>
      <ref source="MISC" url="https://basercms.net/security/JVN78151490" adv="1" patch="1">https://basercms.net/security/JVN78151490</ref>
    </refs>
    <vuln_soft>
      <prod name="basercms" vendor="basercms">
        <vers num="3.0.0"/>
        <vers num="3.0.0.1"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2.1"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3.1"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4.1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5.1"/>
        <vers num="3.0.5.2"/>
        <vers num="3.0.6" edition="-"/>
        <vers num="3.0.6" edition="beta"/>
        <vers num="3.0.6.1"/>
        <vers num="3.0.6.2"/>
        <vers num="3.0.7"/>
        <vers num="3.0.7.1"/>
        <vers num="3.0.8"/>
        <vers num="3.0.8.1"/>
        <vers num="3.0.9"/>
        <vers num="3.0.9.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.10.1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.11.1"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.2.1"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10843" seq="2017-10843" published="2017-08-28" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN78151490/index.html" adv="1">JVN#78151490</ref>
      <ref source="MISC" url="https://basercms.net/security/JVN78151490" adv="1" patch="1">https://basercms.net/security/JVN78151490</ref>
    </refs>
    <vuln_soft>
      <prod name="basercms" vendor="basercms">
        <vers num="3.0.0"/>
        <vers num="3.0.0.1"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2.1"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3.1"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4.1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5.1"/>
        <vers num="3.0.5.2"/>
        <vers num="3.0.6" edition="-"/>
        <vers num="3.0.6" edition="beta"/>
        <vers num="3.0.6.1"/>
        <vers num="3.0.6.2"/>
        <vers num="3.0.7"/>
        <vers num="3.0.7.1"/>
        <vers num="3.0.8"/>
        <vers num="3.0.8.1"/>
        <vers num="3.0.9"/>
        <vers num="3.0.9.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.10.1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.11.1"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.2.1"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10844" seq="2017-10844" published="2017-08-28" modified="2019-03-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN78151490/index.html" adv="1">JVN#78151490</ref>
      <ref source="MISC" url="https://basercms.net/security/JVN78151490" adv="1" patch="1">https://basercms.net/security/JVN78151490</ref>
    </refs>
    <vuln_soft>
      <prod name="basercms" vendor="basercms">
        <vers num="3.0.0"/>
        <vers num="3.0.0.1"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2.1"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3.1"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4.1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.5.1"/>
        <vers num="3.0.5.2"/>
        <vers num="3.0.6" edition="-"/>
        <vers num="3.0.6" edition="beta"/>
        <vers num="3.0.6.1"/>
        <vers num="3.0.6.2"/>
        <vers num="3.0.7"/>
        <vers num="3.0.7.1"/>
        <vers num="3.0.8"/>
        <vers num="3.0.8.1"/>
        <vers num="3.0.9"/>
        <vers num="3.0.9.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.10.1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.11.1"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="beta"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.2.1"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10845" seq="2017-10845" published="2017-09-15" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en//jp/JVN68922465/index.html" adv="1">JVN#68922465</ref>
      <ref source="MISC" url="https://www.nttdocomo.co.jp/info/notice/page/170710_01_m.html" adv="1">https://www.nttdocomo.co.jp/info/notice/page/170710_01_m.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wi-fi_station_l-02f_firmware" vendor="nttdocomo">
        <vers num="v10g" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10846" seq="2017-10846" published="2017-09-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN03044183/index.html" adv="1">JVN#03044183</ref>
      <ref source="MISC" url="https://www.nttdocomo.co.jp/info/notice/page/170710_01_m.html" adv="1">https://www.nttdocomo.co.jp/info/notice/page/170710_01_m.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wi-fi_station_l-02f_firmware" vendor="nttdocomo">
        <vers num="v10b" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10848" seq="2017-10848" published="2017-09-01" modified="2017-09-06" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published in Jul 2017 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html" adv="1">http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN09769017/index.html" adv="1">JVN#09769017</ref>
    </refs>
    <vuln_soft>
      <prod name="docuworks" vendor="fujixerox">
        <vers num="8.0.7" prev="1"/>
      </prod>
      <prod name="docuworks_viewer_light" vendor="fujixerox">
        <vers num="8.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10849" seq="2017-10849" published="2017-09-01" modified="2017-09-05" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html" adv="1">http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN09769017/index.html" adv="1">JVN#09769017</ref>
    </refs>
    <vuln_soft>
      <prod name="docuworks" vendor="fujixerox">
        <vers num="8.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1085" seq="2017-1085" published="2018-09-12" modified="2018-11-23" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42279/" adv="1">42279</ref>
      <ref source="MISC" url="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt" adv="1">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
        <vers num="0.4_1"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5.1"/>
        <vers num="1.2"/>
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3" edition="-"/>
        <vers num="3.3" edition="rc"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3" edition="-"/>
        <vers num="4.3" edition="p24"/>
        <vers num="4.3" edition="p37"/>
        <vers num="4.3" edition="p38"/>
        <vers num="4.3" edition="p40"/>
        <vers num="4.3" edition="p41"/>
        <vers num="4.3" edition="p42"/>
        <vers num="4.3" edition="rc"/>
        <vers num="4.4" edition="-"/>
        <vers num="4.4" edition="p27"/>
        <vers num="4.4" edition="p4"/>
        <vers num="4.4" edition="p41"/>
        <vers num="4.4" edition="p42"/>
        <vers num="4.4" edition="p44"/>
        <vers num="4.4" edition="p45"/>
        <vers num="4.4" edition="p46"/>
        <vers num="4.4" edition="p47"/>
        <vers num="4.4" edition="p8"/>
        <vers num="4.5" edition="-"/>
        <vers num="4.5" edition="p1"/>
        <vers num="4.5" edition="p20"/>
        <vers num="4.5" edition="p31"/>
        <vers num="4.5" edition="p32"/>
        <vers num="4.5" edition="p34"/>
        <vers num="4.5" edition="p35"/>
        <vers num="4.5" edition="p36"/>
        <vers num="4.5" edition="p37"/>
        <vers num="4.6" edition="-"/>
        <vers num="4.6" edition="p11"/>
        <vers num="4.6" edition="p12"/>
        <vers num="4.6" edition="p16"/>
        <vers num="4.6" edition="p19"/>
        <vers num="4.6" edition="p20"/>
        <vers num="4.6" edition="p23"/>
        <vers num="4.6" edition="p24"/>
        <vers num="4.6" edition="p25"/>
        <vers num="4.6" edition="p7"/>
        <vers num="4.6.1" edition="-"/>
        <vers num="4.6.1" edition="p1"/>
        <vers num="4.6.1" edition="p10"/>
        <vers num="4.6.1" edition="p4"/>
        <vers num="4.6.1" edition="p5"/>
        <vers num="4.6.1" edition="p7"/>
        <vers num="4.6.1" edition="p9"/>
        <vers num="4.6.2" edition="-"/>
        <vers num="4.6.2" edition="p2"/>
        <vers num="4.6.2" edition="p22"/>
        <vers num="4.6.2" edition="p26"/>
        <vers num="4.6.2" edition="p27"/>
        <vers num="4.6.2" edition="p8"/>
        <vers num="4.6.2" edition="p9"/>
        <vers num="4.7" edition="-"/>
        <vers num="4.7" edition="p13"/>
        <vers num="4.7" edition="p16"/>
        <vers num="4.7" edition="p17"/>
        <vers num="4.7" edition="p19"/>
        <vers num="4.7" edition="p20"/>
        <vers num="4.7" edition="p21"/>
        <vers num="4.7" edition="p22"/>
        <vers num="4.7" edition="p23"/>
        <vers num="4.7" edition="p24"/>
        <vers num="4.7" edition="p25"/>
        <vers num="4.7" edition="p26"/>
        <vers num="4.7" edition="p27"/>
        <vers num="4.7" edition="p28"/>
        <vers num="4.7" edition="p4"/>
        <vers num="4.7" edition="p5"/>
        <vers num="4.7" edition="p6"/>
        <vers num="4.7" edition="p8"/>
        <vers num="4.7" edition="p9"/>
        <vers num="4.8" edition="-"/>
        <vers num="4.8" edition="p1"/>
        <vers num="4.8" edition="p10"/>
        <vers num="4.8" edition="p11"/>
        <vers num="4.8" edition="p12"/>
        <vers num="4.8" edition="p13"/>
        <vers num="4.8" edition="p14"/>
        <vers num="4.8" edition="p15"/>
        <vers num="4.8" edition="p16"/>
        <vers num="4.8" edition="p17"/>
        <vers num="4.8" edition="p18"/>
        <vers num="4.8" edition="p19"/>
        <vers num="4.8" edition="p2"/>
        <vers num="4.8" edition="p20"/>
        <vers num="4.8" edition="p21"/>
        <vers num="4.8" edition="p22"/>
        <vers num="4.8" edition="p23"/>
        <vers num="4.8" edition="p24"/>
        <vers num="4.8" edition="p25"/>
        <vers num="4.8" edition="p26"/>
        <vers num="4.8" edition="p27"/>
        <vers num="4.8" edition="p28"/>
        <vers num="4.8" edition="p29"/>
        <vers num="4.8" edition="p3"/>
        <vers num="4.8" edition="p6"/>
        <vers num="4.8" edition="p7"/>
        <vers num="4.8" edition="p9"/>
        <vers num="4.9" edition="-"/>
        <vers num="4.9" edition="p1"/>
        <vers num="4.9" edition="p10"/>
        <vers num="4.9" edition="p11"/>
        <vers num="4.9" edition="p12"/>
        <vers num="4.9" edition="p13"/>
        <vers num="4.9" edition="p2"/>
        <vers num="4.9" edition="p3"/>
        <vers num="4.9" edition="p4"/>
        <vers num="4.9" edition="p5"/>
        <vers num="4.9" edition="p6"/>
        <vers num="4.9" edition="p7"/>
        <vers num="4.9" edition="p8"/>
        <vers num="4.9" edition="p9"/>
        <vers num="4.9" edition="rc"/>
        <vers num="4.10" edition="-"/>
        <vers num="4.10" edition="p10"/>
        <vers num="4.10" edition="p11"/>
        <vers num="4.10" edition="p13"/>
        <vers num="4.10" edition="p14"/>
        <vers num="4.10" edition="p15"/>
        <vers num="4.10" edition="p16"/>
        <vers num="4.10" edition="p18"/>
        <vers num="4.10" edition="p19"/>
        <vers num="4.10" edition="p2"/>
        <vers num="4.10" edition="p20"/>
        <vers num="4.10" edition="p21"/>
        <vers num="4.10" edition="p22"/>
        <vers num="4.10" edition="p23"/>
        <vers num="4.10" edition="p24"/>
        <vers num="4.10" edition="p3"/>
        <vers num="4.10" edition="p4"/>
        <vers num="4.10" edition="p5"/>
        <vers num="4.10" edition="p7"/>
        <vers num="4.10" edition="p8"/>
        <vers num="4.10" edition="p9"/>
        <vers num="4.10" edition="rc"/>
        <vers num="4.11" edition="-"/>
        <vers num="4.11" edition="p1"/>
        <vers num="4.11" edition="p10"/>
        <vers num="4.11" edition="p11"/>
        <vers num="4.11" edition="p12"/>
        <vers num="4.11" edition="p13"/>
        <vers num="4.11" edition="p14"/>
        <vers num="4.11" edition="p15"/>
        <vers num="4.11" edition="p16"/>
        <vers num="4.11" edition="p17"/>
        <vers num="4.11" edition="p18"/>
        <vers num="4.11" edition="p19"/>
        <vers num="4.11" edition="p2"/>
        <vers num="4.11" edition="p20"/>
        <vers num="4.11" edition="p21"/>
        <vers num="4.11" edition="p22"/>
        <vers num="4.11" edition="p24"/>
        <vers num="4.11" edition="p25"/>
        <vers num="4.11" edition="p26"/>
        <vers num="4.11" edition="p3"/>
        <vers num="4.11" edition="p4"/>
        <vers num="4.11" edition="p5"/>
        <vers num="4.11" edition="p6"/>
        <vers num="4.11" edition="p8"/>
        <vers num="4.11" edition="p9"/>
        <vers num="5.0" edition="-"/>
        <vers num="5.0" edition="p1"/>
        <vers num="5.0" edition="p11"/>
        <vers num="5.0" edition="p13"/>
        <vers num="5.0" edition="p14"/>
        <vers num="5.0" edition="p16"/>
        <vers num="5.0" edition="p17"/>
        <vers num="5.0" edition="p18"/>
        <vers num="5.0" edition="p19"/>
        <vers num="5.0" edition="p2"/>
        <vers num="5.0" edition="p20"/>
        <vers num="5.0" edition="p21"/>
        <vers num="5.0" edition="p22"/>
        <vers num="5.0" edition="p3"/>
        <vers num="5.0" edition="p4"/>
        <vers num="5.0" edition="p5"/>
        <vers num="5.0" edition="p6"/>
        <vers num="5.0" edition="p7"/>
        <vers num="5.1" edition="-"/>
        <vers num="5.1" edition="p1"/>
        <vers num="5.1" edition="p10"/>
        <vers num="5.1" edition="p11"/>
        <vers num="5.1" edition="p12"/>
        <vers num="5.1" edition="p14"/>
        <vers num="5.1" edition="p15"/>
        <vers num="5.1" edition="p16"/>
        <vers num="5.1" edition="p17"/>
        <vers num="5.1" edition="p18"/>
        <vers num="5.1" edition="p4"/>
        <vers num="5.1" edition="p5"/>
        <vers num="5.1" edition="p7"/>
        <vers num="5.1" edition="p8"/>
        <vers num="5.1" edition="p9"/>
        <vers num="5.2" edition="-"/>
        <vers num="5.2" edition="p1"/>
        <vers num="5.2" edition="p2"/>
        <vers num="5.2.1" edition="-"/>
        <vers num="5.2.1" edition="p10"/>
        <vers num="5.2.1" edition="p11"/>
        <vers num="5.2.1" edition="p12"/>
        <vers num="5.2.1" edition="p13"/>
        <vers num="5.2.1" edition="p2"/>
        <vers num="5.2.1" edition="p3"/>
        <vers num="5.2.1" edition="p4"/>
        <vers num="5.2.1" edition="p5"/>
        <vers num="5.2.1" edition="p6"/>
        <vers num="5.2.1" edition="p7"/>
        <vers num="5.2.1" edition="p8"/>
        <vers num="5.2.1" edition="p9"/>
        <vers num="5.2.1" edition="rc2"/>
        <vers num="5.3" edition="-"/>
        <vers num="5.3" edition="beta6"/>
        <vers num="5.3" edition="p1"/>
        <vers num="5.3" edition="p10"/>
        <vers num="5.3" edition="p11"/>
        <vers num="5.3" edition="p12"/>
        <vers num="5.3" edition="p14"/>
        <vers num="5.3" edition="p15"/>
        <vers num="5.3" edition="p16"/>
        <vers num="5.3" edition="p17"/>
        <vers num="5.3" edition="p18"/>
        <vers num="5.3" edition="p19"/>
        <vers num="5.3" edition="p2"/>
        <vers num="5.3" edition="p22"/>
        <vers num="5.3" edition="p23"/>
        <vers num="5.3" edition="p24"/>
        <vers num="5.3" edition="p25"/>
        <vers num="5.3" edition="p26"/>
        <vers num="5.3" edition="p27"/>
        <vers num="5.3" edition="p28"/>
        <vers num="5.3" edition="p29"/>
        <vers num="5.3" edition="p30"/>
        <vers num="5.3" edition="p31"/>
        <vers num="5.3" edition="p32"/>
        <vers num="5.3" edition="p33"/>
        <vers num="5.3" edition="p34"/>
        <vers num="5.3" edition="p36"/>
        <vers num="5.3" edition="p37"/>
        <vers num="5.3" edition="p6"/>
        <vers num="5.3" edition="p7"/>
        <vers num="5.3" edition="p8"/>
        <vers num="5.3" edition="p9"/>
        <vers num="5.4" edition="-"/>
        <vers num="5.4" edition="p1"/>
        <vers num="5.4" edition="p10"/>
        <vers num="5.4" edition="p11"/>
        <vers num="5.4" edition="p12"/>
        <vers num="5.4" edition="p13"/>
        <vers num="5.4" edition="p14"/>
        <vers num="5.4" edition="p15"/>
        <vers num="5.4" edition="p16"/>
        <vers num="5.4" edition="p17"/>
        <vers num="5.4" edition="p18"/>
        <vers num="5.4" edition="p19"/>
        <vers num="5.4" edition="p2"/>
        <vers num="5.4" edition="p21"/>
        <vers num="5.4" edition="p22"/>
        <vers num="5.4" edition="p3"/>
        <vers num="5.4" edition="p4"/>
        <vers num="5.4" edition="p5"/>
        <vers num="5.4" edition="p7"/>
        <vers num="5.4" edition="p8"/>
        <vers num="5.4" edition="p9"/>
        <vers num="5.5" edition="-"/>
        <vers num="5.5" edition="p1"/>
        <vers num="5.5" edition="p11"/>
        <vers num="5.5" edition="p12"/>
        <vers num="5.5" edition="p13"/>
        <vers num="5.5" edition="p14"/>
        <vers num="5.5" edition="p15"/>
        <vers num="5.5" edition="p16"/>
        <vers num="5.5" edition="p17"/>
        <vers num="5.5" edition="p18"/>
        <vers num="5.5" edition="p19"/>
        <vers num="5.5" edition="p2"/>
        <vers num="5.5" edition="p20"/>
        <vers num="5.5" edition="p3"/>
        <vers num="5.5" edition="p4"/>
        <vers num="5.5" edition="p5"/>
        <vers num="5.5" edition="p7"/>
        <vers num="5.5" edition="p8"/>
        <vers num="5.5" edition="p9"/>
        <vers num="6.0" edition="-"/>
        <vers num="6.0" edition="beta5"/>
        <vers num="6.0" edition="p10"/>
        <vers num="6.0" edition="p11"/>
        <vers num="6.0" edition="p12"/>
        <vers num="6.0" edition="p14"/>
        <vers num="6.0" edition="p15"/>
        <vers num="6.0" edition="p16"/>
        <vers num="6.0" edition="p17"/>
        <vers num="6.0" edition="p2"/>
        <vers num="6.0" edition="p3"/>
        <vers num="6.0" edition="p4"/>
        <vers num="6.0" edition="p5"/>
        <vers num="6.0" edition="p6"/>
        <vers num="6.0" edition="p7"/>
        <vers num="6.0" edition="p8"/>
        <vers num="6.0" edition="p9"/>
        <vers num="6.1" edition="-"/>
        <vers num="6.1" edition="p1"/>
        <vers num="6.1" edition="p10"/>
        <vers num="6.1" edition="p11"/>
        <vers num="6.1" edition="p12"/>
        <vers num="6.1" edition="p13"/>
        <vers num="6.1" edition="p16"/>
        <vers num="6.1" edition="p17"/>
        <vers num="6.1" edition="p18"/>
        <vers num="6.1" edition="p19"/>
        <vers num="6.1" edition="p2"/>
        <vers num="6.1" edition="p20"/>
        <vers num="6.1" edition="p21"/>
        <vers num="6.1" edition="p22"/>
        <vers num="6.1" edition="p23"/>
        <vers num="6.1" edition="p24"/>
        <vers num="6.1" edition="p4"/>
        <vers num="6.1" edition="p6"/>
        <vers num="6.1" edition="p7"/>
        <vers num="6.1" edition="p9"/>
        <vers num="6.2" edition="-"/>
        <vers num="6.2" edition="p1"/>
        <vers num="6.2" edition="p10"/>
        <vers num="6.2" edition="p11"/>
        <vers num="6.2" edition="p12"/>
        <vers num="6.2" edition="p4"/>
        <vers num="6.2" edition="p5"/>
        <vers num="6.2" edition="p6"/>
        <vers num="6.2" edition="p7"/>
        <vers num="6.2" edition="p8"/>
        <vers num="6.2" edition="p9"/>
        <vers num="6.2" edition="rc1"/>
        <vers num="6.2" edition="rc2"/>
        <vers num="6.3" edition="-"/>
        <vers num="6.3" edition="p1"/>
        <vers num="6.3" edition="p10"/>
        <vers num="6.3" edition="p11"/>
        <vers num="6.3" edition="p12"/>
        <vers num="6.3" edition="p13"/>
        <vers num="6.3" edition="p14"/>
        <vers num="6.3" edition="p15"/>
        <vers num="6.3" edition="p2"/>
        <vers num="6.3" edition="p3"/>
        <vers num="6.3" edition="p4"/>
        <vers num="6.3" edition="p5"/>
        <vers num="6.3" edition="p6"/>
        <vers num="6.3" edition="p7"/>
        <vers num="6.3" edition="p8"/>
        <vers num="6.3" edition="p9"/>
        <vers num="6.3" edition="rc2"/>
        <vers num="6.4" edition="-"/>
        <vers num="6.4" edition="p1"/>
        <vers num="6.4" edition="p10"/>
        <vers num="6.4" edition="p11"/>
        <vers num="6.4" edition="p2"/>
        <vers num="6.4" edition="p3"/>
        <vers num="6.4" edition="p4"/>
        <vers num="6.4" edition="p5"/>
        <vers num="6.4" edition="p6"/>
        <vers num="6.4" edition="p7"/>
        <vers num="6.4" edition="p8"/>
        <vers num="6.4" edition="p9"/>
        <vers num="7.0" edition="-"/>
        <vers num="7.0" edition="beta4"/>
        <vers num="7.0" edition="p1"/>
        <vers num="7.0" edition="p10"/>
        <vers num="7.0" edition="p11"/>
        <vers num="7.0" edition="p12"/>
        <vers num="7.0" edition="p3"/>
        <vers num="7.0" edition="p4"/>
        <vers num="7.0" edition="p5"/>
        <vers num="7.0" edition="p6"/>
        <vers num="7.0" edition="p7"/>
        <vers num="7.0" edition="p8"/>
        <vers num="7.0" edition="p9"/>
        <vers num="7.0" edition="rc2"/>
        <vers num="7.1" edition="-"/>
        <vers num="7.1" edition="p1"/>
        <vers num="7.1" edition="p10"/>
        <vers num="7.1" edition="p12"/>
        <vers num="7.1" edition="p13"/>
        <vers num="7.1" edition="p14"/>
        <vers num="7.1" edition="p15"/>
        <vers num="7.1" edition="p16"/>
        <vers num="7.1" edition="p2"/>
        <vers num="7.1" edition="p3"/>
        <vers num="7.1" edition="p4"/>
        <vers num="7.1" edition="p5"/>
        <vers num="7.1" edition="p6"/>
        <vers num="7.1" edition="p7"/>
        <vers num="7.1" edition="p8"/>
        <vers num="7.1" edition="p9"/>
        <vers num="7.1" edition="rc1"/>
        <vers num="7.1" edition="rc2"/>
        <vers num="7.2" edition="-"/>
        <vers num="7.2" edition="p1"/>
        <vers num="7.2" edition="p3"/>
        <vers num="7.2" edition="p4"/>
        <vers num="7.2" edition="p5"/>
        <vers num="7.2" edition="p6"/>
        <vers num="7.2" edition="p8"/>
        <vers num="7.2" edition="rc2"/>
        <vers num="7.3" edition="-"/>
        <vers num="7.3" edition="p1"/>
        <vers num="7.3" edition="p2"/>
        <vers num="7.3" edition="p3"/>
        <vers num="7.3" edition="p4"/>
        <vers num="7.3" edition="p5"/>
        <vers num="7.3" edition="p6"/>
        <vers num="7.3" edition="p7"/>
        <vers num="7.3" edition="p8"/>
        <vers num="7.3" edition="p9"/>
        <vers num="7.4" edition="-"/>
        <vers num="7.4" edition="p1"/>
        <vers num="7.4" edition="p10"/>
        <vers num="7.4" edition="p11"/>
        <vers num="7.4" edition="p12"/>
        <vers num="7.4" edition="p2"/>
        <vers num="7.4" edition="p3"/>
        <vers num="7.4" edition="p4"/>
        <vers num="7.4" edition="p5"/>
        <vers num="7.4" edition="p8"/>
        <vers num="7.4" edition="p9"/>
        <vers num="8.0" edition="-"/>
        <vers num="8.0" edition="p1"/>
        <vers num="8.0" edition="p2"/>
        <vers num="8.0" edition="p3"/>
        <vers num="8.0" edition="p4"/>
        <vers num="8.0" edition="p5"/>
        <vers num="8.0" edition="p6"/>
        <vers num="8.0" edition="rc1"/>
        <vers num="8.1" edition="-"/>
        <vers num="8.1" edition="p1"/>
        <vers num="8.1" edition="p10"/>
        <vers num="8.1" edition="p11"/>
        <vers num="8.1" edition="p12"/>
        <vers num="8.1" edition="p13"/>
        <vers num="8.1" edition="p2"/>
        <vers num="8.1" edition="p3"/>
        <vers num="8.1" edition="p4"/>
        <vers num="8.1" edition="p5"/>
        <vers num="8.1" edition="p6"/>
        <vers num="8.1" edition="p7"/>
        <vers num="8.2" edition="-"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2" edition="p10"/>
        <vers num="8.2" edition="p2"/>
        <vers num="8.2" edition="p3"/>
        <vers num="8.2" edition="p4"/>
        <vers num="8.2" edition="p5"/>
        <vers num="8.2" edition="p8"/>
        <vers num="8.2" edition="p9"/>
        <vers num="8.3" edition="-"/>
        <vers num="8.3" edition="p10"/>
        <vers num="8.3" edition="p11"/>
        <vers num="8.3" edition="p14"/>
        <vers num="8.3" edition="p15"/>
        <vers num="8.3" edition="p16"/>
        <vers num="8.3" edition="p2"/>
        <vers num="8.3" edition="p3"/>
        <vers num="8.3" edition="p4"/>
        <vers num="8.3" edition="p5"/>
        <vers num="8.3" edition="p6"/>
        <vers num="8.3" edition="p7"/>
        <vers num="8.3" edition="p8"/>
        <vers num="8.3" edition="p9"/>
        <vers num="8.4" edition="-"/>
        <vers num="8.4" edition="beta1"/>
        <vers num="8.4" edition="p11"/>
        <vers num="8.4" edition="p12"/>
        <vers num="8.4" edition="p13"/>
        <vers num="8.4" edition="p14"/>
        <vers num="8.4" edition="p15"/>
        <vers num="8.4" edition="p16"/>
        <vers num="8.4" edition="p17"/>
        <vers num="8.4" edition="p19"/>
        <vers num="8.4" edition="p2"/>
        <vers num="8.4" edition="p20"/>
        <vers num="8.4" edition="p21"/>
        <vers num="8.4" edition="p22"/>
        <vers num="8.4" edition="p23"/>
        <vers num="8.4" edition="p24"/>
        <vers num="8.4" edition="p26"/>
        <vers num="8.4" edition="p27"/>
        <vers num="8.4" edition="p3"/>
        <vers num="8.4" edition="p30"/>
        <vers num="8.4" edition="p33"/>
        <vers num="8.4" edition="p34"/>
        <vers num="8.4" edition="p35"/>
        <vers num="8.4" edition="p36"/>
        <vers num="8.4" edition="p4"/>
        <vers num="8.4" edition="p7"/>
        <vers num="8.4" edition="p8"/>
        <vers num="8.4" edition="p9"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="p2"/>
        <vers num="9.0" edition="p3"/>
        <vers num="9.0" edition="p4"/>
        <vers num="9.0" edition="p5"/>
        <vers num="9.0" edition="p6"/>
        <vers num="9.0" edition="p7"/>
        <vers num="9.0" edition="rc1"/>
        <vers num="9.0" edition="rc3"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="p1"/>
        <vers num="9.1" edition="p10"/>
        <vers num="9.1" edition="p11"/>
        <vers num="9.1" edition="p12"/>
        <vers num="9.1" edition="p14"/>
        <vers num="9.1" edition="p15"/>
        <vers num="9.1" edition="p16"/>
        <vers num="9.1" edition="p17"/>
        <vers num="9.1" edition="p18"/>
        <vers num="9.1" edition="p19"/>
        <vers num="9.1" edition="p2"/>
        <vers num="9.1" edition="p20"/>
        <vers num="9.1" edition="p22"/>
        <vers num="9.1" edition="p23"/>
        <vers num="9.1" edition="p24"/>
        <vers num="9.1" edition="p3"/>
        <vers num="9.1" edition="p4"/>
        <vers num="9.1" edition="p5"/>
        <vers num="9.1" edition="p6"/>
        <vers num="9.1" edition="p7"/>
        <vers num="9.1" edition="rc2"/>
        <vers num="9.1" edition="release-p4"/>
        <vers num="9.1" edition="release-p5"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.2" edition="beta2"/>
        <vers num="9.2" edition="p10"/>
        <vers num="9.2" edition="p11"/>
        <vers num="9.2" edition="p12"/>
        <vers num="9.2" edition="p13"/>
        <vers num="9.2" edition="p15"/>
        <vers num="9.2" edition="p16"/>
        <vers num="9.2" edition="p17"/>
        <vers num="9.2" edition="p3"/>
        <vers num="9.2" edition="p4"/>
        <vers num="9.2" edition="p5"/>
        <vers num="9.2" edition="p7"/>
        <vers num="9.2" edition="p8"/>
        <vers num="9.2" edition="p9"/>
        <vers num="9.2" edition="prerelease"/>
        <vers num="9.2" edition="rc1"/>
        <vers num="9.2" edition="rc2"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="p1"/>
        <vers num="9.3" edition="p10"/>
        <vers num="9.3" edition="p12"/>
        <vers num="9.3" edition="p13"/>
        <vers num="9.3" edition="p16"/>
        <vers num="9.3" edition="p19"/>
        <vers num="9.3" edition="p2"/>
        <vers num="9.3" edition="p20"/>
        <vers num="9.3" edition="p21"/>
        <vers num="9.3" edition="p22"/>
        <vers num="9.3" edition="p23"/>
        <vers num="9.3" edition="p24"/>
        <vers num="9.3" edition="p25"/>
        <vers num="9.3" edition="p28"/>
        <vers num="9.3" edition="p3"/>
        <vers num="9.3" edition="p30"/>
        <vers num="9.3" edition="p31"/>
        <vers num="9.3" edition="p32"/>
        <vers num="9.3" edition="p33"/>
        <vers num="9.3" edition="p34"/>
        <vers num="9.3" edition="p35"/>
        <vers num="9.3" edition="p36"/>
        <vers num="9.3" edition="p38"/>
        <vers num="9.3" edition="p39"/>
        <vers num="9.3" edition="p40"/>
        <vers num="9.3" edition="p41"/>
        <vers num="9.3" edition="p42"/>
        <vers num="9.3" edition="p43"/>
        <vers num="9.3" edition="p44"/>
        <vers num="9.3" edition="p45"/>
        <vers num="9.3" edition="p47"/>
        <vers num="9.3" edition="p48"/>
        <vers num="9.3" edition="p49"/>
        <vers num="9.3" edition="p5"/>
        <vers num="9.3" edition="p50"/>
        <vers num="9.3" edition="p51"/>
        <vers num="9.3" edition="p52"/>
        <vers num="9.3" edition="p53"/>
        <vers num="9.3" edition="p6"/>
        <vers num="9.3" edition="p7"/>
        <vers num="9.3" edition="p8"/>
        <vers num="9.3" edition="p9"/>
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="p1"/>
        <vers num="10.0" edition="p10"/>
        <vers num="10.0" edition="p12"/>
        <vers num="10.0" edition="p13"/>
        <vers num="10.0" edition="p14"/>
        <vers num="10.0" edition="p15"/>
        <vers num="10.0" edition="p16"/>
        <vers num="10.0" edition="p17"/>
        <vers num="10.0" edition="p2"/>
        <vers num="10.0" edition="p3"/>
        <vers num="10.0" edition="p4"/>
        <vers num="10.0" edition="p5"/>
        <vers num="10.0" edition="p6"/>
        <vers num="10.0" edition="p7"/>
        <vers num="10.0" edition="p8"/>
        <vers num="10.0" edition="p9"/>
        <vers num="10.1" edition="-"/>
        <vers num="10.1" edition="p1"/>
        <vers num="10.1" edition="p10"/>
        <vers num="10.1" edition="p12"/>
        <vers num="10.1" edition="p15"/>
        <vers num="10.1" edition="p16"/>
        <vers num="10.1" edition="p17"/>
        <vers num="10.1" edition="p18"/>
        <vers num="10.1" edition="p19"/>
        <vers num="10.1" edition="p2"/>
        <vers num="10.1" edition="p22"/>
        <vers num="10.1" edition="p24"/>
        <vers num="10.1" edition="p25"/>
        <vers num="10.1" edition="p26"/>
        <vers num="10.1" edition="p27"/>
        <vers num="10.1" edition="p28"/>
        <vers num="10.1" edition="p29"/>
        <vers num="10.1" edition="p3"/>
        <vers num="10.1" edition="p30"/>
        <vers num="10.1" edition="p31"/>
        <vers num="10.1" edition="p32"/>
        <vers num="10.1" edition="p33"/>
        <vers num="10.1" edition="p34"/>
        <vers num="10.1" edition="p35"/>
        <vers num="10.1" edition="p36"/>
        <vers num="10.1" edition="p37"/>
        <vers num="10.1" edition="p39"/>
        <vers num="10.1" edition="p4"/>
        <vers num="10.1" edition="p40"/>
        <vers num="10.1" edition="p41"/>
        <vers num="10.1" edition="p42"/>
        <vers num="10.1" edition="p43"/>
        <vers num="10.1" edition="p44"/>
        <vers num="10.1" edition="p45"/>
        <vers num="10.1" edition="p5"/>
        <vers num="10.1" edition="p6"/>
        <vers num="10.1" edition="p7"/>
        <vers num="10.1" edition="p8"/>
        <vers num="10.1" edition="p9"/>
        <vers num="10.2" edition="-"/>
        <vers num="10.2" edition="p1"/>
        <vers num="10.2" edition="p10"/>
        <vers num="10.2" edition="p11"/>
        <vers num="10.2" edition="p12"/>
        <vers num="10.2" edition="p13"/>
        <vers num="10.2" edition="p14"/>
        <vers num="10.2" edition="p15"/>
        <vers num="10.2" edition="p16"/>
        <vers num="10.2" edition="p17"/>
        <vers num="10.2" edition="p18"/>
        <vers num="10.2" edition="p19"/>
        <vers num="10.2" edition="p2"/>
        <vers num="10.2" edition="p20"/>
        <vers num="10.2" edition="p22"/>
        <vers num="10.2" edition="p23"/>
        <vers num="10.2" edition="p24"/>
        <vers num="10.2" edition="p25"/>
        <vers num="10.2" edition="p26"/>
        <vers num="10.2" edition="p27"/>
        <vers num="10.2" edition="p28"/>
        <vers num="10.2" edition="p5"/>
        <vers num="10.2" edition="p7"/>
        <vers num="10.2" edition="p8"/>
        <vers num="10.2" edition="p9"/>
        <vers num="10.3" edition="-"/>
        <vers num="10.3" edition="p1"/>
        <vers num="10.3" edition="p10"/>
        <vers num="10.3" edition="p11"/>
        <vers num="10.3" edition="p12"/>
        <vers num="10.3" edition="p13"/>
        <vers num="10.3" edition="p14"/>
        <vers num="10.3" edition="p15"/>
        <vers num="10.3" edition="p16"/>
        <vers num="10.3" edition="p17"/>
        <vers num="10.3" edition="p18"/>
        <vers num="10.3" edition="p19"/>
        <vers num="10.3" edition="p2"/>
        <vers num="10.3" edition="p20"/>
        <vers num="10.3" edition="p21"/>
        <vers num="10.3" edition="p22"/>
        <vers num="10.3" edition="p24"/>
        <vers num="10.3" edition="p25"/>
        <vers num="10.3" edition="p26"/>
        <vers num="10.3" edition="p27"/>
        <vers num="10.3" edition="p28"/>
        <vers num="10.3" edition="p29"/>
        <vers num="10.3" edition="p3"/>
        <vers num="10.3" edition="p4"/>
        <vers num="10.3" edition="p5"/>
        <vers num="10.3" edition="p6"/>
        <vers num="10.3" edition="p9"/>
        <vers num="10.3" edition="rc2"/>
        <vers num="10.4" edition="-"/>
        <vers num="10.4" edition="p1"/>
        <vers num="10.4" edition="p11"/>
        <vers num="10.4" edition="p12"/>
        <vers num="10.4" edition="p13"/>
        <vers num="10.4" edition="p3"/>
        <vers num="10.4" edition="p4"/>
        <vers num="10.4" edition="p5"/>
        <vers num="10.4" edition="p6"/>
        <vers num="10.4" edition="p7"/>
        <vers num="10.4" edition="p8"/>
        <vers num="10.4" edition="p9"/>
        <vers num="11.0" edition="-"/>
        <vers num="11.0" edition="p1"/>
        <vers num="11.0" edition="p10"/>
        <vers num="11.0" edition="p11"/>
        <vers num="11.0" edition="p12"/>
        <vers num="11.0" edition="p13"/>
        <vers num="11.0" edition="p15"/>
        <vers num="11.0" edition="p16"/>
        <vers num="11.0" edition="p2"/>
        <vers num="11.0" edition="p3"/>
        <vers num="11.0" edition="p4"/>
        <vers num="11.0" edition="p5"/>
        <vers num="11.0" edition="p6"/>
        <vers num="11.0" edition="p7"/>
        <vers num="11.0" edition="p8"/>
        <vers num="11.0" edition="p9"/>
        <vers num="11.1" edition="-"/>
        <vers num="11.1" edition="p1"/>
        <vers num="11.1" edition="p11"/>
        <vers num="11.1" edition="p13"/>
        <vers num="11.1" edition="p14"/>
        <vers num="11.1" edition="p15"/>
        <vers num="11.1" edition="p2"/>
        <vers num="11.1" edition="p4"/>
        <vers num="11.1" edition="p5"/>
        <vers num="11.1" edition="p6"/>
        <vers num="11.1" edition="p7"/>
        <vers num="11.1" edition="p9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10850" seq="2017-10850" published="2017-09-01" modified="2017-09-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.), PostScript? Driver + Additional Feature Plug-in + PPD File for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:10 UTC.), XPS Print Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 3 Nov 2017 23:48 UTC.), ART EX Direct FAX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 26 May 2017 07:44 UTC.), Setting Restore Tool for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 25 Aug 2015 08:51 UTC.) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html" adv="1">http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN09769017/index.html" adv="1">JVN#09769017</ref>
    </refs>
    <vuln_soft>
      <prod name="apeosport-vi" vendor="fujixerox">
        <vers num="c2271"/>
        <vers num="c3371"/>
        <vers num="c4471"/>
        <vers num="c5571"/>
        <vers num="c6671"/>
        <vers num="c7771"/>
      </prod>
      <prod name="docucentre-vi" vendor="fujixerox">
        <vers num="c2271"/>
        <vers num="c3371"/>
        <vers num="c4471"/>
        <vers num="c5571"/>
        <vers num="c6671"/>
        <vers num="c7771"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10851" seq="2017-10851" published="2017-09-01" modified="2017-09-06" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html" adv="1">http://www.fujixerox.co.jp/company/news/notice/2017/0831_rectification_work.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN09769017/index.html" adv="1">JVN#09769017</ref>
    </refs>
    <vuln_soft>
      <prod name="contentsbridge_utility" vendor="fujixerox">
        <vers num="7.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10852" seq="2017-10852" published="2018-03-09" modified="2018-03-27" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://corega.jp/support/security/20180309_wgr1200.htm" adv="1">http://corega.jp/support/security/20180309_wgr1200.htm</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN15201064/index.html" adv="1">JVN#15201064</ref>
    </refs>
    <vuln_soft>
      <prod name="cg-wgr_1200_firmware" vendor="corega">
        <vers num="2.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10853" seq="2017-10853" published="2018-03-09" modified="2018-03-27" severity="High" CVSS_version="2.0" CVSS_score="8.3" CVSS_base_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://corega.jp/support/security/20180309_wgr1200.htm" adv="1">http://corega.jp/support/security/20180309_wgr1200.htm</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN15201064/index.html" adv="1">JVN#15201064</ref>
    </refs>
    <vuln_soft>
      <prod name="cg-wgr_1200_firmware" vendor="corega">
        <vers num="2.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10854" seq="2017-10854" published="2018-03-09" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="5.8" CVSS_base_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://corega.jp/support/security/20180309_wgr1200.htm" adv="1">http://corega.jp/support/security/20180309_wgr1200.htm</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN15201064/index.html" adv="1">JVN#15201064</ref>
    </refs>
    <vuln_soft>
      <prod name="cg-wgr_1200_firmware" vendor="corega">
        <vers num="2.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10855" seq="2017-10855" published="2017-09-15" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.fujitsu.com/jp/group/bsc/services/fence/info-2017080101.html" adv="1">http://www.fujitsu.com/jp/group/bsc/services/fence/info-2017080101.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN57205588/index.html" adv="1">JVN#57205588</ref>
    </refs>
    <vuln_soft>
      <prod name="fence-explorer" vendor="fujitsu">
        <vers num="8.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10856" seq="2017-10856" published="2017-09-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SEIL/X 4.60 to 5.72, SEIL/B1 4.60 to 5.72, SEIL/x86 3.20 to 5.72, SEIL/BPV4 5.00 to 5.72 allows remote attackers to cause a temporary failure of the device's encrypted communications via a specially crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.seil.jp/support/security/a01811.html" adv="1">http://www.seil.jp/support/security/a01811.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN76692689/index.html" adv="1">JVN#76692689</ref>
    </refs>
    <vuln_soft>
      <prod name="b1_firmware" vendor="seil">
        <vers num="4.60"/>
        <vers num="5.72"/>
      </prod>
      <prod name="bpv_4_firmware" vendor="seil">
        <vers num="5.00"/>
        <vers num="5.72"/>
      </prod>
      <prod name="x1_firmware" vendor="seil">
        <vers num="4.60"/>
        <vers num="5.72"/>
      </prod>
      <prod name="x2_firmware" vendor="seil">
        <vers num="4.60"/>
        <vers num="5.72"/>
      </prod>
      <prod name="x86_fuji_firmware" vendor="seil">
        <vers num="3.20"/>
        <vers num="5.72"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10857" seq="2017-10857" published="2017-10-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN14658424/index.html" adv="1">JVN#14658424</ref>
      <ref source="CONFIRM" url="https://support.cybozu.com/ja-jp/article/9811" adv="1">https://support.cybozu.com/ja-jp/article/9811</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="cybozu">
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.1.0"/>
        <vers num="10.1.2"/>
        <vers num="10.2.0"/>
        <vers num="10.3.0"/>
        <vers num="10.4.0"/>
        <vers num="10.5.0"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10858" seq="2017-10858" published="2017-09-15" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in "i-filter 6.0 install program" file version 1.0.8.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.daj.jp/cs/info/2017/0912/" adv="1">http://www.daj.jp/cs/info/2017/0912/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN75929834/index.html" adv="1">JVN#75929834</ref>
    </refs>
    <vuln_soft>
      <prod name="i-filter_installer" vendor="daj">
        <vers num="1.0.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10859" seq="2017-10859" published="2017-09-15" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.daj.jp/cs/info/2017/0912/" adv="1">http://www.daj.jp/cs/info/2017/0912/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN75929834/index.html" adv="1">JVN#75929834</ref>
    </refs>
    <vuln_soft>
      <prod name="i-filter_installer" vendor="daj">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1086" seq="2017-1086" published="2017-11-16" modified="2017-12-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, not all information in the struct ptrace_lwpinfo is relevant for the state of any thread, and the kernel does not fill the irrelevant bytes or short strings. Since the structure filled by the kernel is allocated on the kernel stack and copied to userspace, a leak of information of the kernel stack of the thread is possible from the debugger. As a result, some bytes from the kernel stack of the thread using ptrace (PT_LWPINFO) call can be observed in userspace.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101861" adv="1">101861</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039809" adv="1">1039809</ref>
      <ref source="FREEBSD" url="https://www.freebsd.org/security/advisories/FreeBSD-SA-17:08.ptrace.asc" adv="1">FreeBSD-SA-17:08</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10860" seq="2017-10860" published="2017-09-15" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.daj.jp/cs/info/2017/0912/" adv="1">http://www.daj.jp/cs/info/2017/0912/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100916">100916</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN75929834/index.html" adv="1">JVN#75929834</ref>
    </refs>
    <vuln_soft>
      <prod name="i-filter_installer" vendor="daj">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10861" seq="2017-10861" published="2017-12-01" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.qualitysoft.com/qnd_vulnerabilities" adv="1">http://www.qualitysoft.com/qnd_vulnerabilities</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU94198685/index.html" adv="1">https://jvn.jp/en/vu/JVNVU94198685/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="qnd_advance/standard" vendor="qualitysoft">
        <vers num="10.3i" prev="1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10862" seq="2017-10862" published="2017-10-12" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/reallylabs/jwt-scala" adv="1">https://github.com/reallylabs/jwt-scala</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU90916766/index.html" adv="1">https://jvn.jp/en/vu/JVNVU90916766/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="jwt-scala" vendor="really">
        <vers num="1.2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10863" seq="2017-10863" published="2017-10-12" modified="2017-10-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Note this is a separate vulnerability from CVE-2017-10865.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html" adv="1">http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN58909026/index.html" adv="1">JVN#58909026</ref>
    </refs>
    <vuln_soft>
      <prod name="confidential_file_decryption" vendor="hitachi-solutions">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10864" seq="2017-10864" published="2017-10-12" modified="2017-10-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html" adv="1">http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN94056834/index.html" adv="1">JVN#94056834</ref>
    </refs>
    <vuln_soft>
      <prod name="confidential_file_viewer" vendor="hitachi-solutions">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10865" seq="2017-10865" published="2017-10-12" modified="2017-10-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Note this is a separate vulnerability from CVE-2017-10863.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html" adv="1">http://www.hitachi-solutions.co.jp/hibun/sp/support/importance/20170929.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN55516206/index.html" adv="1">JVN#55516206</ref>
    </refs>
    <vuln_soft>
      <prod name="confidential_file_decryption" vendor="hitachi-solutions">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10868" seq="2017-10868" published="2017-12-22" modified="2018-01-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/h2o/h2o/issues/1459" adv="1">https://github.com/h2o/h2o/issues/1459</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN84182676/index.html" adv="1">JVN#84182676</ref>
    </refs>
    <vuln_soft>
      <prod name="h2o" vendor="h2o_project">
        <vers num="1.6.1"/>
        <vers num="1.7.0" edition="beta2"/>
        <vers num="1.7.2"/>
        <vers num="2.0.0" edition="beta4"/>
        <vers num="2.0.3"/>
        <vers num="2.1.0" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10869" seq="2017-10869" published="2017-12-22" modified="2018-01-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/h2o/h2o/issues/1460" adv="1">https://github.com/h2o/h2o/issues/1460</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN84182676/index.html" adv="1">JVN#84182676</ref>
    </refs>
    <vuln_soft>
      <prod name="h2o" vendor="h2o_project">
        <vers num="2.2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1087" seq="2017-1087" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one jail can read and modify the content of POSIX shared memory objects created by a process in another jail or the host system. As a result, a malicious user that has access to a jailed system is able to abuse shared memory by injecting malicious content in the shared memory region. This memory region might be executed by applications trusting the shared memory, like Squid. This issue could lead to a Denial of Service or local privilege escalation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101867" adv="1">101867</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039810" adv="1">1039810</ref>
      <ref source="FREEBSD" url="https://www.freebsd.org/security/advisories/FreeBSD-SA-17:09.shm.asc" adv="1">FreeBSD-SA-17:09</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10870" seq="2017-10870" published="2017-11-02" modified="2017-11-22" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU93703434/index.html" adv="1">https://jvn.jp/en/vu/JVNVU93703434/index.html</ref>
      <ref source="MISC" url="https://www.justsystems.com/jp/info/js17003.html" adv="1" patch="1">https://www.justsystems.com/jp/info/js17003.html</ref>
    </refs>
    <vuln_soft>
      <prod name="easy_postcard_2016" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="easy_postcard_2017" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="easy_postcard_2018" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_2016" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_2017" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_2017_trial_version" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_2018" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_government_6" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_government_7" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_government_8" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_pro" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_pro_2" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_pro_2011" vendor="justsystems">
        <vers num="-"/>
      </prod>
      <prod name="ichitaro_pro_3" vendor="justsystems">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10871" seq="2017-10871" published="2017-11-13" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN23367475/index.html" adv="1">JVN#23367475</ref>
    </refs>
    <vuln_soft>
      <prod name="wi-fi_station_l-02f_firmware" vendor="nttdocomo">
        <vers num="l02f-mdm9625-v10h-jun-23-2017-dcm-jp" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10872" seq="2017-10872" published="2017-12-22" modified="2018-01-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/h2o/h2o/issues/1543" adv="1">https://github.com/h2o/h2o/issues/1543</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN84182676/index.html" adv="1">JVN#84182676</ref>
    </refs>
    <vuln_soft>
      <prod name="h2o" vendor="h2o_project">
        <vers num="2.2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10873" seq="2017-10873" published="2017-11-02" modified="2017-11-22" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN79546124/" adv="1">JVN#97243511</ref>
      <ref source="MISC" url="https://www.cs.themistruct.com/" adv="1">https://www.cs.themistruct.com/</ref>
      <ref source="MISC" url="https://www.osstech.co.jp/support/am2017-2-1-en" adv="1" patch="1">https://www.osstech.co.jp/support/am2017-2-1-en</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10874" seq="2017-10874" published="2017-12-01" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://web116.jp/shop/hikari_p/q200/q200_00.html" adv="1">http://web116.jp/shop/hikari_p/q200/q200_00.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN73141967/index.html" adv="1">JVN#73141967</ref>
    </refs>
    <vuln_soft>
      <prod name="pwr-q200_firmware" vendor="ntt-east">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10875" seq="2017-10875" published="2017-11-13" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN87886530/index.html" adv="1">JVN#87886530</ref>
      <ref source="CONFIRM" url="http://www.iodata.jp/support/information/2017/ld-connect/" adv="1">http://www.iodata.jp/support/information/2017/ld-connect/</ref>
    </refs>
    <vuln_soft>
      <prod name="lan_disk_connect_firmware" vendor="iodata">
        <vers num="2.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1088" seq="2017-1088" published="2017-11-16" modified="2017-12-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not properly clear the memory of the kld_file_stat structure before filling the data. Since the structure filled by the kernel is allocated on the kernel stack and copied to userspace, a leak of information from the kernel stack is possible. As a result, some bytes from the kernel stack can be observed in userspace.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101857" adv="1">101857</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039811" adv="1">1039811</ref>
      <ref source="FREEBSD" url="https://www.freebsd.org/security/advisories/FreeBSD-SA-17:10.kldstat.asc" adv="1">FreeBSD-SA-17:10</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10885" seq="2017-10885" published="2017-11-13" modified="2017-11-29" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in HYPER SBI Ver. 2.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="http://jvn.jp/en/jp/JVN71284826/index.html" adv="1">JVN#71284826</ref>
    </refs>
    <vuln_soft>
      <prod name="hyper_sbi" vendor="sbisec">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10886" seq="2017-10886" published="2017-11-17" modified="2017-12-04" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://tips.cs-cart.jp/fix-jvn-29602086.html" adv="1">http://tips.cs-cart.jp/fix-jvn-29602086.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN29602086/index.html" adv="1">JVN#29602086</ref>
    </refs>
    <vuln_soft>
      <prod name="cs-cart" vendor="cs-cart">
        <vers num="4.0.1" edition="::ja"/>
        <vers num="4.0.2" edition="::ja"/>
        <vers num="4.0.3" edition="::ja"/>
        <vers num="4.1.1" edition="::ja"/>
        <vers num="4.1.2" edition="::ja"/>
        <vers num="4.1.3" edition="::ja"/>
        <vers num="4.1.4" edition="::ja"/>
        <vers num="4.2.1" edition="::ja"/>
        <vers num="4.2.2" edition="::ja"/>
        <vers num="4.2.3" edition="::ja"/>
        <vers num="4.2.4" edition="::ja"/>
        <vers num="4.3.1" edition="::ja"/>
        <vers num="4.3.2" edition="::ja"/>
        <vers num="4.3.3" edition="::ja"/>
        <vers num="4.3.4" edition="::ja"/>
        <vers num="4.3.5" edition="::ja"/>
        <vers num="4.3.6" edition="::ja"/>
        <vers num="4.3.7" edition="::ja"/>
        <vers num="4.3.8" edition="::ja"/>
        <vers num="4.3.9" edition="::ja"/>
        <vers num="4.3.10" edition="::ja"/>
      </prod>
      <prod name="cs-cart_multivendor" vendor="cs-cart">
        <vers num="4.0.1" edition="::ja"/>
        <vers num="4.0.2" edition="::ja"/>
        <vers num="4.0.3" edition="::ja"/>
        <vers num="4.1.1" edition="::ja"/>
        <vers num="4.1.2" edition="::ja"/>
        <vers num="4.1.3" edition="::ja"/>
        <vers num="4.1.4" edition="::ja"/>
        <vers num="4.2.1" edition="::ja"/>
        <vers num="4.2.2" edition="::ja"/>
        <vers num="4.2.3" edition="::ja"/>
        <vers num="4.2.4" edition="::ja"/>
        <vers num="4.3.1" edition="::ja"/>
        <vers num="4.3.2" edition="::ja"/>
        <vers num="4.3.3" edition="::ja"/>
        <vers num="4.3.4" edition="::ja"/>
        <vers num="4.3.5" edition="::ja"/>
        <vers num="4.3.6" edition="::ja"/>
        <vers num="4.3.7" edition="::ja"/>
        <vers num="4.3.8" edition="::ja"/>
        <vers num="4.3.9" edition="::ja"/>
        <vers num="4.3.10" edition="::ja"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10887" seq="2017-10887" published="2017-11-17" modified="2017-12-04" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bookwalker.jp/info/message20171113_pc_app/" adv="1">https://bookwalker.jp/info/message20171113_pc_app/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN18420340/index.html" adv="1">JVN#18420340</ref>
    </refs>
    <vuln_soft>
      <prod name="book_walker" vendor="bookwalker">
        <vers num="1.2.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10888" seq="2017-10888" published="2017-11-17" modified="2017-12-04" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access local files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bookwalker.jp/info/message20171113_pc_app/" adv="1">https://bookwalker.jp/info/message20171113_pc_app/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN18420340/index.html" adv="1">JVN#18420340</ref>
    </refs>
    <vuln_soft>
      <prod name="book_walker" vendor="bookwalker">
        <vers num="1.2.5" prev="1"/>
        <vers num="1.2.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10889" seq="2017-10889" published="2017-11-17" modified="2017-12-04" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN05398317/index.html" adv="1">JVN#05398317</ref>
      <ref source="CONFIRM" url="https://wordpress.org/plugins/tablepress/#developers" adv="1">https://wordpress.org/plugins/tablepress/#developers</ref>
    </refs>
    <vuln_soft>
      <prod name="tablepress" vendor="tablepress">
        <vers num="1.8" prev="1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1089" seq="2017-1089" published="2019-03-05" modified="2019-03-05" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10890" seq="2017-10890" published="2017-11-17" modified="2017-12-08" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="5.5" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN76382932/index.html" adv="1">JVN#76382932</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10891" seq="2017-10891" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Media Go version 3.2.0.191 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN08517069/index.html" adv="1">JVN#08517069</ref>
    </refs>
    <vuln_soft>
      <prod name="media_go" vendor="sony">
        <vers num="3.2.0.191" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10892" seq="2017-10892" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN08517069/index.html" adv="1">JVN#08517069</ref>
    </refs>
    <vuln_soft>
      <prod name="music_center" vendor="sony">
        <vers num="1.0.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10893" seq="2017-10893" published="2017-12-08" modified="2017-12-20" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software" Ver3.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN30352845/index.html" adv="1">JVN#30352845</ref>
    </refs>
    <vuln_soft>
      <prod name="the_public_certification_service_for_individuals" vendor="j-lis">
        <vers num="3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10894" seq="2017-10894" published="2017-12-01" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">StreamRelay.NET.exe ver2.14.0.7 and earlier allows remote attackers to cause a denial of service via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN71291160/index.html" adv="1">JVN#71291160</ref>
    </refs>
    <vuln_soft>
      <prod name="streamrelay" vendor="streamrelay">
        <vers num="2.14.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10895" seq="2017-10895" published="2017-12-01" modified="2017-12-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">sDNSProxy.exe ver1.1.0.0 and earlier allows remote attackers to cause a denial of service via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN71291160/index.html" adv="1">JVN#71291160</ref>
    </refs>
    <vuln_soft>
      <prod name="sdnsproxy" vendor="sdnsproxy_project">
        <vers num="1.1.0.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10896" seq="2017-10896" published="2017-12-08" modified="2017-12-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://buffalo.jp/support_s/s20171201.html" adv="1" patch="1">http://buffalo.jp/support_s/s20171201.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN65994435/index.html" adv="1">JVN#65994435</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10897" seq="2017-10897" published="2017-12-08" modified="2017-12-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.1" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Input validation issue in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to cause the device to become unresponsive via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://buffalo.jp/support_s/s20171201.html" adv="1" patch="1">http://buffalo.jp/support_s/s20171201.html</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN65994435/index.html" adv="1">JVN#65994435</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10898" seq="2017-10898" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN78501037/index.html" adv="1">JVN#78501037</ref>
    </refs>
    <vuln_soft>
      <prod name="a-member" vendor="ark-web">
        <vers num="3.8.6" prev="1" edition=":~~~movabletype~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10899" seq="2017-10899" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN78501037/index.html" adv="1">JVN#78501037</ref>
    </refs>
    <vuln_soft>
      <prod name="a-reserve" vendor="ark-web">
        <vers num="3.8.6" prev="1" edition=":~~~movabletype~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1090" seq="2017-1090" published="2019-03-05" modified="2019-03-05" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10900" seq="2017-10900" published="2017-12-01" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PTW-WMS1 firmware version 2.000.012 allows remote attackers to bypass access restrictions to obtain or delete data on the disk via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN98295787/index.html" adv="1">JVN#98295787</ref>
    </refs>
    <vuln_soft>
      <prod name="ptw-wms1_firmware" vendor="princeton">
        <vers num="2.000.012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10901" seq="2017-10901" published="2017-12-01" modified="2017-12-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN98295787/index.html" adv="1">JVN#98295787</ref>
    </refs>
    <vuln_soft>
      <prod name="ptw-wms1_firmware" vendor="princeton">
        <vers num="2.000.012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10902" seq="2017-10902" published="2017-12-01" modified="2017-12-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN98295787/index.html" adv="1">JVN#98295787</ref>
    </refs>
    <vuln_soft>
      <prod name="ptw-wms1_firmware" vendor="princeton">
        <vers num="2.000.012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10903" seq="2017-10903" published="2017-12-01" modified="2017-12-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN98295787/index.html" adv="1">JVN#98295787</ref>
    </refs>
    <vuln_soft>
      <prod name="ptw-wms1_firmware" vendor="princeton">
        <vers num="2.000.012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10904" seq="2017-10904" published="2017-12-15" modified="2017-12-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://blog.qt.io/blog/2017/11/22/security-advisory-qt-android/" adv="1">https://blog.qt.io/blog/2017/11/22/security-advisory-qt-android/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN67389262/index.html" adv="1">JVN#67389262</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10905" seq="2017-10905" published="2017-12-15" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://blog.qt.io/blog/2017/11/22/security-advisory-qt-android/" adv="1">https://blog.qt.io/blog/2017/11/22/security-advisory-qt-android/</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN27342829/index.html" adv="1">JVN#27342829</ref>
    </refs>
    <vuln_soft>
      <prod name="qt" vendor="qt">
        <vers num="5.9.0" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10906" seq="2017-10906" published="2017-12-08" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:2225" adv="1">RHSA-2018:2225</ref>
      <ref source="CONFIRM" url="https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes" adv="1">https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes</ref>
      <ref source="CONFIRM" url="https://github.com/fluent/fluentd/pull/1733" adv="1" patch="1">https://github.com/fluent/fluentd/pull/1733</ref>
      <ref source="MISC" url="https://jvn.jp/en/vu/JVNVU95124098/index.html" adv="1">https://jvn.jp/en/vu/JVNVU95124098/index.html</ref>
    </refs>
    <vuln_soft>
      <prod name="fluentd" vendor="fluentd">
        <vers num="0.12.29"/>
        <vers num="0.12.30"/>
        <vers num="0.12.31"/>
        <vers num="0.12.32"/>
        <vers num="0.12.33"/>
        <vers num="0.12.34"/>
        <vers num="0.12.35"/>
        <vers num="0.12.36"/>
        <vers num="0.12.37"/>
        <vers num="0.12.38"/>
        <vers num="0.12.39"/>
        <vers num="0.12.40"/>
      </prod>
      <prod name="openstack" vendor="redhat">
        <vers num="13.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10907" seq="2017-10907" published="2017-12-22" modified="2018-01-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an attacker to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN93333702/index.html" adv="1">JVN#93333702</ref>
      <ref source="CONFIRM" url="https://onethird.net/en/p1307.html" adv="1">https://onethird.net/en/p1307.html</ref>
    </refs>
    <vuln_soft>
      <prod name="onethird_cms_show_off" vendor="spiqe">
        <vers num="1.85" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10908" seq="2017-10908" published="2017-12-22" modified="2018-01-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/h2o/h2o/issues/1544" adv="1">https://github.com/h2o/h2o/issues/1544</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN84182676/index.html" adv="1">JVN#84182676</ref>
    </refs>
    <vuln_soft>
      <prod name="h2o" vendor="h2o_project">
        <vers num="2.2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10909" seq="2017-10909" published="2017-12-22" modified="2018-01-09" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN60695371/index.html" adv="1">JVN#60695371</ref>
    </refs>
    <vuln_soft>
      <prod name="music_center" vendor="sony">
        <vers num="1.0.01" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10910" seq="2017-10910" published="2017-12-27" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e9923" adv="1" patch="1">https://github.com/mqttjs/MQTT.js/commit/403ba53b838f2d319a0c0505a045fe00239e9923</ref>
      <ref source="MISC" url="https://github.com/mqttjs/MQTT.js/releases/tag/v2.15.0" adv="1">https://github.com/mqttjs/MQTT.js/releases/tag/v2.15.0</ref>
      <ref source="JVN" url="https://jvn.jp/en/jp/JVN45494523/index.html" adv="1">JVN#45494523</ref>
    </refs>
    <vuln_soft>
      <prod name="mqtt.js" vendor="mqtt.js_project">
        <vers num="2.0.0" edition=":~~~node.js~~"/>
        <vers num="2.0.1" edition=":~~~node.js~~"/>
        <vers num="2.1.0" edition=":~~~node.js~~"/>
        <vers num="2.1.1" edition=":~~~node.js~~"/>
        <vers num="2.1.2" edition=":~~~node.js~~"/>
        <vers num="2.1.3" edition=":~~~node.js~~"/>
        <vers num="2.2.0" edition=":~~~node.js~~"/>
        <vers num="2.2.1" edition=":~~~node.js~~"/>
        <vers num="2.3.0" edition=":~~~node.js~~"/>
        <vers num="2.3.1" edition=":~~~node.js~~"/>
        <vers num="2.4.0" edition=":~~~node.js~~"/>
        <vers num="2.5.0" edition=":~~~node.js~~"/>
        <vers num="2.5.1" edition=":~~~node.js~~"/>
        <vers num="2.5.2" edition=":~~~node.js~~"/>
        <vers num="2.6.0" edition=":~~~node.js~~"/>
        <vers num="2.6.1" edition=":~~~node.js~~"/>
        <vers num="2.6.2" edition=":~~~node.js~~"/>
        <vers num="2.7.0" edition=":~~~node.js~~"/>
        <vers num="2.7.2" edition=":~~~node.js~~"/>
        <vers num="2.8.0" edition=":~~~node.js~~"/>
        <vers num="2.8.1" edition=":~~~node.js~~"/>
        <vers num="2.8.2" edition=":~~~node.js~~"/>
        <vers num="2.9.0" edition=":~~~node.js~~"/>
        <vers num="2.9.1" edition=":~~~node.js~~"/>
        <vers num="2.9.2" edition=":~~~node.js~~"/>
        <vers num="2.9.3" edition=":~~~node.js~~"/>
        <vers num="2.10.0" edition=":~~~node.js~~"/>
        <vers num="2.11.0" edition=":~~~node.js~~"/>
        <vers num="2.12.0" edition=":~~~node.js~~"/>
        <vers num="2.12.1" edition=":~~~node.js~~"/>
        <vers num="2.13.0" edition=":~~~node.js~~"/>
        <vers num="2.13.1" edition=":~~~node.js~~"/>
        <vers num="2.14.0" edition=":~~~node.js~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10911" seq="2017-10911" published="2017-07-04" modified="2018-09-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3920">DSA-3920</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3927">DSA-3927</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3945">DSA-3945</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8" adv="1">http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99162" adv="1">99162</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038720" adv="1">1038720</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341" adv="1" patch="1">https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html">[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-216.html" adv="1">https://xenbits.xen.org/xsa/advisory-216.html</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10912" seq="2017-10912" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99158">99158</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038721">1038721</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-217.html" adv="1">https://xenbits.xen.org/xsa/advisory-217.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10913" seq="2017-10913" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99411" adv="1">99411</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038722">1038722</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-218.html" adv="1">https://xenbits.xen.org/xsa/advisory-218.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10914" seq="2017-10914" published="2017-07-04" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99411" adv="1">99411</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038722">1038722</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-218.html" adv="1">https://xenbits.xen.org/xsa/advisory-218.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10915" seq="2017-10915" published="2017-07-04" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99174" adv="1">99174</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-219.html" adv="1">https://xenbits.xen.org/xsa/advisory-219.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10916" seq="2017-10916" published="2017-07-04" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99167">99167</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038730">1038730</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-220.html" adv="1">https://xenbits.xen.org/xsa/advisory-220.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.5.0"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.5"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.7.1"/>
        <vers num="4.8.0"/>
        <vers num="4.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10917" seq="2017-10917" published="2017-07-04" modified="2017-11-03" severity="High" CVSS_version="2.0" CVSS_score="9.4" CVSS_base_score="9.4" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:C)">
    <desc>
      <descript source="cve">Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99157">99157</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038731">1038731</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-221.html" adv="1">https://xenbits.xen.org/xsa/advisory-221.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10918" seq="2017-10918" published="2017-07-04" modified="2017-11-03" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99161" adv="1">99161</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038732">1038732</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-222.html" adv="1">https://xenbits.xen.org/xsa/advisory-222.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10919" seq="2017-10919" published="2017-07-04" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99159" adv="1">99159</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038733">1038733</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-223.html" adv="1">https://xenbits.xen.org/xsa/advisory-223.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1092" seq="2017-1092" published="2017-05-22" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22002897" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22002897</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42091/">42091</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42541/">42541</ref>
    </refs>
    <vuln_soft>
      <prod name="informix_open_admin_tool" vendor="ibm">
        <vers num="11.5"/>
        <vers num="11.7"/>
        <vers num="12.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10920" seq="2017-10920" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038734">1038734</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-224.html" adv="1" patch="1">https://xenbits.xen.org/xsa/advisory-224.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10921" seq="2017-10921" published="2017-07-04" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038734">1038734</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-224.html" adv="1" patch="1">https://xenbits.xen.org/xsa/advisory-224.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10922" seq="2017-10922" published="2017-07-04" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3969">DSA-3969</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038734">1038734</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-17">GLSA-201710-17</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-224.html" adv="1" patch="1">https://xenbits.xen.org/xsa/advisory-224.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.8.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10923" seq="2017-10923" published="2017-07-04" modified="2017-08-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99160" sig="1">99160</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038735" adv="1">1038735</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201708-03">GLSA-201708-03</ref>
      <ref source="CONFIRM" url="https://xenbits.xen.org/xsa/advisory-225.html" adv="1">https://xenbits.xen.org/xsa/advisory-225.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xen" vendor="xen">
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.7.1"/>
        <vers num="4.8.0"/>
        <vers num="4.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10924" seq="2017-10924" published="2017-07-05" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.net/main_history.htm">http://www.irfanview.net/main_history.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10924" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10924</ref>
    </refs>
    <vuln_soft>
      <prod name="fpx" vendor="irfanview">
        <vers num="4.47"/>
      </prod>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10925" seq="2017-10925" published="2017-07-05" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b3ae."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.net/main_history.htm">http://www.irfanview.net/main_history.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10925" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10925</ref>
    </refs>
    <vuln_soft>
      <prod name="fpx" vendor="irfanview">
        <vers num="4.47"/>
      </prod>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10926" seq="2017-10926" published="2017-07-05" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.irfanview.net/main_history.htm">http://www.irfanview.net/main_history.htm</ref>
      <ref source="MISC" url="https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10926" adv="1">https://github.com/wlinzi/security_advisories/tree/master/CVE-2017-10926</ref>
    </refs>
    <vuln_soft>
      <prod name="fpx" vendor="irfanview">
        <vers num="4.47"/>
      </prod>
      <prod name="irfanview" vendor="irfanview">
        <vers num="4.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10928" seq="2017-10928" published="2017-07-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99480" adv="1">99480</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/539" adv="1">https://github.com/ImageMagick/ImageMagick/issues/539</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10929" seq="2017-10929" published="2017-07-05" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99608" adv="1">99608</ref>
      <ref source="CONFIRM" url="https://github.com/radare/radare2/commit/c57997e76ec70862174a1b3b3aeb62a6f8570e85" adv="1" patch="1">https://github.com/radare/radare2/commit/c57997e76ec70862174a1b3b3aeb62a6f8570e85</ref>
      <ref source="CONFIRM" url="https://github.com/radare/radare2/issues/7855" adv="1">https://github.com/radare/radare2/issues/7855</ref>
    </refs>
    <vuln_soft>
      <prod name="radare2" vendor="radare">
        <vers num="1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1093" seq="2017-1093" published="2017-02-02" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM AIX 6.1, 7.1, and 7.2 could allow a local user to exploit a vulnerability in the bellmail binary to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://aix.software.ibm.com/aix/efixes/security/bellmail_advisory2.asc" adv="1">http://aix.software.ibm.com/aix/efixes/security/bellmail_advisory2.asc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/95891" adv="1">95891</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037748">1037748</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="6.1"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10930" seq="2017-10930" published="2017-09-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262</ref>
    </refs>
    <vuln_soft>
      <prod name="zxr10_1800-2s_firmware" vendor="zte">
        <vers num="-" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10931" seq="2017-10931" published="2017-09-19" modified="2017-09-27" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262</ref>
    </refs>
    <vuln_soft>
      <prod name="zxr10_1800-2s_firmware" vendor="zte">
        <vers num="-" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10932" seq="2017-10932" published="2017-09-27" modified="2017-10-11" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008422" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008422</ref>
    </refs>
    <vuln_soft>
      <prod name="nr8000tr_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
      <prod name="nr8120_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
      <prod name="nr8120a_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
      <prod name="nr8150_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
      <prod name="nr8250_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
      <prod name="nr8950_firmware" vendor="zte">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10933" seq="2017-10933" published="2017-10-19" modified="2017-11-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008582" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008582</ref>
    </refs>
    <vuln_soft>
      <prod name="zxdt22_sf01_firmware" vendor="zte">
        <vers num="v2.06.00.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10934" seq="2017-10934" published="2018-07-25" modified="2018-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008682" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008682</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10935" seq="2017-10935" published="2018-07-25" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008723" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008723</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10936" seq="2017-10936" published="2018-07-25" modified="2018-09-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008722" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008722</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10937" seq="2017-10937" published="2018-07-25" modified="2018-09-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008782" adv="1">http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008782</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10938" seq="2017-10938" published="2018-02-27" modified="2018-02-27" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10939" seq="2017-10939" published="2018-02-27" modified="2018-02-27" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10940" seq="2017-10940" published="2017-10-31" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-ab42837916ad). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the docker API. The process does not properly validate user-supplied data which can allow for the upload of arbitrary files. An attacker can leverage this vulnerability to execute arbitrary code under the context of root. Was ZDI-CAN-3853.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99510" adv="1">99510</ref>
      <ref source="CONFIRM" url="https://help.joyent.com/hc/en-us/articles/115009649927-Security-Advisory-ZDI-CAN-3853-Docker-File-Overwrite-Vulnerability" adv="1">https://help.joyent.com/hc/en-us/articles/115009649927-Security-Advisory-ZDI-CAN-3853-Docker-File-Overwrite-Vulnerability</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-453" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-453</ref>
    </refs>
    <vuln_soft>
      <prod name="triton_datacenter" vendor="joyent">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10941" seq="2017-10941" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the AFParseDateEx function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4816.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-454" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-454</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10942" seq="2017-10942" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4737.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-455" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-455</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10943" seq="2017-10943" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4738.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-456" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-456</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10944" seq="2017-10944" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ObjStm objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-4846.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-457" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-457</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10945" seq="2017-10945" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the app.alert function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4855.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-458" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-458</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10946" seq="2017-10946" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the setItem function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4721.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-459" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-459</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.2.1.6871"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10947" seq="2017-10947" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the print function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4722.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-460" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-460</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.2.1.6871"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10948" seq="2017-10948" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the app.execMenuItem function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4723.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101670" adv="1">101670</ref>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-461" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-461</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.2.1.6871"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10949" seq="2017-10949" published="2017-08-04" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf" adv="1">http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100138" adv="1">100138</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-523" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-523</ref>
    </refs>
    <vuln_soft>
      <prod name="storage_manager_2016" vendor="dell">
        <vers num="r2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10950" seq="2017-10950" published="2017-08-29" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100418" adv="1">100418</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-693" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-693</ref>
    </refs>
    <vuln_soft>
      <prod name="total_security" vendor="bitdefender">
        <vers num="21.0.24.62"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10951" seq="2017-10951" published="2017-08-29" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within app.launchURL method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4724.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100409" adv="1">100409</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039213" adv="1">1039213</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-691" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-691</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10952" seq="2017-10952" published="2017-08-29" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100412" adv="1">100412</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039212" adv="1">1039212</ref>
      <ref source="MISC" url="https://0patch.blogspot.com/2017/08/0patching-foxit-readers-saveas-0day-cve.html" adv="1">https://0patch.blogspot.com/2017/08/0patching-foxit-readers-saveas-0day-cve.html</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-692" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-692</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.2.0.2051"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10953" seq="2017-10953" published="2017-10-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the gotoURL method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5030.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100682" adv="1">100682</ref>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-718" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-718</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10954" seq="2017-10954" published="2017-10-31" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security Internet Security 2018 prior to build 7.72918. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within pdf.xmd. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code under the context of SYSTEM. Was ZDI-CAN-4361.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100676" adv="1">100676</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-717" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-717</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2017-10955" seq="2017-10955" published="2017-10-19" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">** DISPUTED ** This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the preScript parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute arbitrary code under the context of SYSTEM. Was ZDI-CAN-4697. NOTE: Dell EMC disputes that this is a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101008" adv="1">101008</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-812" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-812</ref>
    </refs>
    <vuln_soft>
      <prod name="data_protection_advisor" vendor="emc">
        <vers num="6.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10956" seq="2017-10956" published="2017-12-20" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the tile index member of SOT markers. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4978.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-858" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-858</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.1.21155"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10957" seq="2017-10957" published="2017-12-20" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the arrowEnd attribute of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4979.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-859" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-859</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.1.21155"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10958" seq="2017-10958" published="2017-12-20" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the value attribute of Field objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4980.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-860" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-860</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.1.21155"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10959" seq="2017-10959" published="2017-12-20" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the setAction method of Link objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4981.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1" patch="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
      <ref source="MISC" url="https://zerodayinitiative.com/advisories/ZDI-17-861" adv="1">https://zerodayinitiative.com/advisories/ZDI-17-861</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.1.21155"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1096" seq="2017-1096" published="2017-07-05" modified="2017-07-14" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22001007" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22001007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99353" adv="1">99353</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120656" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120656</ref>
    </refs>
    <vuln_soft>
      <prod name="jazz_reporting_service" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10961" seq="2017-10961" published="2017-07-18" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://community.projectredcap.org/articles/13/changelog-standard-release.html">https://community.projectredcap.org/articles/13/changelog-standard-release.html</ref>
      <ref source="MISC" url="https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae" adv="1">https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae</ref>
    </refs>
    <vuln_soft>
      <prod name="redcap" vendor="project-redcap">
        <vers num="7.5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10962" seq="2017-10962" published="2017-07-18" modified="2017-07-24" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">REDCap before 7.5.1 has XSS via the query string.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://community.projectredcap.org/articles/13/changelog-standard-release.html">https://community.projectredcap.org/articles/13/changelog-standard-release.html</ref>
      <ref source="MISC" url="https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae" adv="1">https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae</ref>
    </refs>
    <vuln_soft>
      <prod name="redcap" vendor="project-redcap">
        <vers num="7.5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10963" seq="2017-10963" published="2018-02-20" modified="2018-03-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://gist.github.com/e96e02/12ce905e3b724954273dd7d543a968f1" adv="1">https://gist.github.com/e96e02/12ce905e3b724954273dd7d543a968f1</ref>
      <ref source="MISC" url="https://www.lgsinnovations.com/lgs-innovations-discovers-samsung-mobile-product-security-vulnerability/" adv="1">https://www.lgsinnovations.com/lgs-innovations-discovers-samsung-mobile-product-security-vulnerability/</ref>
    </refs>
    <vuln_soft>
      <prod name="knox_enterprise_mobility_management" vendor="samsung">
        <vers num="16.11"/>
      </prod>
      <prod name="knox_identity_access_management" vendor="samsung">
        <vers num="16.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10965" seq="2017-10965" published="2017-07-07" modified="2017-11-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291" adv="1" patch="1">https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291</ref>
      <ref source="CONFIRM" url="https://irssi.org/security/irssi_sa_2017_07.txt" adv="1" patch="1">https://irssi.org/security/irssi_sa_2017_07.txt</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4016">DSA-4016</ref>
    </refs>
    <vuln_soft>
      <prod name="irssi" vendor="irssi">
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10966" seq="2017-10966" published="2017-07-07" modified="2017-11-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291" adv="1" patch="1">https://github.com/irssi/irssi/commit/5e26325317c72a04c1610ad952974e206384d291</ref>
      <ref source="CONFIRM" url="https://irssi.org/security/irssi_sa_2017_07.txt" adv="1" patch="1">https://irssi.org/security/irssi_sa_2017_07.txt</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4016">DSA-4016</ref>
    </refs>
    <vuln_soft>
      <prod name="irssi" vendor="irssi">
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10967" seq="2017-10967" published="2017-07-06" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/andrzuk/FineCMS/pull/9" adv="1">https://github.com/andrzuk/FineCMS/pull/9</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10968" seq="2017-10968" published="2017-07-07" modified="2017-07-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "&lt;?php" in a route=template request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/finecms_codeexec/finecmscodeexec_2017_07_06_submit.html" adv="1">http://www.yuesec.com/img/cccccve/finecms_codeexec/finecmscodeexec_2017_07_06_submit.html</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1097" seq="2017-1097" published="2017-09-05" modified="2017-09-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 120657.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22006963" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22006963</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120657">https://exchange.xforce.ibmcloud.com/vulnerabilities/120657</ref>
    </refs>
    <vuln_soft>
      <prod name="emptoris_strategic_supply_management" vendor="ibm">
        <vers num="10.0.0.0"/>
        <vers num="10.0.0.1"/>
        <vers num="10.0.0.2"/>
        <vers num="10.0.0.3"/>
        <vers num="10.0.1.0"/>
        <vers num="10.0.1.1"/>
        <vers num="10.0.1.2"/>
        <vers num="10.0.1.3"/>
        <vers num="10.0.1.4"/>
        <vers num="10.0.2.0"/>
        <vers num="10.0.2.1"/>
        <vers num="10.0.2.2"/>
        <vers num="10.0.2.3"/>
        <vers num="10.0.2.4"/>
        <vers num="10.0.2.5"/>
        <vers num="10.0.2.6"/>
        <vers num="10.0.2.7"/>
        <vers num="10.0.2.8"/>
        <vers num="10.0.2.9"/>
        <vers num="10.0.2.10"/>
        <vers num="10.0.2.11"/>
        <vers num="10.0.2.12"/>
        <vers num="10.0.2.13"/>
        <vers num="10.0.2.14"/>
        <vers num="10.0.2.15"/>
        <vers num="10.0.2.16"/>
        <vers num="10.0.2.17"/>
        <vers num="10.0.4.0"/>
        <vers num="10.1.0.0"/>
        <vers num="10.1.0.1"/>
        <vers num="10.1.0.2"/>
        <vers num="10.1.0.3"/>
        <vers num="10.1.0.4"/>
        <vers num="10.1.0.5"/>
        <vers num="10.1.0.6"/>
        <vers num="10.1.0.7"/>
        <vers num="10.1.0.8"/>
        <vers num="10.1.0.9"/>
        <vers num="10.1.0.10"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.0.12"/>
        <vers num="10.1.0.13"/>
        <vers num="10.1.0.14"/>
        <vers num="10.1.1.0"/>
        <vers num="10.1.1.1"/>
        <vers num="10.1.1.2"/>
        <vers num="10.1.1.3"/>
        <vers num="10.1.1.4"/>
        <vers num="10.1.1.5"/>
        <vers num="10.1.1.6"/>
        <vers num="10.1.1.7"/>
        <vers num="10.1.1.8"/>
        <vers num="10.1.1.9"/>
        <vers num="10.1.1.10"/>
        <vers num="10.1.1.11"/>
        <vers num="10.1.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10970" seq="2017-10970" published="2017-07-06" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038908">1038908</ref>
      <ref source="CONFIRM" url="https://github.com/Cacti/cacti/issues/838" adv="1">https://github.com/Cacti/cacti/issues/838</ref>
    </refs>
    <vuln_soft>
      <prod name="cacti" vendor="cacti">
        <vers num="1.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10971" seq="2017-10971" published="2017-07-06" modified="2017-11-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3905">DSA-3905</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99546" adv="1">99546</ref>
      <ref source="MISC" url="https://bugzilla.suse.com/show_bug.cgi?id=1035283" adv="1">https://bugzilla.suse.com/show_bug.cgi?id=1035283</ref>
      <ref source="MISC" url="https://cgit.freedesktop.org/xorg/xserver/commit/?id=215f894965df5fb0bb45b107d84524e700d2073c" adv="1">https://cgit.freedesktop.org/xorg/xserver/commit/?id=215f894965df5fb0bb45b107d84524e700d2073c</ref>
      <ref source="MISC" url="https://cgit.freedesktop.org/xorg/xserver/commit/?id=8caed4df36b1f802b4992edcfd282cbeeec35d9d" adv="1">https://cgit.freedesktop.org/xorg/xserver/commit/?id=8caed4df36b1f802b4992edcfd282cbeeec35d9d</ref>
      <ref source="MISC" url="https://cgit.freedesktop.org/xorg/xserver/commit/?id=ba336b24052122b136486961c82deac76bbde455" adv="1">https://cgit.freedesktop.org/xorg/xserver/commit/?id=ba336b24052122b136486961c82deac76bbde455</ref>
    </refs>
    <vuln_soft>
      <prod name="xorg-server" vendor="x.org">
        <vers num="1.19.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10972" seq="2017-10972" published="2017-07-06" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3905">DSA-3905</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99543" adv="1">99543</ref>
      <ref source="MISC" url="https://bugzilla.suse.com/show_bug.cgi?id=1035283" adv="1">https://bugzilla.suse.com/show_bug.cgi?id=1035283</ref>
      <ref source="MISC" url="https://cgit.freedesktop.org/xorg/xserver/commit/?id=05442de962d3dc624f79fc1a00eca3ffc5489ced" adv="1" patch="1">https://cgit.freedesktop.org/xorg/xserver/commit/?id=05442de962d3dc624f79fc1a00eca3ffc5489ced</ref>
    </refs>
    <vuln_soft>
      <prod name="xorg-server" vendor="x.org">
        <vers num="1.19.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10973" seq="2017-10973" published="2017-07-06" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/andrzuk/FineCMS/pull/10" adv="1">https://github.com/andrzuk/FineCMS/pull/10</ref>
      <ref source="CONFIRM" url="https://github.com/andrzuk/FineCMS/pull/11" adv="1">https://github.com/andrzuk/FineCMS/pull/11</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="2017-05-12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10974" seq="2017-10974" published="2017-07-07" modified="2017-07-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://hyp3rlinx.altervista.org/advisories/YAWS-WEB-SERVER-v1.91-UNAUTHENTICATED-REMOTE-FILE-DISCLOSURE.txt" adv="1">http://hyp3rlinx.altervista.org/advisories/YAWS-WEB-SERVER-v1.91-UNAUTHENTICATED-REMOTE-FILE-DISCLOSURE.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99515" adv="1">99515</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42303/" adv="1">42303</ref>
    </refs>
    <vuln_soft>
      <prod name="yaws" vendor="yaws">
        <vers num="1.91"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10975" seq="2017-10975" published="2017-07-06" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://framagit.org/luc/lutim/issues/40" adv="1">https://framagit.org/luc/lutim/issues/40</ref>
    </refs>
    <vuln_soft>
      <prod name="lutim" vendor="lutim_project">
        <vers num="0.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10976" seq="2017-10976" published="2017-07-06" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/28" adv="1">https://github.com/matthiaskramm/swftools/issues/28</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10978" seq="2017-10978" published="2017-07-17" modified="2019-07-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930" adv="1">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99893" adv="1">99893</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759" adv="1">RHSA-2017:1759</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389" adv="1">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0"/>
        <vers num="2.0.0" edition="-"/>
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="3.0.0" edition="-"/>
        <vers num="3.0.0" edition="beta0"/>
        <vers num="3.0.0" edition="beta1"/>
        <vers num="3.0.0" edition="rc0"/>
        <vers num="3.0.0" edition="rc1"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4" edition="-"/>
        <vers num="3.0.4" edition="rc0"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.4" edition="rc2"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7" edition="-"/>
        <vers num="3.0.7" edition="rc0"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="enterprise_linux_server_aus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
      </prod>
      <prod name="enterprise_linux_server_eus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
      </prod>
      <prod name="enterprise_linux_server_tus" vendor="redhat">
        <vers num="7.4"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10979" seq="2017-10979" published="2017-07-17" modified="2018-01-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99901">99901</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759">RHSA-2017:1759</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1098" seq="2017-1098" published="2017-09-07" modified="2017-09-14" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22005824" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22005824</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120658" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120658</ref>
    </refs>
    <vuln_soft>
      <prod name="emptoris_supplier_lifecycle_management" vendor="ibm">
        <vers num="10.1.0.0"/>
        <vers num="10.1.0.1"/>
        <vers num="10.1.0.2"/>
        <vers num="10.1.0.3"/>
        <vers num="10.1.0.4"/>
        <vers num="10.1.0.5"/>
        <vers num="10.1.0.6"/>
        <vers num="10.1.0.7"/>
        <vers num="10.1.0.8"/>
        <vers num="10.1.0.9"/>
        <vers num="10.1.0.10"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.0.12"/>
        <vers num="10.1.0.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10980" seq="2017-10980" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99905">99905</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759">RHSA-2017:1759</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10981" seq="2017-10981" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99898">99898</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759">RHSA-2017:1759</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10982" seq="2017-10982" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99912">99912</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759">RHSA-2017:1759</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10983" seq="2017-10983" published="2017-07-17" modified="2018-01-04" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99915">99915</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038914" adv="1">1038914</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:1759">RHSA-2017:1759</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="2.0.0" edition="pre1"/>
        <vers num="2.0.0" edition="pre2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10984" seq="2017-10984" published="2017-07-17" modified="2018-01-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99876">99876</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10985" seq="2017-10985" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99968">99968</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10986" seq="2017-10986" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1" patch="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99971">99971</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10987" seq="2017-10987" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freeradius.org/security/fuzzer-2017.html" adv="1">http://freeradius.org/security/fuzzer-2017.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3930">DSA-3930</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99970">99970</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2389">RHSA-2017:2389</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10988" seq="2017-10988" published="2017-07-17" modified="2017-07-17" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-10989" seq="2017-10989" published="2017-07-07" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00050.html">openSUSE-SU-2019:1426</ref>
      <ref source="MISC" url="http://marc.info/?l=sqlite-users&amp;m=149933696214713&amp;w=2" adv="1" patch="1">http://marc.info/?l=sqlite-users&amp;m=149933696214713&amp;w=2</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html">http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99502" adv="1">99502</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039427">1039427</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2405">https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2405</ref>
      <ref source="MISC" url="https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1700937" adv="1" patch="1">https://bugs.launchpad.net/ubuntu/+source/sqlite3/+bug/1700937</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/01/msg00009.html">[debian-lts-announce] 20190111 [SECURITY] [DLA 1633-1] sqlite3 security update</ref>
      <ref source="MISC" url="https://sqlite.org/src/info/66de6f4a" adv="1" patch="1">https://sqlite.org/src/info/66de6f4a</ref>
      <ref source="MISC" url="https://sqlite.org/src/vpatch?from=0db20efe201736b3&amp;to=66de6f4a9504ec26" adv="1" patch="1">https://sqlite.org/src/vpatch?from=0db20efe201736b3&amp;to=66de6f4a9504ec26</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113">https://support.apple.com/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208115">https://support.apple.com/HT208115</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208144">https://support.apple.com/HT208144</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/4019-1/">USN-4019-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/4019-2/">USN-4019-2</ref>
    </refs>
    <vuln_soft>
      <prod name="sqlite" vendor="sqlite">
        <vers num="3.19.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1099" seq="2017-1099" published="2017-06-13" modified="2017-06-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004534" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22004534</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120659" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120659</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_collaborative_lifecycle_management" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_doors_next_generation" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_engineering_lifecycle_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_rhapsody_design_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_software_architect_design_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
      <prod name="rational_team_concert" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10991" seq="2017-10991" published="2017-07-07" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://lorexxar.cn/2017/07/07/WordPress%20WP%20Statistics%20authenticated%20xss%20Vulnerability(WP%20Statistics%20-=12.0.9)/">https://lorexxar.cn/2017/07/07/WordPress%20WP%20Statistics%20authenticated%20xss%20Vulnerability(WP%20Statistics%20-=12.0.9)/</ref>
    </refs>
    <vuln_soft>
      <prod name="wp_statistics" vendor="wp-statistics">
        <vers num="12.0.9" prev="1" edition=":~~~wordpress~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10993" seq="2017-10993" published="2017-07-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://contao.org/en/news/contao-3_5_28.html" adv="1">https://contao.org/en/news/contao-3_5_28.html</ref>
    </refs>
    <vuln_soft>
      <prod name="contao_cms" vendor="contao">
        <vers num="3.5.27" prev="1"/>
        <vers num="4.0.0" edition="beta1"/>
        <vers num="4.0.0" edition="rc1"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1.0" edition="beta1"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.2.0" edition="beta1"/>
        <vers num="4.2.0" edition="rc1"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.3.0" edition="rc1"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.4.0" edition="beta1"/>
        <vers num="4.4.0" edition="rc1"/>
        <vers num="4.4.0" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10994" seq="2017-10994" published="2017-07-07" modified="2017-08-23" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99499" adv="1">99499</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039113">1039113</ref>
      <ref source="CONFIRM" url="https://www.foxitsoftware.com/support/security-bulletins.php" adv="1">https://www.foxitsoftware.com/support/security-bulletins.php</ref>
    </refs>
    <vuln_soft>
      <prod name="foxit_reader" vendor="foxitsoftware">
        <vers num="8.3.0.14878" prev="1"/>
      </prod>
      <prod name="phantompdf" vendor="foxitsoftware">
        <vers num="8.3.0.14878" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10995" seq="2017-10995" published="2017-07-07" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99496" adv="1">99496</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/538" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/538</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3681-1/">USN-3681-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4204">DSA-4204</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10996" seq="2017-10996" published="2017-09-21" modified="2017-09-26" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10997" seq="2017-10997" published="2017-09-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10998" seq="2017-10998" published="2017-09-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region. If the buffer length is large enough then the address + length operation could overflow and produce a result far below the valid region.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-10999" seq="2017-10999" published="2017-09-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1100" seq="2017-1100" published="2017-06-13" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120661.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004428" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004428</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99006" adv="1">99006</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038698">1038698</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120661" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120661</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11000" seq="2017-11000" published="2017-09-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11001" seq="2017-11001" published="2017-09-21" modified="2017-09-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11002" seq="2017-11002" published="2017-09-21" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11003" seq="2017-11003" published="2018-01-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating a firmware image, data is read from flash into RAM without checking that the data fits into allotted RAM size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11004" seq="2017-11004" published="2019-01-03" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/106128" adv="1">106128</ref>
      <ref source="CONFIRM" url="https://www.qualcomm.com/company/product-security/bulletins" adv="1">https://www.qualcomm.com/company/product-security/bulletins</ref>
    </refs>
    <vuln_soft>
      <prod name="ipq8074_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9206_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9607_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9635m_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9650_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9655_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="msm8996au_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_205_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_210_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_212_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_410_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_412_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_415_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_425_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_427_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_429_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_430_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_435_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_439_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_450_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_615_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_616_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_625_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_632_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_636_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_650_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_652_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_810_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_820_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_820a_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_835_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sda660_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sdm439_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sdm630_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sdm660_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sdx24_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="snapdragon_high_med_2016_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11005" seq="2017-11005" published="2017-12-05" modified="2017-12-15" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during a deinitialization path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102072" adv="1">102072</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11006" seq="2017-11006" published="2017-12-05" modified="2017-12-15" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during positioning.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102072" adv="1">102072</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11007" seq="2017-11007" published="2017-12-05" modified="2017-12-15" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of stack corruption due to buffer overflow of Partition name while converting ascii string to unicode string in function HandleMetaImgFlash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102073" adv="1">102073</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1101" seq="2017-1101" published="2017-06-13" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120662.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004428" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004428</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98997" adv="1">98997</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038698">1038698</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120662" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120662</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11010" seq="2017-11010" published="2018-03-30" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102386" adv="1">102386</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040106" adv="1">1040106</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-01-01" adv="1">https://source.android.com/security/bulletin/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11011" seq="2017-11011" published="2018-04-11" modified="2018-05-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 835, a Use After Free condition can occur in a communication API.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/103671" adv="1">103671</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-04-01" adv="1">https://source.android.com/security/bulletin/2018-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="mdm9206_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="mdm9607_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_205_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_210_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_212_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_425_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_430_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_450_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_625_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_820_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_835_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11012" seq="2017-11012" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_ENCRYPTION_TEST cfg80211 vendor command a stack-based buffer overflow can occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11013" seq="2017-11013" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, countOffset (in function UnpackCore) is increased for each loop, while there is no boundary check against "pIe->arraybound".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11014" seq="2017-11014" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing a Measurement Request IE in a Roam Neighbor Action Report, a buffer overflow can occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11015" seq="2017-11015" published="2017-11-16" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently, the value of SIR_MAC_AUTH_CHALLENGE_LENGTH is set to 128 which may result in buffer overflow since the frame parser allows challenge text of length up to 253 bytes, but the driver can not handle challenge text larger than 128 bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11016" seq="2017-11016" published="2017-12-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when memory allocation fails while creating a calibration block in create_cal_block stale pointers are left uncleared.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11017" seq="2017-11017" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially crafted UBI image, it is possible to corrupt memory, or access uninitialized memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11018" seq="2017-11018" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, array access out of bounds may occur in the camera driver in the kernel</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11019" seq="2017-11019" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the fd allocated during the get_metadata was not closed even though the buffer allocated to the fd was freed. This resulted in a failure during exit sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1102" seq="2017-1102" published="2017-06-13" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120663.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004428" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004428</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99008" adv="1">99008</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038698">1038698</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120663" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120663</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11022" seq="2017-11022" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the probe requests originated from user's phone contains the information elements which specifies the supported wifi features. This shall impact the user's privacy if someone sniffs the probe requests originated by this DUT. Hence, control the presence of information elements using ini file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11023" seq="2017-11023" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of out-of-bound buffer accesses due to no synchronization in accessing global variables by multiple threads.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11024" seq="2017-11024" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in the rmnet USB control driver can potentially lead to a Use After Free condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11025" seq="2017-11025" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the function audio_effects_shared_ioctl(), memory corruption can occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11026" seq="2017-11026" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using reference FRP unlock, authentication method can be compromised for static keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11027" seq="2017-11027" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11028" seq="2017-11028" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data().</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11029" seq="2017-11029" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides in user space. An unchecked userspace value (ioctl_ptr->len) is used to copy contents to a kernel buffer which can lead to kernel buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1103" seq="2017-1103" published="2017-05-10" modified="2017-05-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:C)">
    <desc>
      <descript source="cve">IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22002429" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22002429</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
      </prod>
      <prod name="rational_team_concert" vendor="ibm">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11030" seq="2017-11030" published="2017-12-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11031" seq="2017-11031" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl command can be used to cause a Use After Free condition.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11032" seq="2017-11032" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc fails to allocate memory for pointers resp/req in the service-locator driver function service_locator_send_msg().</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11033" seq="2017-11033" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the coresight-tmc driver, a simultaneous read and enable of the ETR device after changing the buffer size may result in a Use After Free condition of the previous buffer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11035" seq="2017-11035" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, possible buffer overflow or information leak in the functions "sme_set_ft_ies" and "csr_roam_issue_ft_preauth_req" due to incorrect initialization of WEXT callbacks and lack of the checks for buffer size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11038" seq="2017-11038" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the boot image header, range checks can be bypassed by supplying different versions of the header at the time of check and use.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1104" seq="2017-1104" published="2017-06-13" modified="2017-07-07" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120666.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004428" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004428</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99004" adv="1">99004</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038698">1038698</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120666" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120666</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_quality_manager" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11040" seq="2017-11040" published="2017-09-21" modified="2017-09-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11041" seq="2017-11041" published="2017-09-21" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100658" adv="1">100658</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-02-01">https://source.android.com/security/bulletin/2018-02-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11042" seq="2017-11042" published="2017-12-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL APIs are not subject to access control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11043" seq="2017-11043" published="2017-12-05" modified="2019-04-29" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a WiFI driver function, an integer overflow leading to heap buffer overflow may potentially occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102073" adv="1">102073</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-12-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-12-01</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-02-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-02-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11044" seq="2017-11044" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a KGSL driver function, a race condition exists which can lead to a Use After Free condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11045" seq="2017-11045" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race condition exists which can lead to a Use After Free condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11046" seq="2017-11046" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is called, a kernel out-of-bounds write can potentially occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11047" seq="2017-11047" published="2017-12-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a graphics driver ioctl handler, the lack of copy_from_user() function calls may result in writes to kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11048" seq="2017-11048" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use After Free condition can occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11049" seq="2017-11049" published="2017-12-05" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a video driver, a race condition exists which can potentially lead to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-12-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-12-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1105" seq="2017-1105" published="2017-06-27" modified="2017-07-06" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22003877" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22003877</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99264" adv="1">99264</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038773">1038773</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120668" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120668</ref>
    </refs>
    <vuln_soft>
      <prod name="data_server_client" vendor="ibm">
        <vers num="-"/>
      </prod>
      <prod name="data_server_driver_for_odbc_and_cli" vendor="ibm">
        <vers num="-"/>
      </prod>
      <prod name="data_server_driver_package" vendor="ibm">
        <vers num="-"/>
      </prod>
      <prod name="data_server_runtime_client" vendor="ibm">
        <vers num="-"/>
      </prod>
      <prod name="db2" vendor="ibm">
        <vers num="9.7" edition=":~~advanced_enterprise~~~"/>
        <vers num="9.7" edition=":~~advanced_workgroup~~~"/>
        <vers num="9.7" edition=":~~enterprise~~~"/>
        <vers num="9.7" edition=":~~express~~~"/>
        <vers num="9.7" edition=":~~workgroup~~~"/>
        <vers num="10.1" edition=":~~advanced_enterprise~~~"/>
        <vers num="10.1" edition=":~~advanced_workgroup~~~"/>
        <vers num="10.1" edition=":~~enterprise~~~"/>
        <vers num="10.1" edition=":~~express~~~"/>
        <vers num="10.1" edition=":~~workgroup~~~"/>
        <vers num="10.5" edition=":~~advanced_enterprise~~~"/>
        <vers num="10.5" edition=":~~advanced_workgroup~~~"/>
        <vers num="10.5" edition=":~~enterprise~~~"/>
        <vers num="10.5" edition=":~~express~~~"/>
        <vers num="10.5" edition=":~~workgroup~~~"/>
        <vers num="11.1" edition=":~~advanced_enterprise~~~"/>
        <vers num="11.1" edition=":~~advanced_workgroup~~~"/>
        <vers num="11.1" edition=":~~enterprise~~~"/>
        <vers num="11.1" edition=":~~express~~~"/>
        <vers num="11.1" edition=":~~workgroup~~~"/>
      </prod>
      <prod name="db2_connect" vendor="ibm">
        <vers num="9.7" edition=":~~application_server~~~"/>
        <vers num="9.7" edition=":~~enterprise~~~"/>
        <vers num="9.7" edition=":~~unlimited~~~"/>
        <vers num="10.1" edition=":~~application_server~~~"/>
        <vers num="10.1" edition=":~~enterprise~~~"/>
        <vers num="10.1" edition=":~~unlimited~~~"/>
        <vers num="10.5" edition=":~~application_server~~~"/>
        <vers num="10.5" edition=":~~enterprise~~~"/>
        <vers num="10.5" edition=":~~unlimited~~~"/>
        <vers num="11.1.0.0" edition=":~~application_server~~~"/>
        <vers num="11.1.0.0" edition=":~~enterprise~~~"/>
        <vers num="11.1.0.0" edition=":~~unlimited~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11050" seq="2017-11050" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when the pktlogconf tool gives a pktlog buffer of size less than the minimal possible source data size in the host driver, a buffer overflow can potentially occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11051" seq="2017-11051" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, information disclosure is possible in function __wlan_hdd_cfg80211_testmode since buffer hb_params is not initialized to zero.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11052" seq="2017-11052" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_NDP cfg80211 vendor command a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11053" seq="2017-11053" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when qos map set IE of length less than 16 is received in association response or in qos map configure action frame, a buffer overflow can potentially occur in ConvertQosMapsetFrame().</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101117" adv="1">101117</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-10-01" adv="1">https://source.android.com/security/bulletin/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11054" seq="2017-11054" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11055" seq="2017-11055" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION cfg80211 vendor command, a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11056" seq="2017-11056" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while doing sha and cipher operations, a userspace buffer is directly accessed in kernel space potentially leading to a page fault.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11057" seq="2017-11057" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in compatibility mode, flash_data from 64-bit userspace may cause disclosure of kernel memory or a fault due to using a userspace-provided address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11058" seq="2017-11058" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11059" seq="2017-11059" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1106" seq="2017-1106" published="2017-06-28" modified="2017-07-03" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004580" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22004580</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99306" adv="1">99306</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120744" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120744</ref>
    </refs>
    <vuln_soft>
      <prod name="curam_social_program_management" vendor="ibm">
        <vers num="5.2" edition="sp1"/>
        <vers num="5.2" edition="sp4"/>
        <vers num="5.2" edition="sp6"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0.0"/>
        <vers num="6.0.4.0"/>
        <vers num="6.0.4.1"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.4.3"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.4.5"/>
        <vers num="6.0.4.6"/>
        <vers num="6.0.4.7"/>
        <vers num="6.0.4.8"/>
        <vers num="6.0.4.9"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.0"/>
        <vers num="6.0.5.1"/>
        <vers num="6.0.5.2"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.5.4"/>
        <vers num="6.0.5.5"/>
        <vers num="6.0.5.6"/>
        <vers num="6.0.5.7"/>
        <vers num="6.0.5.8"/>
        <vers num="6.0.5.9"/>
        <vers num="6.0.5.10"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.4"/>
        <vers num="6.1.1.0"/>
        <vers num="6.1.1.1"/>
        <vers num="6.1.1.2"/>
        <vers num="6.1.1.3"/>
        <vers num="6.1.1.4"/>
        <vers num="6.2.0.0"/>
        <vers num="6.2.0.1"/>
        <vers num="6.2.0.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="7.0.0.0"/>
        <vers num="7.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11060" seq="2017-11060" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_LIST cfg80211 vendor commands in __wlan_hdd_cfg80211_set_passpoint_list and hdd_extscan_passpoint_fill_network_list function respectively. Android ID: A-36817548. References: QC-CR#2058447, QC-CR#2054770.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11061" seq="2017-11061" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub command QCA_NL80211_VENDOR_SUBCMD_ROAM, a buffer over-read can occur.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11062" seq="2017-11062" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validated in __wlan_hdd_cfg80211_do_acs which can potentially lead to a buffer overread.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11063" seq="2017-11063" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the driver concurrently, a null pointer dereference can potentially occur.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11064" seq="2017-11064" published="2017-10-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_LIST cfg80211 vendor commands in __wlan_hdd_cfg80211_set_passpoint_list and hdd_extscan_passpoint_fill_network_list function respectively. Android ID: A-36815952. References: QC-CR#2054770, QC-CR#2058447, QC-CR#2066628, QC-CR#2087785</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11066" seq="2017-11066" published="2018-01-10" modified="2018-01-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitialized memory could be accessed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11067" seq="2017-11067" published="2017-10-10" modified="2017-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentially lead to the use of an out-of-range pointer offset.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101160" adv="1">101160</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-10-01" adv="1">https://source.android.com/security/bulletin/pixel/2017-10-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11069" seq="2017-11069" published="2018-01-10" modified="2018-01-29" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102413" adv="1">102413</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1040106" adv="1">1040106</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1107" seq="2017-1107" published="2019-06-19" modified="2019-06-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/108918">108918</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120906" adv="1">ibm-marketing-cve20171107-info-disc (120906)</ref>
      <ref source="CONFIRM" url="https://www.ibm.com/support/docview.wss?uid=ibm10887815" adv="1" patch="1">https://www.ibm.com/support/docview.wss?uid=ibm10887815</ref>
    </refs>
    <vuln_soft>
      <prod name="marketing_platform" vendor="ibm">
        <vers num="9.1.0.0"/>
        <vers num="9.1.2"/>
        <vers num="10.0"/>
        <vers num="10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11072" seq="2017-11072" published="2018-01-16" modified="2018-02-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header fields with partition entries greater than 16384 buffer overflow occurs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11073" seq="2017-11073" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qcacld pktlog allows mapping memory via /proc/ath_pktlog/cld to user space.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11074" seq="2017-11074" published="2018-03-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is an obsolete set/reset ssid hotlist API.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-03-01" adv="1">https://source.android.com/security/bulletin/pixel/2018-03-01</ref>
      <ref source="MISC" url="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima/commit/?id=f5ae7b35c90f14b7e66b3a91d4fb247563a8a22b" adv="1" patch="1">https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima/commit/?id=f5ae7b35c90f14b7e66b3a91d4fb247563a8a22b</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11075" seq="2017-11075" published="2018-04-03" modified="2018-05-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if cmd_pkt and reg_pkt are called from different userspace threads, a use after free condition can potentially occur in wdsp_glink_write().</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-04-01" adv="1">https://source.android.com/security/bulletin/pixel/2018-04-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11078" seq="2017-11078" published="2018-11-27" modified="2018-12-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the boot image header, an out of bounds read can occur in boot.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=c975b4c716511c9086f6eb885f9a3524c428a19b" adv="1" patch="1">https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=c975b4c716511c9086f6eb885f9a3524c428a19b</ref>
      <ref source="CONFIRM" url="https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletin" adv="1" patch="1">https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletin</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11079" seq="2017-11079" published="2018-01-10" modified="2018-01-26" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing sparse image, uninitialized heap memory can potentially be flashed due to the lack of validation of sparse image block header size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11080" seq="2017-11080" published="2018-01-10" modified="2018-01-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a user supplied sparse image, a buffer overflow vulnerability could occur if the sparse header block size is equal to 4294967296.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11081" seq="2017-11081" published="2018-01-10" modified="2018-01-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a potential buffer overflow vulnerability in hdd_parse_setrmcenable_command and hdd_parse_setrmcactionperiod_command APIs as buffers defined in this API can hold maximum 32 bytes but data more than 32 bytes can get copied.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-01-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2018-01-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11082" seq="2017-11082" published="2018-03-16" modified="2018-04-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.4" CVSS_base_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in a firmware loading routine, a buffer overflow could potentially occur if multiple user space threads try to update the WLAN firmware file through sysfs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-03-01" adv="1">https://source.android.com/security/bulletin/pixel/2018-03-01</ref>
      <ref source="MISC" url="https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=2d4f8cd8d11f8fb1491a20d7e316cc0fd03eeb59" adv="1" patch="1">https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=2d4f8cd8d11f8fb1491a20d7e316cc0fd03eeb59</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11085" seq="2017-11085" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an integer overflow leading to a buffer overflow due to improper bound checking in msm_audio_effects_virtualizer_handler, file msm-audio-effects-q6-v2.c</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11087" seq="2017-11087" published="2018-03-30" modified="2018-04-25" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/103669" adv="1">103669</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2018-02-01" adv="1">https://source.android.com/security/bulletin/pixel/2018-02-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11088" seq="2017-11088" published="2018-07-06" modified="2018-09-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 835, SD 845.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.qualcomm.com/company/product-security/bulletins" adv="1">https://www.qualcomm.com/company/product-security/bulletins</ref>
    </refs>
    <vuln_soft>
      <prod name="msm8909w_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="msm8996au_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_205_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_210_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_212_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_430_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_450_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_617_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_625_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_650_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_652_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_820_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_835_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
      <prod name="sd_845_firmware" vendor="qualcomm">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11089" seq="2017-11089" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in nl80211_set_station when user space application sends attribute NL80211_ATTR_LOCAL_MESH_POWER_MODE with data of size less than 4 bytes</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3620-1/">USN-3620-1</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3620-2/">USN-3620-2</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11090" seq="2017-11090" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in __wlan_hdd_cfg80211_set_pmksa when user space application sends PMKID of size less than WLAN_PMKID_LEN bytes.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11091" seq="2017-11091" published="2017-11-16" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function mdss_rotator_ioctl in the driver /dev/mdss_rotator, a Use-After-Free condition can potentially occur due to a fence being installed too early.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11092" seq="2017-11092" published="2017-11-16" modified="2017-11-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function kgsl_ioctl_gpu_command, a Use After Free condition can potentially occur.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101774" adv="1">101774</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11093" seq="2017-11093" published="2017-11-16" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer Over-read in Display due to the lack of an upper-bound validation when reading "num_of_cea_blocks" from the untrusted source (EDID), kernel memory can be exposed.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/pixel/2017-11-01" adv="1" patch="1">https://source.android.com/security/bulletin/pixel/2017-11-01</ref>
    </refs>
    <vuln_soft>
      <prod name="android" vendor="google">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11096" seq="2017-11096" published="2017-07-07" modified="2017-07-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteFilter() function in lib/modules/swffilter.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/25" adv="1">https://github.com/matthiaskramm/swftools/issues/25</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11097" seq="2017-11097" published="2017-07-07" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/24" adv="1">https://github.com/matthiaskramm/swftools/issues/24</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11098" seq="2017-11098" published="2017-07-07" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/32" adv="1">https://github.com/matthiaskramm/swftools/issues/32</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11099" seq="2017-11099" published="2017-07-07" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/31" adv="1">https://github.com/matthiaskramm/swftools/issues/31</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1110" seq="2017-1110" published="2017-08-28" modified="2017-09-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22007161" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22007161</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/120915" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/120915</ref>
    </refs>
    <vuln_soft>
      <prod name="curam_social_program_management" vendor="ibm">
        <vers num="6.0.4.0"/>
        <vers num="6.0.4.1"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.4.3"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.4.5"/>
        <vers num="6.0.4.6"/>
        <vers num="6.0.4.7"/>
        <vers num="6.0.4.8"/>
        <vers num="6.0.4.9"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.0"/>
        <vers num="6.0.5.1"/>
        <vers num="6.0.5.2"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.5.4"/>
        <vers num="6.0.5.5"/>
        <vers num="6.0.5.6"/>
        <vers num="6.0.5.7"/>
        <vers num="6.0.5.8"/>
        <vers num="6.0.5.9"/>
        <vers num="6.0.5.10"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.4"/>
        <vers num="6.1.1.0"/>
        <vers num="6.1.1.1"/>
        <vers num="6.1.1.2"/>
        <vers num="6.1.1.3"/>
        <vers num="6.1.1.4"/>
        <vers num="6.2.0.0"/>
        <vers num="6.2.0.1"/>
        <vers num="6.2.0.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="7.0.0.0"/>
        <vers num="7.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11100" seq="2017-11100" published="2017-07-07" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/27" adv="1">https://github.com/matthiaskramm/swftools/issues/27</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11101" seq="2017-11101" published="2017-07-07" modified="2017-07-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/matthiaskramm/swftools/issues/26" adv="1">https://github.com/matthiaskramm/swftools/issues/26</ref>
    </refs>
    <vuln_soft>
      <prod name="swftools" vendor="swftools">
        <vers num="0.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11102" seq="2017-11102" published="2017-07-07" modified="2018-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data structure.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/d445af60a8d5" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/d445af60a8d5</ref>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/dea93a690fc1" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/dea93a690fc1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99498" adv="1">99498</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html">[debian-lts-announce] 20180803 [SECURITY] [DLA 1456-1] graphicsmagick security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11103" seq="2017-11103" published="2017-07-13" modified="2017-11-13" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3912">DSA-3912</ref>
      <ref source="CONFIRM" url="http://www.h5l.org/advisories.html?show=2017-07-11" adv="1">http://www.h5l.org/advisories.html?show=2017-07-11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99551" adv="1">99551</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038876" adv="1">1038876</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039427">1039427</ref>
      <ref source="CONFIRM" url="https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0" adv="1">https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208144">https://support.apple.com/HT208144</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208221">https://support.apple.com/HT208221</ref>
      <ref source="FREEBSD" url="https://www.freebsd.org/security/advisories/FreeBSD-SA-17:05.heimdal.asc" adv="1">FreeBSD-SA-17:05</ref>
      <ref source="MISC" url="https://www.orpheus-lyre.info/" adv="1">https://www.orpheus-lyre.info/</ref>
      <ref source="CONFIRM" url="https://www.samba.org/samba/security/CVE-2017-11103.html" adv="1">https://www.samba.org/samba/security/CVE-2017-11103.html</ref>
    </refs>
    <vuln_soft>
      <prod name="heimdal" vendor="h5l">
        <vers num="0.0a"/>
        <vers num="0.8"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="7.1.0"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
      </prod>
      <prod name="samba" vendor="samba">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.16"/>
        <vers num="4.0.17"/>
        <vers num="4.0.18"/>
        <vers num="4.0.19"/>
        <vers num="4.0.20"/>
        <vers num="4.0.21"/>
        <vers num="4.0.22"/>
        <vers num="4.0.23"/>
        <vers num="4.0.24"/>
        <vers num="4.0.25"/>
        <vers num="4.0.26"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.2.0" edition="rc1"/>
        <vers num="4.2.0" edition="rc2"/>
        <vers num="4.2.0" edition="rc3"/>
        <vers num="4.2.0" edition="rc4"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers num="4.2.10"/>
        <vers num="4.2.11"/>
        <vers num="4.2.12"/>
        <vers num="4.2.13"/>
        <vers num="4.2.14"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.4.0" edition="rc1"/>
        <vers num="4.4.0" edition="rc2"/>
        <vers num="4.4.0" edition="rc3"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11104" seq="2017-11104" published="2017-07-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3910">DSA-3910</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99598">99598</ref>
      <ref source="MISC" url="http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdf" adv="1" patch="1">http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdf</ref>
      <ref source="MISC" url="https://bugs.debian.org/865678" adv="1">https://bugs.debian.org/865678</ref>
      <ref source="MISC" url="https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html" adv="1" patch="1">https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html</ref>
    </refs>
    <vuln_soft>
      <prod name="knot_dns" vendor="knot-dns">
        <vers num="2.4.4" prev="1"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11105" seq="2017-11105" published="2017-08-03" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://alephsecurity.com/vulns/aleph-2017026" adv="1">https://alephsecurity.com/vulns/aleph-2017026</ref>
    </refs>
    <vuln_soft>
      <prod name="primary_bootloader" vendor="oneplus">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11107" seq="2017-11107" published="2017-07-08" modified="2019-03-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1701731" adv="1">https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1701731</ref>
      <ref source="MISC" url="https://github.com/leenooks/phpLDAPadmin/issues/50" adv="1" patch="1">https://github.com/leenooks/phpLDAPadmin/issues/50</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/10/msg00023.html" adv="1">[debian-lts-announce] 20181031 [SECURITY] [DLA 1561-1] phpldapadmin security update</ref>
    </refs>
    <vuln_soft>
      <prod name="phpldapadmin" vendor="phpldapadmin">
        <vers num="1.2.3" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11108" seq="2017-11108" published="2017-07-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3971">DSA-3971</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHEA-2018:0705">RHEA-2018:0705</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1468504" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1468504</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-23">GLSA-201709-23</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208221">https://support.apple.com/HT208221</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="tcpdump">
        <vers num="4.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11109" seq="2017-11109" published="2017-07-08" modified="2019-08-03" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1468492">https://bugzilla.redhat.com/show_bug.cgi?id=1468492</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/08/msg00003.html">[debian-lts-announce] 20190803 [SECURITY] [DLA 1871-1] vim security update</ref>
      <ref source="MISC." url="https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-11109.html" adv="1">https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-11109.html</ref>
    </refs>
    <vuln_soft>
      <prod name="vim" vendor="vim">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11110" seq="2017-11110" published="2017-07-08" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1468471">https://bugzilla.redhat.com/show_bug.cgi?id=1468471</ref>
    </refs>
    <vuln_soft>
      <prod name="catdoc" vendor="fossies">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11111" seq="2017-11111" published="2017-07-08" modified="2019-03-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.nasm.us/show_bug.cgi?id=3392415" adv="1">https://bugzilla.nasm.us/show_bug.cgi?id=3392415</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201903-19">GLSA-201903-19</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3694-1/" adv="1">USN-3694-1</ref>
    </refs>
    <vuln_soft>
      <prod name="netwide_assembler" vendor="nasm">
        <vers num="2.14" edition="rc0"/>
      </prod>
      <prod name="ubuntu_linux" vendor="canonical">
        <vers num="14.04" edition=":~~lts~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11112" seq="2017-11112" published="2017-07-08" modified="2018-10-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1464686">https://bugzilla.redhat.com/show_bug.cgi?id=1464686</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-13">GLSA-201804-13</ref>
    </refs>
    <vuln_soft>
      <prod name="ncurses" vendor="gnu">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11113" seq="2017-11113" published="2017-07-08" modified="2019-05-06" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1464691" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1464691</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-13" adv="1">GLSA-201804-13</ref>
    </refs>
    <vuln_soft>
      <prod name="ncurses" vendor="gnu">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11114" seq="2017-11114" published="2017-07-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/76" adv="1">http://seclists.org/fulldisclosure/2017/Jul/76</ref>
    </refs>
    <vuln_soft>
      <prod name="links" vendor="twibright">
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11115" seq="2017-11115" published="2017-07-31" modified="2017-11-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted jpg file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/77" adv="1">http://seclists.org/fulldisclosure/2017/Jul/77</ref>
      <ref source="MISC" url="https://sourceforge.net/p/openexif/bugs/18/">https://sourceforge.net/p/openexif/bugs/18/</ref>
    </refs>
    <vuln_soft>
      <prod name="openexif" vendor="openexif_project">
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11116" seq="2017-11116" published="2017-07-31" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/77" adv="1">http://seclists.org/fulldisclosure/2017/Jul/77</ref>
      <ref source="MISC" url="https://sourceforge.net/p/openexif/bugs/18/">https://sourceforge.net/p/openexif/bugs/18/</ref>
    </refs>
    <vuln_soft>
      <prod name="openexif" vendor="openexif_project">
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11117" seq="2017-11117" published="2017-07-31" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/77" adv="1">http://seclists.org/fulldisclosure/2017/Jul/77</ref>
      <ref source="MISC" url="https://sourceforge.net/p/openexif/bugs/18/">https://sourceforge.net/p/openexif/bugs/18/</ref>
    </refs>
    <vuln_soft>
      <prod name="openexif" vendor="openexif_project">
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11118" seq="2017-11118" published="2017-07-31" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted jpg file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/77" adv="1">http://seclists.org/fulldisclosure/2017/Jul/77</ref>
      <ref source="MISC" url="https://sourceforge.net/p/openexif/bugs/18/">https://sourceforge.net/p/openexif/bugs/18/</ref>
    </refs>
    <vuln_soft>
      <prod name="openexif" vendor="openexif_project">
        <vers num="2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11119" seq="2017-11119" published="2017-07-31" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The chk_mem_access function in cpu/nes6502/nes6502.c in libnosefart.a in Nosefart 2.9-mls allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted nsf file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/78" adv="1">http://seclists.org/fulldisclosure/2017/Jul/78</ref>
    </refs>
    <vuln_soft>
      <prod name="nosefart" vendor="nosefart_project">
        <vers num="2.9-mls"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11120" seq="2017-11120" published="2017-09-27" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/144328/Broadcom-802.11k-Neighbor-Report-Response-Out-Of-Bounds-Write.html" adv="1">http://packetstormsecurity.com/files/144328/Broadcom-802.11k-Neighbor-Report-Response-Out-Of-Bounds-Write.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100984" adv="1">100984</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1289" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1289</ref>
      <ref source="APPLE" url="https://lists.apple.com/archives/security-announce/2017/Sep/msg00007.html" adv="1">APPLE-SA-2017-09-25-6</ref>
      <ref source="APPLE" url="https://lists.apple.com/archives/security-announce/2017/Sep/msg00009.html" adv="1">APPLE-SA-2017-09-25-4</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208112" adv="1">https://support.apple.com/en-us/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208113" adv="1">https://support.apple.com/en-us/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112" adv="1">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113" adv="1">https://support.apple.com/HT208113</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42784/" adv="1">42784</ref>
    </refs>
    <vuln_soft>
      <prod name="iphone_os" vendor="apple">
        <vers num="1.0.0" edition="-:iphone"/>
        <vers num="1.0.1" edition="-:iphone"/>
        <vers num="1.0.2" edition="-:iphone"/>
        <vers num="1.1.0" edition="-:iphone"/>
        <vers num="1.1.0" edition="-:ipodtouch"/>
        <vers num="1.1.1" edition="-:iphone"/>
        <vers num="1.1.1" edition="-:ipodtouch"/>
        <vers num="1.1.2" edition="-:iphone"/>
        <vers num="1.1.2" edition="-:ipodtouch"/>
        <vers num="1.1.3" edition="-:iphone"/>
        <vers num="1.1.3" edition="-:ipodtouch"/>
        <vers num="1.1.4" edition="-:iphone"/>
        <vers num="1.1.4" edition="-:ipodtouch"/>
        <vers num="1.1.5" edition="-:iphone"/>
        <vers num="1.1.5" edition="-:ipodtouch"/>
        <vers num="2.0"/>
        <vers num="2.0.0" edition="-:iphone"/>
        <vers num="2.0.0" edition="-:ipodtouch"/>
        <vers num="2.0.1" edition="-:iphone"/>
        <vers num="2.0.1" edition="-:ipodtouch"/>
        <vers num="2.0.2" edition="-:iphone"/>
        <vers num="2.0.2" edition="-:ipodtouch"/>
        <vers num="2.1" edition="-:iphone"/>
        <vers num="2.1" edition="-:ipodtouch"/>
        <vers num="2.1.1"/>
        <vers num="2.2" edition="-:iphone"/>
        <vers num="2.2" edition="-:ipodtouch"/>
        <vers num="2.2.1" edition="-:iphone"/>
        <vers num="2.2.1" edition="-:ipodtouch"/>
        <vers num="3.0" edition="-:iphone"/>
        <vers num="3.0" edition="-:ipodtouch"/>
        <vers num="3.0.1" edition="-:iphone"/>
        <vers num="3.0.1" edition="-:ipodtouch"/>
        <vers num="3.1" edition=":~~~ipod_touch~~"/>
        <vers num="3.1" edition="-:iphone"/>
        <vers num="3.1" edition="-:ipodtouch"/>
        <vers num="3.1.1" edition=":~~~ipod_touch~~"/>
        <vers num="3.1.2" edition="-:iphone"/>
        <vers num="3.1.2" edition="-:ipodtouch"/>
        <vers num="3.1.3" edition="-:iphone"/>
        <vers num="3.1.3" edition="-:ipodtouch"/>
        <vers num="3.2" edition="-:iphone"/>
        <vers num="3.2" edition="-:ipodtouch"/>
        <vers num="3.2.1" edition="-:ipad"/>
        <vers num="3.2.2"/>
        <vers num="4.0" edition="-:iphone"/>
        <vers num="4.0" edition="-:ipodtouch"/>
        <vers num="4.0.1" edition="-:iphone"/>
        <vers num="4.0.1" edition="-:ipodtouch"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.2.1"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers num="4.2.10"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5" edition="-:ipad"/>
        <vers num="4.3.5" edition="-:ipodtouch"/>
        <vers num="5.0" edition="-:ipad"/>
        <vers num="5.0" edition="-:iphone"/>
        <vers num="5.0" edition="-:ipodtouch"/>
        <vers num="5.0.1" edition="-:ipad"/>
        <vers num="5.0.1" edition="-:iphone"/>
        <vers num="5.0.1" edition="-:ipodtouch"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.1.4"/>
        <vers num="6.1.5"/>
        <vers num="6.1.6"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.1.3"/>
        <vers num="8.2"/>
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4"/>
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="11"/>
      </prod>
      <prod name="tvos" vendor="apple">
        <vers num="1.0.0"/>
        <vers num="1.1.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.2.0"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3.0"/>
        <vers num="4.4.0"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.2.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.2"/>
        <vers num="6.2.1"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="11"/>
      </prod>
      <prod name="bcm4355c0_firmware" vendor="broadcom">
        <vers num="9.44.78.27.0.1.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11121" seq="2017-11121" published="2017-09-27" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transition frames can potentially trigger internal Wi-Fi firmware heap and/or stack overflows, leading to denial of service or other effects, aka B-V2017061205.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/144329/Broadcom-802.11r-FT-Reassociation-Response-Overflows.html" adv="1">http://packetstormsecurity.com/files/144329/Broadcom-802.11r-FT-Reassociation-Response-Overflows.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100984" adv="1">100984</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1291" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1291</ref>
      <ref source="APPLE" url="https://lists.apple.com/archives/security-announce/2017/Sep/msg00007.html" adv="1">APPLE-SA-2017-09-25-6</ref>
      <ref source="APPLE" url="https://lists.apple.com/archives/security-announce/2017/Sep/msg00009.html" adv="1">APPLE-SA-2017-09-25-4</ref>
      <ref source="CONFIRM" url="https://source.android.com/security/bulletin/2017-09-01" adv="1">https://source.android.com/security/bulletin/2017-09-01</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208112" adv="1">https://support.apple.com/en-us/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208113" adv="1">https://support.apple.com/en-us/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112" adv="1">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113" adv="1">https://support.apple.com/HT208113</ref>
    </refs>
    <vuln_soft>
      <prod name="iphone_os" vendor="apple">
        <vers num="1.0.0" edition="-:iphone"/>
        <vers num="1.0.1" edition="-:iphone"/>
        <vers num="1.0.2" edition="-:iphone"/>
        <vers num="1.1.0" edition="-:iphone"/>
        <vers num="1.1.0" edition="-:ipodtouch"/>
        <vers num="1.1.1" edition="-:iphone"/>
        <vers num="1.1.1" edition="-:ipodtouch"/>
        <vers num="1.1.2" edition="-:iphone"/>
        <vers num="1.1.2" edition="-:ipodtouch"/>
        <vers num="1.1.3" edition="-:iphone"/>
        <vers num="1.1.3" edition="-:ipodtouch"/>
        <vers num="1.1.4" edition="-:iphone"/>
        <vers num="1.1.4" edition="-:ipodtouch"/>
        <vers num="1.1.5" edition="-:iphone"/>
        <vers num="1.1.5" edition="-:ipodtouch"/>
        <vers num="2.0"/>
        <vers num="2.0.0" edition="-:iphone"/>
        <vers num="2.0.0" edition="-:ipodtouch"/>
        <vers num="2.0.1" edition="-:iphone"/>
        <vers num="2.0.1" edition="-:ipodtouch"/>
        <vers num="2.0.2" edition="-:iphone"/>
        <vers num="2.0.2" edition="-:ipodtouch"/>
        <vers num="2.1" edition="-:iphone"/>
        <vers num="2.1" edition="-:ipodtouch"/>
        <vers num="2.1.1"/>
        <vers num="2.2" edition="-:iphone"/>
        <vers num="2.2" edition="-:ipodtouch"/>
        <vers num="2.2.1" edition="-:iphone"/>
        <vers num="2.2.1" edition="-:ipodtouch"/>
        <vers num="3.0" edition="-:iphone"/>
        <vers num="3.0" edition="-:ipodtouch"/>
        <vers num="3.0.1" edition="-:iphone"/>
        <vers num="3.0.1" edition="-:ipodtouch"/>
        <vers num="3.1" edition=":~~~ipod_touch~~"/>
        <vers num="3.1" edition="-:iphone"/>
        <vers num="3.1" edition="-:ipodtouch"/>
        <vers num="3.1.1" edition=":~~~ipod_touch~~"/>
        <vers num="3.1.2" edition="-:iphone"/>
        <vers num="3.1.2" edition="-:ipodtouch"/>
        <vers num="3.1.3" edition="-:iphone"/>
        <vers num="3.1.3" edition="-:ipodtouch"/>
        <vers num="3.2" edition="-:iphone"/>
        <vers num="3.2" edition="-:ipodtouch"/>
        <vers num="3.2.1" edition="-:ipad"/>
        <vers num="3.2.2"/>
        <vers num="4.0" edition="-:iphone"/>
        <vers num="4.0" edition="-:ipodtouch"/>
        <vers num="4.0.1" edition="-:iphone"/>
        <vers num="4.0.1" edition="-:ipodtouch"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.2.1"/>
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers num="4.2.10"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5" edition="-:ipad"/>
        <vers num="4.3.5" edition="-:ipodtouch"/>
        <vers num="5.0" edition="-:ipad"/>
        <vers num="5.0" edition="-:iphone"/>
        <vers num="5.0" edition="-:ipodtouch"/>
        <vers num="5.0.1" edition="-:ipad"/>
        <vers num="5.0.1" edition="-:iphone"/>
        <vers num="5.0.1" edition="-:ipodtouch"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.1.4"/>
        <vers num="6.1.5"/>
        <vers num="6.1.6"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.1.3"/>
        <vers num="8.2"/>
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4"/>
        <vers num="9.3.5"/>
        <vers num="9.3.6"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="11"/>
      </prod>
      <prod name="tvos" vendor="apple">
        <vers num="1.0.0"/>
        <vers num="1.1.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.2.0"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.3.0"/>
        <vers num="4.4.0"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.2.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.2"/>
        <vers num="6.2.1"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="11"/>
      </prod>
      <prod name="bcm4355c0_firmware" vendor="broadcom">
        <vers num="9.44.78.27.0.1.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11122" seq="2017-11122" published="2017-10-03" modified="2019-03-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/144461/Broadcom-ICMPv6-Information-Leak.html" adv="1">http://packetstormsecurity.com/files/144461/Broadcom-ICMPv6-Information-Leak.html</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1300" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1300</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208112" adv="1">https://support.apple.com/en-us/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/en-us/HT208113" adv="1">https://support.apple.com/en-us/HT208113</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208112" adv="1">https://support.apple.com/HT208112</ref>
      <ref source="CONFIRM" url="https://support.apple.com/HT208113" adv="1">https://support.apple.com/HT208113</ref>
    </refs>
    <vuln_soft>
      <prod name="iphone_os" vendor="apple">
        <vers num="10.3.3" prev="1"/>
      </prod>
      <prod name="tvos" vendor="apple">
        <vers num="10.2.2" prev="1"/>
      </prod>
      <prod name="bcm4355c0_firmware" vendor="broadcom">
        <vers num="9.44.78.27.0.1.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11124" seq="2017-11124" published="2017-07-09" modified="2017-07-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://blogs.gentoo.org/ago/2017/06/28/xar-null-pointer-dereference-in-xar_unserialize-archive-c/" adv="1">https://blogs.gentoo.org/ago/2017/06/28/xar-null-pointer-dereference-in-xar_unserialize-archive-c/</ref>
    </refs>
    <vuln_soft>
      <prod name="xar" vendor="xar_project">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11125" seq="2017-11125" published="2017-07-09" modified="2017-07-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://blogs.gentoo.org/ago/2017/06/28/xar-null-pointer-dereference-in-xar_get_path-util-c/" adv="1">https://blogs.gentoo.org/ago/2017/06/28/xar-null-pointer-dereference-in-xar_get_path-util-c/</ref>
    </refs>
    <vuln_soft>
      <prod name="xar" vendor="xar_project">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11126" seq="2017-11126" published="2017-07-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, a similar issue to CVE-2017-9870.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://openwall.com/lists/oss-security/2017/07/10/4" adv="1" patch="1">http://openwall.com/lists/oss-security/2017/07/10/4</ref>
      <ref source="MISC" url="https://blogs.gentoo.org/ago/2017/07/03/mpg123-global-buffer-overflow-in-iii_i_stereo-layer3-c/" adv="1" patch="1">https://blogs.gentoo.org/ago/2017/07/03/mpg123-global-buffer-overflow-in-iii_i_stereo-layer3-c/</ref>
    </refs>
    <vuln_soft>
      <prod name="mpg123" vendor="mpg123">
        <vers num="1.25.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11127" seq="2017-11127" published="2017-07-17" modified="2017-07-19" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html" adv="1">https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html</ref>
    </refs>
    <vuln_soft>
      <prod name="bolt_cms" vendor="bolt">
        <vers num="3.2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11128" seq="2017-11128" published="2017-07-17" modified="2017-07-19" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html" adv="1">https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html</ref>
    </refs>
    <vuln_soft>
      <prod name="bolt_cms" vendor="bolt">
        <vers num="3.2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11129" seq="2017-11129" published="2017-08-01" modified="2017-08-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1113" seq="2017-1113" published="2017-07-05" modified="2017-07-25" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121151.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004611" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22004611</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99352" adv="1">99352</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038912">1038912</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121151" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121151</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_team_concert" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11130" seq="2017-11130" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct replay attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="0.0.80w" prev="1" edition=":~~web~~~"/>
        <vers num="0.0.86w" prev="1" edition=":~~desktop~~~"/>
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11131" seq="2017-11131" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover, only the first 32 bytes of the hash are used. This allows for easy dictionary and rainbow-table attacks if an attacker has access to the password hash.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="0.0.80w" prev="1" edition=":~~web~~~"/>
        <vers num="0.0.86w" prev="1" edition=":~~desktop~~~"/>
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11132" seq="2017-11132" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backend and the application would not notice it.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="stashcat" vendor="heinekingmedia">
        <vers num="1.5.17" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11133" seq="2017-11133" published="2017-08-01" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used with a pseudo-random secret. This secret and the IV are generated with math.random() in previous versions and with CryptoJS.lib.WordArray.random() in newer versions, which uses math.random() internally. This is not cryptographically strong.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="0.0.80w" prev="1" edition=":~~web~~~"/>
        <vers num="0.0.86w" prev="1" edition=":~~desktop~~~"/>
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11134" seq="2017-11134" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11135" seq="2017-11135" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only needs to know the device ID. This causes a denial of service. This might be interpreted as a vulnerability in customer-controlled software, in the sense that the StashCat client side has no secure way to signal that it is ending a session and that data should be deleted.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="0.0.80w" prev="1" edition=":~~web~~~"/>
        <vers num="0.0.86w" prev="1" edition=":~~desktop~~~"/>
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11136" seq="2017-11136" published="2017-08-01" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetric encryption of messages. However, the private RSA key is not only stored on the client but transmitted to the backend, too. Moreover, the key to decrypt the private key is composed of the first 32 bytes of the SHA-512 hash of the user password. But this hash is stored on the backend, too. Therefore, everyone with access to the backend database can read the transmitted secret for symmetric encryption, hence can read the communication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/90" adv="1">http://seclists.org/fulldisclosure/2017/Jul/90</ref>
    </refs>
    <vuln_soft>
      <prod name="heinekingmedia" vendor="stashcat">
        <vers num="0.0.80w" prev="1" edition=":~~web~~~"/>
        <vers num="0.0.86w" prev="1" edition=":~~desktop~~~"/>
        <vers num="1.7.5" prev="1" edition=":~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11139" seq="2017-11139" published="2017-07-09" modified="2019-05-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/4d0baa77245b" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/4d0baa77245b</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99504" adv="1">99504</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321" adv="1">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.26"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1114" seq="2017-1114" published="2018-09-07" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121152" adv="1">ibm-campaign-cve20171114-xss(121152)</ref>
      <ref source="CONFIRM" url="https://www.ibm.com/support/docview.wss?uid=ibm10729773" adv="1">https://www.ibm.com/support/docview.wss?uid=ibm10729773</ref>
    </refs>
    <vuln_soft>
      <prod name="campaign" vendor="ibm">
        <vers num="9.1"/>
        <vers num="9.1.2"/>
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11140" seq="2017-11140" published="2017-07-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/b4139088b49a" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/b4139088b49a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99503" adv="1">99503</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html">[debian-lts-announce] 20180803 [SECURITY] [DLA 1456-1] graphicsmagick security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11141" seq="2017-11141" published="2017-07-09" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99506" adv="1">99506</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/469" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/469</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.5-6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11142" seq="2017-11142" published="2017-07-10" modified="2018-01-13" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://openwall.com/lists/oss-security/2017/07/10/6">http://openwall.com/lists/oss-security/2017/07/10/6</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-5.php" adv="1">http://php.net/ChangeLog-5.php</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-7.php" adv="1">http://php.net/ChangeLog-7.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99601">99601</ref>
      <ref source="CONFIRM" url="https://bugs.php.net/bug.php?id=73807" adv="1">https://bugs.php.net/bug.php?id=73807</ref>
      <ref source="CONFIRM" url="https://github.com/php/php-src/commit/0f8cf3b8497dc45c010c44ed9e96518e11e19fc3" adv="1" patch="1">https://github.com/php/php-src/commit/0f8cf3b8497dc45c010c44ed9e96518e11e19fc3</ref>
      <ref source="CONFIRM" url="https://github.com/php/php-src/commit/a15bffd105ac28fd0dd9b596632dbf035238fda3" adv="1" patch="1">https://github.com/php/php-src/commit/a15bffd105ac28fd0dd9b596632dbf035238fda3</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4081">DSA-4081</ref>
      <ref source="CONFIRM" url="https://www.tenable.com/security/tns-2017-12">https://www.tenable.com/security/tns-2017-12</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="5.6.30" prev="1"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11143" seq="2017-11143" published="2017-07-10" modified="2018-05-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://openwall.com/lists/oss-security/2017/07/10/6" adv="1" patch="1">http://openwall.com/lists/oss-security/2017/07/10/6</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-5.php" adv="1">http://php.net/ChangeLog-5.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99553">99553</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1296">RHSA-2018:1296</ref>
      <ref source="CONFIRM" url="https://bugs.php.net/bug.php?id=74145" adv="1" patch="1">https://bugs.php.net/bug.php?id=74145</ref>
      <ref source="CONFIRM" url="https://git.php.net/?p=php-src.git;a=commit;h=2aae60461c2ff7b7fbcdd194c789ac841d0747d7" adv="1" patch="1">https://git.php.net/?p=php-src.git;a=commit;h=2aae60461c2ff7b7fbcdd194c789ac841d0747d7</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4081">DSA-4081</ref>
      <ref source="CONFIRM" url="https://www.tenable.com/security/tns-2017-12">https://www.tenable.com/security/tns-2017-12</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="5.6.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11144" seq="2017-11144" published="2017-07-10" modified="2018-05-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL sealing function, which could lead to a crash of the PHP interpreter, related to an interpretation conflict for a negative number in ext/openssl/openssl.c, and an OpenSSL documentation omission.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.php.net/?p=php-src.git;a=commit;h=73cabfedf519298e1a11192699f44d53c529315e" adv="1">http://git.php.net/?p=php-src.git;a=commit;h=73cabfedf519298e1a11192699f44d53c529315e</ref>
      <ref source="CONFIRM" url="http://git.php.net/?p=php-src.git;a=commit;h=89637c6b41b510c20d262c17483f582f115c66d6" adv="1">http://git.php.net/?p=php-src.git;a=commit;h=89637c6b41b510c20d262c17483f582f115c66d6</ref>
      <ref source="CONFIRM" url="http://git.php.net/?p=php-src.git;a=commit;h=91826a311dd37f4c4e5d605fa7af331e80ddd4c3" adv="1">http://git.php.net/?p=php-src.git;a=commit;h=91826a311dd37f4c4e5d605fa7af331e80ddd4c3</ref>
      <ref source="CONFIRM" url="http://openwall.com/lists/oss-security/2017/07/10/6">http://openwall.com/lists/oss-security/2017/07/10/6</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-5.php" adv="1">http://php.net/ChangeLog-5.php</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-7.php" adv="1">http://php.net/ChangeLog-7.php</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1296">RHSA-2018:1296</ref>
      <ref source="CONFIRM" url="https://bugs.php.net/bug.php?id=74651" adv="1">https://bugs.php.net/bug.php?id=74651</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4080">DSA-4080</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4081">DSA-4081</ref>
      <ref source="CONFIRM" url="https://www.tenable.com/security/tns-2017-12">https://www.tenable.com/security/tns-2017-12</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="5.6.30" prev="1"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.20"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11145" seq="2017-11145" published="2017-07-10" modified="2018-05-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: the correct fix is in the e8b7698f5ee757ce2c8bd10a192a491a498f891c commit, not the bd77ac90d3bdf31ce2a5251ad92e9e75 gist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.php.net/?p=php-src.git;a=commit;h=e8b7698f5ee757ce2c8bd10a192a491a498f891c">http://git.php.net/?p=php-src.git;a=commit;h=e8b7698f5ee757ce2c8bd10a192a491a498f891c</ref>
      <ref source="CONFIRM" url="http://openwall.com/lists/oss-security/2017/07/10/6" adv="1">http://openwall.com/lists/oss-security/2017/07/10/6</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-5.php" adv="1">http://php.net/ChangeLog-5.php</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-7.php" adv="1">http://php.net/ChangeLog-7.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99550">99550</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1296">RHSA-2018:1296</ref>
      <ref source="CONFIRM" url="https://bugs.php.net/bug.php?id=74819" adv="1">https://bugs.php.net/bug.php?id=74819</ref>
      <ref source="MISC" url="https://gist.github.com/anonymous/bd77ac90d3bdf31ce2a5251ad92e9e75" adv="1" patch="1">https://gist.github.com/anonymous/bd77ac90d3bdf31ce2a5251ad92e9e75</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4080">DSA-4080</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4081">DSA-4081</ref>
      <ref source="CONFIRM" url="https://www.tenable.com/security/tns-2017-12">https://www.tenable.com/security/tns-2017-12</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="5.6.30" prev="1"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.20"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11146" seq="2017-11146" published="2017-07-10" modified="2017-07-23" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not an independently fixable security issue relative to CVE-2017-11145.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-11147" seq="2017-11147" published="2017-07-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.php.net/?p=php-src.git;a=commit;h=e5246580a85f031e1a3b8064edbaa55c1643a451" adv="1">http://git.php.net/?p=php-src.git;a=commit;h=e5246580a85f031e1a3b8064edbaa55c1643a451</ref>
      <ref source="CONFIRM" url="http://openwall.com/lists/oss-security/2017/07/10/6" adv="1">http://openwall.com/lists/oss-security/2017/07/10/6</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-5.php" adv="1">http://php.net/ChangeLog-5.php</ref>
      <ref source="CONFIRM" url="http://php.net/ChangeLog-7.php" adv="1">http://php.net/ChangeLog-7.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99607">99607</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1296">RHSA-2018:1296</ref>
      <ref source="CONFIRM" url="https://bugs.php.net/bug.php?id=73773" adv="1">https://bugs.php.net/bug.php?id=73773</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="CONFIRM" url="https://www.tenable.com/security/tns-2017-12">https://www.tenable.com/security/tns-2017-12</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="5.6.29" prev="1"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11148" seq="2017-11148" published="2017-08-11" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100310" adv="1">100310</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_38_Chat" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_38_Chat</ref>
    </refs>
    <vuln_soft>
      <prod name="chat" vendor="synology">
        <vers num="1.0.2-0159" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11149" seq="2017-11149" published="2017-08-14" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_28_Download_Station" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_28_Download_Station</ref>
    </refs>
    <vuln_soft>
      <prod name="download_station" vendor="synology">
        <vers num="3.2-2295"/>
        <vers num="3.3-2382"/>
        <vers num="3.3-2383"/>
        <vers num="3.3-2386"/>
        <vers num="3.4-2477"/>
        <vers num="3.4-2478"/>
        <vers num="3.4-2480"/>
        <vers num="3.4-2485"/>
        <vers num="3.4-2486"/>
        <vers num="3.4-2489"/>
        <vers num="3.4-2490"/>
        <vers num="3.4-2514"/>
        <vers num="3.4-2555"/>
        <vers num="3.4-2557"/>
        <vers num="3.4-2558"/>
        <vers num="3.5-2638"/>
        <vers num="3.5-2705"/>
        <vers num="3.5-2706"/>
        <vers num="3.5-2955"/>
        <vers num="3.5-2956"/>
        <vers num="3.5-2962"/>
        <vers num="3.5-2963"/>
        <vers num="3.5-2967"/>
        <vers num="3.5-2968"/>
        <vers num="3.5-2970"/>
        <vers num="3.5-2973"/>
        <vers num="3.5-2980"/>
        <vers num="3.5-2982"/>
        <vers num="3.8.0-3416"/>
        <vers num="3.8.1-3420"/>
        <vers num="3.8.2-3455"/>
        <vers num="3.8.3-3458"/>
        <vers num="3.8.4-3468"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1115" seq="2017-1115" published="2018-09-07" modified="2019-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121153" adv="1">ibm-campaign-cve20171115-html-injection(121153)</ref>
      <ref source="CONFIRM" url="https://www.ibm.com/support/docview.wss?uid=ibm10729769" adv="1" patch="1">https://www.ibm.com/support/docview.wss?uid=ibm10729769</ref>
    </refs>
    <vuln_soft>
      <prod name="campaign" vendor="ibm">
        <vers num="9.1"/>
        <vers num="9.1.2"/>
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11150" seq="2017-11150" published="2017-08-14" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_26_Office" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_26_Office</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="synology">
        <vers num="2.2.0-1502"/>
        <vers num="2.2.1-1506"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11151" seq="2017-11151" published="2017-08-08" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42434/" adv="1">42434</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967"/>
        <vers num="6.7.2-3429" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11152" seq="2017-11152" published="2017-08-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42434/" adv="1">42434</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967"/>
        <vers num="6.7.2-3429" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11153" seq="2017-11153" published="2017-08-08" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42434/" adv="1">42434</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967"/>
        <vers num="6.7.2-3429" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11154" seq="2017-11154" published="2017-08-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42434/" adv="1">42434</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967"/>
        <vers num="6.7.2-3429" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11155" seq="2017-11155" published="2017-08-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42434/" adv="1">42434</ref>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967"/>
        <vers num="6.7.2-3429" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11156" seq="2017-11156" published="2017-08-14" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_28_Download_Station" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_28_Download_Station</ref>
    </refs>
    <vuln_soft>
      <prod name="download_station" vendor="synology">
        <vers num="3.2-2295"/>
        <vers num="3.3-2382"/>
        <vers num="3.3-2383"/>
        <vers num="3.3-2386"/>
        <vers num="3.4-2477"/>
        <vers num="3.4-2478"/>
        <vers num="3.4-2480"/>
        <vers num="3.4-2485"/>
        <vers num="3.4-2486"/>
        <vers num="3.4-2489"/>
        <vers num="3.4-2490"/>
        <vers num="3.4-2514"/>
        <vers num="3.4-2555"/>
        <vers num="3.4-2557"/>
        <vers num="3.4-2558"/>
        <vers num="3.5-2638"/>
        <vers num="3.5-2705"/>
        <vers num="3.5-2706"/>
        <vers num="3.5-2955"/>
        <vers num="3.5-2956"/>
        <vers num="3.5-2962"/>
        <vers num="3.5-2963"/>
        <vers num="3.5-2967"/>
        <vers num="3.5-2968"/>
        <vers num="3.5-2970"/>
        <vers num="3.5-2973"/>
        <vers num="3.5-2980"/>
        <vers num="3.5-2982"/>
        <vers num="3.8.0-3416"/>
        <vers num="3.8.1-3420"/>
        <vers num="3.8.2-3455"/>
        <vers num="3.8.3-3458"/>
        <vers num="3.8.4-3468"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11157" seq="2017-11157" published="2017-08-30" modified="2017-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_50_Cloud_Station_Backup" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_50_Cloud_Station_Backup</ref>
    </refs>
    <vuln_soft>
      <prod name="cloud_station_backup" vendor="synology">
        <vers num="4.2.4-4393" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11158" seq="2017-11158" published="2017-08-31" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_51_Cloud_Station_Drive" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_51_Cloud_Station_Drive</ref>
    </refs>
    <vuln_soft>
      <prod name="cloud_station_drive" vendor="synology">
        <vers num="4.2.4-4393" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11159" seq="2017-11159" published="2017-08-23" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_45_Photo_Station_Uploader" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_45_Photo_Station_Uploader</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station_uploader" vendor="synology">
        <vers num="1.4.1-083" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1116" seq="2017-1116" published="2018-04-27" modified="2018-05-25" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22015569" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22015569</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/104011" adv="1">104011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121154" adv="1">ibm-campaign-cve20171116-info-disc(121154)</ref>
    </refs>
    <vuln_soft>
      <prod name="campaign" vendor="ibm">
        <vers num="8.6"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11160" seq="2017-11160" published="2017-08-18" modified="2017-08-29" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_44_Synology_Assistant" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_44_Synology_Assistant</ref>
    </refs>
    <vuln_soft>
      <prod name="assistant" vendor="synology">
        <vers num="6.1-15030" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11161" seq="2017-11161" published="2017-09-08" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_35_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_35_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967" prev="1"/>
        <vers num="6.7.3-3432" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11162" seq="2017-11162" published="2017-09-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://www.synology.com/en-global/support/security/Synology_SA_17_35_PhotoStation" adv="1">https://www.synology.com/en-global/support/security/Synology_SA_17_35_PhotoStation</ref>
    </refs>
    <vuln_soft>
      <prod name="photo_station" vendor="synology">
        <vers num="6.3-2967" prev="1"/>
        <vers num="6.7.3-3432" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11163" seq="2017-11163" published="2017-07-10" modified="2019-05-03" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038908" adv="1">1038908</ref>
      <ref source="CONFIRM" url="https://github.com/Cacti/cacti/issues/847" adv="1" patch="1">https://github.com/Cacti/cacti/issues/847</ref>
    </refs>
    <vuln_soft>
      <prod name="cacti" vendor="cacti">
        <vers num="1.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11164" seq="2017-11164" published="2017-07-10" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://openwall.com/lists/oss-security/2017/07/11/3" adv="1">http://openwall.com/lists/oss-security/2017/07/11/3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99575">99575</ref>
    </refs>
    <vuln_soft>
      <prod name="pcre" vendor="pcre">
        <vers num="8.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11165" seq="2017-11165" published="2017-07-12" modified="2017-08-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-Sensitive-Configuration-Exposure.html" adv="1">https://packetstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-Sensitive-Configuration-Exposure.html</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42313/" adv="1">42313</ref>
    </refs>
    <vuln_soft>
      <prod name="dt80_dex_firmware" vendor="datataker">
        <vers num="1.50.012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11166" seq="2017-11166" published="2017-07-10" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/471" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/471</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.5-6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11167" seq="2017-11167" published="2017-07-12" modified="2017-07-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.03sec.com/3169.shtml" adv="1">http://www.03sec.com/3169.shtml</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11169" seq="2017-11169" published="2017-11-13" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter to /form2userconfig.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.uniquish.tech/2017/11/privelege-escalation-in-iball-ib.html" adv="1">http://www.uniquish.tech/2017/11/privelege-escalation-in-iball-ib.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ib-wra300n3gt_firmware" vendor="iball">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1117" seq="2017-1117" published="2017-06-21" modified="2019-10-02" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22001468" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22001468</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99136" adv="1">99136</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121155" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121155</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_mq" vendor="ibm">
        <vers num="8.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="9.0.0.0"/>
        <vers num="9.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11170" seq="2017-11170" published="2017-07-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99565">99565</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/472" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/472</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.5-6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11171" seq="2017-11171" published="2017-07-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed authentication attempt will leak a file descriptor in gnome-session. When the maximum number of file descriptors is exhausted in the gnome-session process, it will enter an infinite loop trying to communicate without success, consuming 100% of the CPU. The graphical session associated with the gnome-session process will stop working correctly, because communication with gnome-session is no longer possible.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugzilla.suse.com/show_bug.cgi?id=1025068" adv="1">https://bugzilla.suse.com/show_bug.cgi?id=1025068</ref>
      <ref source="CONFIRM" url="https://github.com/GNOME/gnome-session/commit/b0dc999e0b45355314616321dbb6cb71e729fc9d" adv="1">https://github.com/GNOME/gnome-session/commit/b0dc999e0b45355314616321dbb6cb71e729fc9d</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome-session" vendor="gnome">
        <vers num="2.29.92" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11173" seq="2017-11173" published="2017-07-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/22" adv="1">http://seclists.org/fulldisclosure/2017/Jul/22</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3931">DSA-3931</ref>
      <ref source="MISC" url="https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6" adv="1" patch="1">https://github.com/cyu/rack-cors/commit/42ebe6caa8e85ffa9c8a171bda668ba1acc7a5e6</ref>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143345/rack-cors-Missing-Anchor.html" adv="1">https://packetstormsecurity.com/files/143345/rack-cors-Missing-Anchor.html</ref>
    </refs>
    <vuln_soft>
      <prod name="rack-cors" vendor="rack-cors_project">
        <vers num="0.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11174" seq="2017-11174" published="2017-07-12" modified="2017-07-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://tsublogs.wordpress.com/2017/07/12/xoops-core-2-5-8-1-install-db-sql-injection/" adv="1">https://tsublogs.wordpress.com/2017/07/12/xoops-core-2-5-8-1-install-db-sql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod name="xoops" vendor="xoops">
        <vers num="2.5.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11175" seq="2017-11175" published="2018-07-05" modified="2018-09-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/miruser/Roche-CVEs/blob/master/CVE-2017-11175.md" adv="1">https://github.com/miruser/Roche-CVEs/blob/master/CVE-2017-11175.md</ref>
    </refs>
    <vuln_soft>
      <prod name="fin_stack" vendor="j2inn">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11176" seq="2017-11176" published="2017-07-11" modified="2018-12-13" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f991af3daabaecff34684fd51fac80319d1baad1" adv="1" patch="1">http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f991af3daabaecff34684fd51fac80319d1baad1</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3927" adv="1">DSA-3927</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3945" adv="1">DSA-3945</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99919" adv="1">99919</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2918" adv="1">RHSA-2017:2918</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2930" adv="1">RHSA-2017:2930</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2931" adv="1">RHSA-2017:2931</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0169" adv="1">RHSA-2018:0169</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:3822">RHSA-2018:3822</ref>
      <ref source="CONFIRM" url="https://github.com/torvalds/linux/commit/f991af3daabaecff34684fd51fac80319d1baad1" adv="1" patch="1">https://github.com/torvalds/linux/commit/f991af3daabaecff34684fd51fac80319d1baad1</ref>
      <ref source="CONFIRM" url="https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0">https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/45553/">45553</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="4.11.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11177" seq="2017-11177" published="2017-11-06" modified="2017-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://support.forcepoint.com/KBArticle?id=000014490" adv="1">https://support.forcepoint.com/KBArticle?id=000014490</ref>
    </refs>
    <vuln_soft>
      <prod name="triton_ap_email" vendor="websense">
        <vers num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11178" seq="2017-11178" published="2017-07-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to overwrite a .php file because the file extension is not checked.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/finecms_writefile/finecmswritefile_2017_07_011_subm1t.html" adv="1">http://www.yuesec.com/img/cccccve/finecms_writefile/finecmswritefile_2017_07_011_subm1t.html</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="2017-05-12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11179" seq="2017-11179" published="2017-07-11" modified="2017-07-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/finecms_storedxss/finecms_storedxss26543.html" adv="1">http://www.yuesec.com/img/cccccve/finecms_storedxss/finecms_storedxss26543.html</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1118" seq="2017-1118" published="2017-08-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22006580" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22006580</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100021" adv="1">100021</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121156" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121156</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_mq_internet_pass-thru" vendor="ibm">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11180" seq="2017-11180" published="2017-07-11" modified="2017-07-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/finecms_storedxss/finecms_storedxss26543.html" adv="1">http://www.yuesec.com/img/cccccve/finecms_storedxss/finecms_storedxss26543.html</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11181" seq="2017-11181" published="2017-07-11" modified="2017-07-14" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143307/Rise-Ultimate-Project-Manager-1.8-Cross-Site-Scripting.html" adv="1">https://packetstormsecurity.com/files/143307/Rise-Ultimate-Project-Manager-1.8-Cross-Site-Scripting.html</ref>
    </refs>
    <vuln_soft>
      <prod name="rise_ultimate_project_manager" vendor="fairsketch">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11182" seq="2017-11182" published="2017-07-11" modified="2017-07-14" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143307/Rise-Ultimate-Project-Manager-1.8-Cross-Site-Scripting.html" adv="1">https://packetstormsecurity.com/files/143307/Rise-Ultimate-Project-Manager-1.8-Cross-Site-Scripting.html</ref>
    </refs>
    <vuln_soft>
      <prod name="rise_ultimate_project_manager" vendor="fairsketch">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11183" seq="2017-11183" published="2017-07-28" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.5" CVSS_base_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/issues/2450" adv="1">https://github.com/glpi-project/glpi/issues/2450</ref>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/releases/tag/9.1.5" adv="1">https://github.com/glpi-project/glpi/releases/tag/9.1.5</ref>
    </refs>
    <vuln_soft>
      <prod name="glpi" vendor="glpi-project">
        <vers num="9.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11184" seq="2017-11184" published="2017-07-28" modified="2017-08-04" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/issues/2449" adv="1">https://github.com/glpi-project/glpi/issues/2449</ref>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/releases/tag/9.1.5" adv="1">https://github.com/glpi-project/glpi/releases/tag/9.1.5</ref>
    </refs>
    <vuln_soft>
      <prod name="glpi" vendor="glpi-project">
        <vers num="9.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11185" seq="2017-11185" published="2017-08-18" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3962">DSA-3962</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100492">100492</ref>
      <ref source="CONFIRM" url="https://www.strongswan.org/blog/2017/08/14/strongswan-vulnerability-(cve-2017-11185).html">https://www.strongswan.org/blog/2017/08/14/strongswan-vulnerability-(cve-2017-11185).html</ref>
    </refs>
    <vuln_soft>
      <prod name="strongswan" vendor="strongswan">
        <vers num="5.5.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11187" seq="2017-11187" published="2017-07-12" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.phpmyfaq.de/security/advisory-2017-07-12" adv="1">http://www.phpmyfaq.de/security/advisory-2017-07-12</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyfaq" vendor="phpmyfaq">
        <vers num="2.9.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11188" seq="2017-11188" published="2017-07-12" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99566">99566</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/509" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/509</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11189" seq="2017-11189" published="2017-07-12" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code for a long-running application.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/0x09AL/my-exploits/tree/master/pocs/unrar-free/dos" adv="1">https://github.com/0x09AL/my-exploits/tree/master/pocs/unrar-free/dos</ref>
    </refs>
    <vuln_soft>
      <prod name="unrar-free" vendor="rarzilla">
        <vers num="0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1119" seq="2017-1119" published="2018-11-08" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use this information to launch further attacks against the affected system. IBM X-Force ID: 121171.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=ibm10738519" adv="1">http://www.ibm.com/support/docview.wss?uid=ibm10738519</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121171" adv="1">ibm-marketing-cve20171119-path-disc(121171)</ref>
    </refs>
    <vuln_soft>
      <prod name="marketing_operations" vendor="ibm">
        <vers num="9.1.0.0"/>
        <vers num="9.1.0.2"/>
        <vers num="9.1.0.3"/>
        <vers num="9.1.0.4"/>
        <vers num="9.1.0.5"/>
        <vers num="9.1.0.6"/>
        <vers num="9.1.0.7"/>
        <vers num="9.1.0.8"/>
        <vers num="9.1.0.9"/>
        <vers num="9.1.0.10"/>
        <vers num="9.1.0.11"/>
        <vers num="9.1.0.12"/>
        <vers num="9.1.2.0"/>
        <vers num="9.1.2.1"/>
        <vers num="9.1.2.2"/>
        <vers num="9.1.2.3"/>
        <vers num="9.1.2.4"/>
        <vers num="9.1.2.5"/>
        <vers num="9.1.2.6"/>
        <vers num="9.1.2.7"/>
        <vers num="10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11190" seq="2017-11190" published="2017-07-12" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via an RAR archive containing a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/0x09AL/my-exploits/blob/master/pocs/unrar-free/buffer-overflow/DESCRIPTION" adv="1">https://github.com/0x09AL/my-exploits/blob/master/pocs/unrar-free/buffer-overflow/DESCRIPTION</ref>
    </refs>
    <vuln_soft>
      <prod name="unrar-free" vendor="rarzilla">
        <vers num="0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11191" seq="2017-11191" published="2017-09-27" modified="2017-10-11" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">** DISPUTED ** FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/143532/FreeIPA-2.213-Session-Hijacking.html" adv="1">http://packetstormsecurity.com/files/143532/FreeIPA-2.213-Session-Hijacking.html</ref>
    </refs>
    <vuln_soft>
      <prod name="freeipa" vendor="freeipa">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.4.4"/>
        <vers num="4.5.0"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11193" seq="2017-11193" published="2017-07-12" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99621">99621</ref>
      <ref source="MISC" url="http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf" adv="1">http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf</ref>
      <ref source="MISC" url="https://twitter.com/sxcurity/status/884556905145937921" adv="1">https://twitter.com/sxcurity/status/884556905145937921</ref>
    </refs>
    <vuln_soft>
      <prod name="pulse_connect_secure" vendor="pulsesecure">
        <vers num="8.3r1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11194" seq="2017-11194" published="2017-07-12" modified="2017-07-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject tags. An attacker could come up with clever payloads to make the system run commands such as ping, ping6, traceroute, nslookup, arp, etc.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf" adv="1">http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf</ref>
      <ref source="MISC" url="https://twitter.com/sxcurity/status/884556905145937921" adv="1">https://twitter.com/sxcurity/status/884556905145937921</ref>
    </refs>
    <vuln_soft>
      <prod name="pulse_connect_secure" vendor="pulsesecure">
        <vers num="8.3r1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11195" seq="2017-11195" published="2017-07-12" modified="2017-07-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99615">99615</ref>
      <ref source="MISC" url="http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf" adv="1">http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf</ref>
      <ref source="MISC" url="https://twitter.com/sxcurity/status/884556905145937921" adv="1">https://twitter.com/sxcurity/status/884556905145937921</ref>
    </refs>
    <vuln_soft>
      <prod name="pulse_connect_secure" vendor="pulsesecure">
        <vers num="8.3r1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11196" seq="2017-11196" published="2017-07-12" modified="2017-07-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99613">99613</ref>
      <ref source="MISC" url="http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf" adv="1">http://www.sxcurity.pro/Multiple%20XSS%20and%20CSRF%20in%20Pulse%20Connect%20Secure%20v8.3R1.pdf</ref>
      <ref source="MISC" url="https://twitter.com/sxcurity/status/884556905145937921" adv="1">https://twitter.com/sxcurity/status/884556905145937921</ref>
    </refs>
    <vuln_soft>
      <prod name="pulse_connect_secure" vendor="pulsesecure">
        <vers num="8.3r1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11198" seq="2017-11198" published="2017-07-12" modified="2017-07-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Reflected-XSS-in-get-image-php" adv="1">http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Reflected-XSS-in-get-image-php</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1120" seq="2017-1120" published="2017-03-27" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22000152" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22000152</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97075" adv="1">97075</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038146">1038146</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_portal" vendor="ibm">
        <vers num="8.5"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11200" seq="2017-11200" published="2017-07-12" modified="2017-07-16" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Authenticated-SQL-injection" adv="1">http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Authenticated-SQL-injection</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11201" seq="2017-11201" published="2017-07-12" modified="2017-07-16" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Stored-XSS-in-images-php" adv="1">http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Stored-XSS-in-images-php</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11202" seq="2017-11202" published="2017-07-12" modified="2017-07-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Stored-XSS-in-visitors-php" adv="1">http://lorexxar.cn/2017/07/11/Some%20Vulnerability%20for%20FineCMS%20through%202017.7.11/#Stored-XSS-in-visitors-php</ref>
    </refs>
    <vuln_soft>
      <prod name="finecms" vendor="finecms_project">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11209" seq="2017-11209" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability that occurs when reading a JPEG file embedded within XML Paper Specification (XPS) file. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-577/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-577/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1121" seq="2017-1121" published="2017-02-13" modified="2017-07-24" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21997743" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21997743</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96164">96164</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1037806">1037806</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="8.5"/>
        <vers num="8.5.5"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11210" seq="2017-11210" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing, where the font is embedded in the XML Paper Specification (XPS) file. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-578/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-578/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11211" seq="2017-11211" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100180" adv="1">100180</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-579/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-579/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11212" seq="2017-11212" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text output. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-580/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-580/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11213" seq="2017-11213" published="2017-12-09" modified="2017-12-21" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101837" adv="1">101837</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039778" adv="1">1039778</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3222" adv="1">RHSA-2017:3222</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-33.html" adv="1" patch="1">https://helpx.adobe.com/security/products/flash-player/apsb17-33.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-13" adv="1">GLSA-201711-13</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="27.0.0.183" prev="1" edition=":~~~chrome~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~edge~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~intenet_explorer_11~~"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11214" seq="2017-11214" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to rendering a path. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11215" seq="2017-11215" published="2017-12-09" modified="2017-12-21" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101837" adv="1">101837</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039778" adv="1">1039778</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3222" adv="1">RHSA-2017:3222</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-33.html" adv="1" patch="1">https://helpx.adobe.com/security/products/flash-player/apsb17-33.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-13" adv="1">GLSA-201711-13</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="27.0.0.183" prev="1" edition=":~~~chrome~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~edge~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~intenet_explorer_11~~"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11216" seq="2017-11216" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to bitmap transformations. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-584" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-584</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11217" seq="2017-11217" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to drawing of Unicode text strings. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-586" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-586</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11218" seq="2017-11218" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in XFA event management. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-572/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-572/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11219" seq="2017-11219" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA rendering engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-585/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-585/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1122" seq="2017-1122" published="2017-04-20" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.9" CVSS_base_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21997868" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21997868</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97995" adv="1">97995</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038347">1038347</ref>
    </refs>
    <vuln_soft>
      <prod name="security_guardium" vendor="ibm">
        <vers num="8.2"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.5"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11220" seq="2017-11220" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in an internal data structure. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100180" adv="1">100180</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11221" seq="2017-11221" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type confusion vulnerability in the annotation functionality. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100181" adv="1">100181</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11222" seq="2017-11222" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Product Representation Compact (PRC) engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11223" seq="2017-11223" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the core of the XFA engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-588/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-588/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11224" seq="2017-11224" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA layout engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-587/" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-587/</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11225" seq="2017-11225" published="2017-12-09" modified="2017-12-21" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101837" adv="1">101837</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039778" adv="1">1039778</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3222" adv="1">RHSA-2017:3222</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-33.html" adv="1" patch="1">https://helpx.adobe.com/security/products/flash-player/apsb17-33.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201711-13" adv="1">GLSA-201711-13</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="27.0.0.183" prev="1" edition=":~~~chrome~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~edge~~"/>
        <vers num="27.0.0.183" prev="1" edition=":~~~intenet_explorer_11~~"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11226" seq="2017-11226" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image processing engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11227" seq="2017-11227" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11228" seq="2017-11228" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11229" seq="2017-11229" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability when manipulating Forms Data Format (FDF).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100186" adv="1">100186</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11230" seq="2017-11230" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11231" seq="2017-11231" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in Acrobat/Reader rendering engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11232" seq="2017-11232" published="2017-08-11" modified="2019-03-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100185" adv="1">100185</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11233" seq="2017-11233" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to block transfer of pixels. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11234" seq="2017-11234" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF data related to the way how the components of each pixel are stored. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11235" seq="2017-11235" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the image conversion engine when decompressing JPEG data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11236" seq="2017-11236" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal handling of UTF-16 literal strings. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11237" seq="2017-11237" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing module. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11238" seq="2017-11238" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to curve drawing. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11239" seq="2017-11239" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text strings. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1124" seq="2017-1124" published="2017-03-07" modified="2017-03-09" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21998053" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21998053</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96536">96536</ref>
    </refs>
    <vuln_soft>
      <prod name="maximo_asset_management" vendor="ibm">
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.1.1"/>
        <vers num="7.1.1.2"/>
        <vers num="7.1.1.3"/>
        <vers num="7.1.1.5"/>
        <vers num="7.1.1.6"/>
        <vers num="7.1.1.7"/>
        <vers num="7.1.1.8"/>
        <vers num="7.1.1.9"/>
        <vers num="7.1.1.10"/>
        <vers num="7.1.1.11"/>
        <vers num="7.1.1.12"/>
        <vers num="7.1.2"/>
        <vers num="7.5.0.0"/>
        <vers num="7.5.0.1"/>
        <vers num="7.5.0.2"/>
        <vers num="7.5.0.3"/>
        <vers num="7.5.0.4"/>
        <vers num="7.5.0.5"/>
        <vers num="7.5.0.6"/>
        <vers num="7.5.0.7"/>
        <vers num="7.5.0.8"/>
        <vers num="7.5.0.9"/>
        <vers num="7.5.0.10"/>
        <vers num="7.6"/>
        <vers num="7.6.0.0"/>
        <vers num="7.6.0.1"/>
        <vers num="7.6.0.2"/>
        <vers num="7.6.0.3"/>
        <vers num="7.6.0.4"/>
        <vers num="7.6.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11240" seq="2017-11240" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11241" seq="2017-11241" published="2017-08-11" modified="2019-03-13" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to polygons. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100180" adv="1">100180</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11242" seq="2017-11242" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to line segments. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11243" seq="2017-11243" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the XSLT engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11244" seq="2017-11244" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transformation of blocks of pixels. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11245" seq="2017-11245" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11246" seq="2017-11246" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when parsing JPEG data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11247" seq="2017-11247" published="2019-03-05" modified="2019-03-05" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-11248" seq="2017-11248" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to pixel block transfer. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11249" seq="2017-11249" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when parsing an invalid Enhanced Metafile Format (EMF) record. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1125" seq="2017-1125" published="2017-06-07" modified="2017-06-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004036" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004036</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98945" adv="1">98945</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121340" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121340</ref>
    </refs>
    <vuln_soft>
      <prod name="cognos_business_intelligence_server" vendor="ibm">
        <vers num="10.1.1"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.1.1"/>
        <vers num="10.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11250" seq="2017-11250" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11251" seq="2017-11251" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 parsing module. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11252" seq="2017-11252" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Adobe Graphics Manager (AGM) module. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11253" seq="2017-11253" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11254" seq="2017-11254" published="2017-08-11" modified="2019-03-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the Acrobat/Reader's JavaScript engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11255" seq="2017-11255" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF color map data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11256" seq="2017-11256" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when generating content using XFA layout engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100182" adv="1">100182</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11257" seq="2017-11257" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type confusion vulnerability in the XFA layout engine. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100181" adv="1">100181</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11258" seq="2017-11258" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded GIF image. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11259" seq="2017-11259" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1126" seq="2017-1126" published="2017-10-03" modified="2017-10-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22008470" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22008470</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101104" adv="1">101104</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121341" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121341</ref>
    </refs>
    <vuln_soft>
      <prod name="integration_bus" vendor="ibm">
        <vers num="9.0.0.0"/>
        <vers num="9.0.0.1"/>
        <vers num="9.0.0.2"/>
        <vers num="9.0.0.4"/>
        <vers num="9.0.0.5"/>
        <vers num="9.0.0.6"/>
        <vers num="9.0.0.7"/>
        <vers num="9.0.0.8"/>
        <vers num="10.0.0.0"/>
        <vers num="10.0.0.1"/>
        <vers num="10.0.0.2"/>
        <vers num="10.0.0.3"/>
        <vers num="10.0.0.4"/>
        <vers num="10.0.0.5"/>
        <vers num="10.0.0.6"/>
        <vers num="10.0.0.7"/>
        <vers num="10.0.0.8"/>
        <vers num="10.0.0.9"/>
      </prod>
      <prod name="websphere_message_broker" vendor="ibm">
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.0.0.6"/>
        <vers num="8.0.0.7"/>
        <vers num="8.0.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11260" seq="2017-11260" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as a GIF image. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11261" seq="2017-11261" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded TIF image. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11262" seq="2017-11262" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to drawing ASCII text string. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11263" seq="2017-11263" published="2017-08-11" modified="2019-03-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal data structure manipulation related to document encoding. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11264" seq="2017-11264" published="2019-03-05" modified="2019-03-05" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-11265" seq="2017-11265" published="2017-08-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Adobe Graphics Manager module. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100184" adv="1">100184</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11266" seq="2017-11266" published="2019-03-05" modified="2019-03-05" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2017-11267" seq="2017-11267" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as JPEG data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11268" seq="2017-11268" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11269" seq="2017-11269" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) image stream data. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1127" seq="2017-1127" published="2017-02-08" modified="2017-02-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21996645" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21996645</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96019" adv="1">96019</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_doors_next_generation" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
      </prod>
      <prod name="rational_requirements_composer" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11270" seq="2017-11270" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data representing icons. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11271" seq="2017-11271" published="2017-08-11" modified="2019-03-14" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transfer of pixel blocks. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100179" adv="1">100179</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039098" adv="1">1039098</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-24.html" adv="1" patch="1">https://helpx.adobe.com/security/products/acrobat/apsb17-24.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.1"/>
        <vers num="11.0.2"/>
        <vers num="11.0.3"/>
        <vers num="11.0.4"/>
        <vers num="11.0.5" edition="-:~~~windows~~"/>
        <vers num="11.0.6"/>
        <vers num="11.0.7"/>
        <vers num="11.0.8"/>
        <vers num="11.0.9"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
      </prod>
      <prod name="reader" vendor="adobe">
        <vers num="11.0.0"/>
        <vers num="11.0.01"/>
        <vers num="11.0.02"/>
        <vers num="11.0.03"/>
        <vers num="11.0.04"/>
        <vers num="11.0.05"/>
        <vers num="11.0.06"/>
        <vers num="11.0.07"/>
        <vers num="11.0.08"/>
        <vers num="11.0.09"/>
        <vers num="11.0.10"/>
        <vers num="11.0.11"/>
        <vers num="11.0.12"/>
        <vers num="11.0.13"/>
        <vers num="11.0.14"/>
        <vers num="11.0.15" edition=":~~desktop~~~"/>
        <vers num="11.0.16"/>
        <vers num="11.0.17"/>
        <vers num="11.0.18"/>
        <vers num="11.0.19"/>
        <vers num="11.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11272" seq="2017-11272" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100193" adv="1">100193</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11273" seq="2017-11273" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, which could lead to sensitive information disclosure.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11274" seq="2017-11274" published="2017-08-11" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100194" adv="1">100194</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11275" seq="2017-11275" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11276" seq="2017-11276" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11277" seq="2017-11277" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11278" seq="2017-11278" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11279" seq="2017-11279" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1128" seq="2017-1128" published="2017-02-08" modified="2017-02-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21996645" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21996645</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96017" adv="1">96017</ref>
    </refs>
    <vuln_soft>
      <prod name="rational_doors_next_generation" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
      </prod>
      <prod name="rational_requirements_composer" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.0.0"/>
        <vers num="4.0.0.1"/>
        <vers num="4.0.0.2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11280" seq="2017-11280" published="2017-08-11" modified="2017-08-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100244" adv="1">100244</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039100" adv="1">1039100</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html" adv="1" patch="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-27.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11281" seq="2017-11281" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100710" adv="1">100710</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039314" adv="1">1039314</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2702" adv="1">RHSA-2017:2702</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-28.html" adv="1" patch="1">https://helpx.adobe.com/security/products/flash-player/apsb17-28.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-16" adv="1">GLSA-201709-16</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42781/" adv="1">42781</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42782/" adv="1">42782</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=CvmnUeza9zw" adv="1">https://www.youtube.com/watch?v=CvmnUeza9zw</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="26.0.0.151" prev="1" edition=":~~~chrome~~"/>
        <vers num="26.0.0.151" prev="1" edition=":~~~edge~~"/>
        <vers num="26.0.0.151" prev="1" edition=":~~~internet_explorer~~"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11282" seq="2017-11282" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Bounds-Read.html" adv="1">http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Bounds-Read.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100716" adv="1">100716</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039314" adv="1">1039314</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2702" adv="1">RHSA-2017:2702</ref>
      <ref source="MISC" url="https://bugs.chromium.org/p/project-zero/issues/detail?id=1323" adv="1">https://bugs.chromium.org/p/project-zero/issues/detail?id=1323</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-28.html" adv="1">https://helpx.adobe.com/security/products/flash-player/apsb17-28.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-16" adv="1">GLSA-201709-16</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42783/" adv="1">42783</ref>
      <ref source="MISC" url="https://www.youtube.com/watch?v=6iZnIQbRf5M" adv="1">https://www.youtube.com/watch?v=6iZnIQbRf5M</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="26.0.0.151" prev="1" edition=":~~~chrome~~"/>
        <vers num="26.0.0.151" prev="1" edition=":~~~edge~~"/>
        <vers num="26.0.0.151" prev="1" edition=":~~~internet_explorer~~"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_server" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="enterprise_linux_workstation" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11283" seq="2017-11283" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100708" adv="1">100708</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039321" adv="1">1039321</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html" adv="1" patch="1">https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="adobe">
        <vers num="11.0" edition="update_1"/>
        <vers num="11.0" edition="update_10"/>
        <vers num="11.0" edition="update_11"/>
        <vers num="11.0" edition="update_12"/>
        <vers num="11.0" edition="update_2"/>
        <vers num="11.0" edition="update_3"/>
        <vers num="11.0" edition="update_4"/>
        <vers num="11.0" edition="update_5"/>
        <vers num="11.0" edition="update_6"/>
        <vers num="11.0" edition="update_7"/>
        <vers num="11.0" edition="update_8"/>
        <vers num="11.0" edition="update_9"/>
        <vers num="2016" edition="update_1"/>
        <vers num="2016" edition="update_2"/>
        <vers num="2016" edition="update_3"/>
        <vers num="2016" edition="update_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11284" seq="2017-11284" published="2017-12-01" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100708" adv="1">100708</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039321" adv="1">1039321</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html" adv="1" patch="1">https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="adobe">
        <vers num="11.0" edition="update_1"/>
        <vers num="11.0" edition="update_10"/>
        <vers num="11.0" edition="update_11"/>
        <vers num="11.0" edition="update_12"/>
        <vers num="11.0" edition="update_2"/>
        <vers num="11.0" edition="update_3"/>
        <vers num="11.0" edition="update_4"/>
        <vers num="11.0" edition="update_5"/>
        <vers num="11.0" edition="update_6"/>
        <vers num="11.0" edition="update_7"/>
        <vers num="11.0" edition="update_8"/>
        <vers num="11.0" edition="update_9"/>
        <vers num="2016" edition="update_1"/>
        <vers num="2016" edition="update_2"/>
        <vers num="2016" edition="update_3"/>
        <vers num="2016" edition="update_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11285" seq="2017-11285" published="2017-12-01" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100711" adv="1">100711</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039321" adv="1">1039321</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html" adv="1" patch="1">https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="adobe">
        <vers num="11.0" edition="update_1"/>
        <vers num="11.0" edition="update_10"/>
        <vers num="11.0" edition="update_11"/>
        <vers num="11.0" edition="update_12"/>
        <vers num="11.0" edition="update_2"/>
        <vers num="11.0" edition="update_3"/>
        <vers num="11.0" edition="update_4"/>
        <vers num="11.0" edition="update_5"/>
        <vers num="11.0" edition="update_6"/>
        <vers num="11.0" edition="update_7"/>
        <vers num="11.0" edition="update_8"/>
        <vers num="11.0" edition="update_9"/>
        <vers num="2016" edition="update_1"/>
        <vers num="2016" edition="update_2"/>
        <vers num="2016" edition="update_3"/>
        <vers num="2016" edition="update_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11286" seq="2017-11286" published="2017-12-01" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100715" adv="1">100715</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039321" adv="1">1039321</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html" adv="1" patch="1">https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="adobe">
        <vers num="11.0" edition="update_1"/>
        <vers num="11.0" edition="update_10"/>
        <vers num="11.0" edition="update_11"/>
        <vers num="11.0" edition="update_12"/>
        <vers num="11.0" edition="update_2"/>
        <vers num="11.0" edition="update_3"/>
        <vers num="11.0" edition="update_4"/>
        <vers num="11.0" edition="update_5"/>
        <vers num="11.0" edition="update_6"/>
        <vers num="11.0" edition="update_7"/>
        <vers num="11.0" edition="update_8"/>
        <vers num="11.0" edition="update_9"/>
        <vers num="2016" edition="update_1"/>
        <vers num="2016" edition="update_2"/>
        <vers num="2016" edition="update_3"/>
        <vers num="2016" edition="update_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11287" seq="2017-11287" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101838" adv="1">101838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039799" adv="1">1039799</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/connect/apsb17-35.html" adv="1">https://helpx.adobe.com/security/products/connect/apsb17-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="connect" vendor="adobe">
        <vers num="9.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11288" seq="2017-11288" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101838" adv="1">101838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039799" adv="1">1039799</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/connect/apsb17-35.html" adv="1">https://helpx.adobe.com/security/products/connect/apsb17-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="connect" vendor="adobe">
        <vers num="9.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11289" seq="2017-11289" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101838" adv="1">101838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039799" adv="1">1039799</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/connect/apsb17-35.html" adv="1">https://helpx.adobe.com/security/products/connect/apsb17-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="connect" vendor="adobe">
        <vers num="9.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1129" seq="2017-1129" published="2017-09-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999385" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21999385</ref>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22002103" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22002103</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121370" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121370</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42602/" adv="1">42602</ref>
    </refs>
    <vuln_soft>
      <prod name="expeditor" vendor="ibm">
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.3"/>
      </prod>
      <prod name="inotes" vendor="ibm">
        <vers num="8.5.0.0"/>
        <vers num="8.5.1.0"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.6"/>
        <vers num="9.0.0.0"/>
        <vers num="9.0.1.0"/>
        <vers num="9.0.1.1"/>
        <vers num="9.0.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11290" seq="2017-11290" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101838" adv="1">101838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039799" adv="1">1039799</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/connect/apsb17-35.html" adv="1">https://helpx.adobe.com/security/products/connect/apsb17-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="connect" vendor="adobe">
        <vers num="9.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11291" seq="2017-11291" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101838" adv="1">101838</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039799" adv="1">1039799</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/connect/apsb17-35.html" adv="1">https://helpx.adobe.com/security/products/connect/apsb17-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="connect" vendor="adobe">
        <vers num="9.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11292" seq="2017-11292" published="2017-10-22" modified="2017-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101286" adv="1">101286</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039582" adv="1">1039582</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:2899">RHSA-2017:2899</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-32.html" adv="1">https://helpx.adobe.com/security/products/flash-player/apsb17-32.html</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201710-22" adv="1">GLSA-201710-22</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="27.0.0.130" prev="1" edition=":~~~edge~~"/>
        <vers num="27.0.0.130" prev="1" edition=":~~~internet_explorer_11~~"/>
        <vers num="27.0.0.159" prev="1" edition=":~~~chrome~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11293" seq="2017-11293" published="2017-12-09" modified="2017-12-22" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102140" adv="1">102140</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039791" adv="1">1039791</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
        <vers num="17.000.0000" edition=":~~classic~~~"/>
        <vers num="17.008.30051"/>
        <vers num="17.011.30056" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="15.000.0000" edition=":~~classic~~~"/>
        <vers num="15.000.0000" edition=":~~continuous~~~"/>
        <vers num="15.006.30033" edition=":~~classic~~~"/>
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.006.30352" edition=":~~classic~~~"/>
        <vers num="15.006.30354" edition=":~~classic~~~"/>
        <vers num="15.006.30355" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
        <vers num="17.012.20093" edition=":~~continuous~~~"/>
        <vers num="17.012.20095" edition=":~~continuous~~~"/>
        <vers num="17.012.20096" edition=":~~continuous~~~"/>
        <vers num="17.012.20098" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
        <vers num="17.000.0000" edition=":~~classic~~~"/>
        <vers num="17.011.30059" edition=":~~classic~~~"/>
        <vers num="17.011.30065" edition=":~~classic~~~"/>
        <vers num="17.011.30066" edition=":~~classic~~~"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="15.000.0000" edition=":~~classic~~~"/>
        <vers num="15.000.0000" edition=":~~continuous~~~"/>
        <vers num="15.006.30033" edition=":~~classic~~~"/>
        <vers num="15.006.30060" edition=":~~classic~~~"/>
        <vers num="15.006.30094" edition=":~~classic~~~"/>
        <vers num="15.006.30096" edition=":~~classic~~~"/>
        <vers num="15.006.30097" edition=":~~classic~~~"/>
        <vers num="15.006.30119" edition=":~~classic~~~"/>
        <vers num="15.006.30121" edition=":~~classic~~~"/>
        <vers num="15.006.30172" edition=":~~classic~~~"/>
        <vers num="15.006.30173" edition=":~~classic~~~"/>
        <vers num="15.006.30174" edition=":~~classic~~~"/>
        <vers num="15.006.30198" edition=":~~classic~~~"/>
        <vers num="15.006.30201" edition=":~~classic~~~"/>
        <vers num="15.006.30243" edition=":~~classic~~~"/>
        <vers num="15.006.30244" edition=":~~classic~~~"/>
        <vers num="15.006.30279" edition=":~~classic~~~"/>
        <vers num="15.006.30280" edition=":~~classic~~~"/>
        <vers num="15.006.30306" edition=":~~classic~~~"/>
        <vers num="15.006.30352" edition=":~~classic~~~"/>
        <vers num="15.006.30354" edition=":~~classic~~~"/>
        <vers num="15.006.30355" edition=":~~classic~~~"/>
        <vers num="15.008.20082" edition=":~~continuous~~~"/>
        <vers num="15.009.20069" edition=":~~continuous~~~"/>
        <vers num="15.009.20071" edition=":~~continuous~~~"/>
        <vers num="15.009.20077" edition=":~~continuous~~~"/>
        <vers num="15.009.20079" edition=":~~continuous~~~"/>
        <vers num="15.010.20056" edition=":~~continuous~~~"/>
        <vers num="15.010.20059" edition=":~~continuous~~~"/>
        <vers num="15.010.20060" edition=":~~continuous~~~"/>
        <vers num="15.016.20039" edition=":~~continuous~~~"/>
        <vers num="15.016.20041" edition=":~~continuous~~~"/>
        <vers num="15.016.20045" edition=":~~continuous~~~"/>
        <vers num="15.017.20050" edition=":~~continuous~~~"/>
        <vers num="15.017.20053" edition=":~~continuous~~~"/>
        <vers num="15.020.20039" edition=":~~continuous~~~"/>
        <vers num="15.020.20042" edition=":~~continuous~~~"/>
        <vers num="15.023.20053" edition=":~~continuous~~~"/>
        <vers num="15.023.20056" edition=":~~continuous~~~"/>
        <vers num="15.023.20070" edition=":~~continuous~~~"/>
        <vers num="17.000.0000" edition=":~~continuous~~~"/>
        <vers num="17.009.20044" edition=":~~continuous~~~"/>
        <vers num="17.009.20058" edition=":~~continuous~~~"/>
        <vers num="17.012.20093" edition=":~~continuous~~~"/>
        <vers num="17.012.20095" edition=":~~continuous~~~"/>
        <vers num="17.012.20098" edition=":~~continuous~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11294" seq="2017-11294" published="2017-12-09" modified="2017-12-26" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101836" adv="1">101836</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039784" adv="1">1039784</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/shockwave/apsb17-40.html" adv="1">https://helpx.adobe.com/security/products/shockwave/apsb17-40.html</ref>
    </refs>
    <vuln_soft>
      <prod name="shockwave" vendor="adobe">
        <vers num="12.2.9.199" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11295" seq="2017-11295" published="2017-12-09" modified="2017-12-22" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101828" adv="1">101828</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/dng-converter/apsb17-37.html" adv="1" patch="1">https://helpx.adobe.com/security/products/dng-converter/apsb17-37.html</ref>
    </refs>
    <vuln_soft>
      <prod name="dng_converter" vendor="adobe">
        <vers num="9.12.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11296" seq="2017-11296" published="2017-12-09" modified="2017-12-14" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101844" adv="1">101844</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039800" adv="1">1039800</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/experience-manager/apsb17-41.html" adv="1">https://helpx.adobe.com/security/products/experience-manager/apsb17-41.html</ref>
    </refs>
    <vuln_soft>
      <prod name="experience_manager" vendor="adobe">
        <vers num="6.0.0"/>
        <vers num="6.1.0"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11297" seq="2017-11297" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11298" seq="2017-11298" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11299" seq="2017-11299" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1130" seq="2017-1130" published="2017-09-05" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999384" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21999384</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100632" adv="1">100632</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121371" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121371</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42604/" adv="1">42604</ref>
    </refs>
    <vuln_soft>
      <prod name="inotes" vendor="ibm">
        <vers num="8.5.0.0"/>
        <vers num="8.5.1.0"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.6"/>
        <vers num="9.0.0.0"/>
        <vers num="9.0.1.0"/>
        <vers num="9.0.1.1"/>
        <vers num="9.0.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11300" seq="2017-11300" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11301" seq="2017-11301" published="2017-12-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101839" adv="1">101839</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039798" adv="1">1039798</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html" adv="1">https://helpx.adobe.com/security/products/Digital-Editions/apsb17-39.html</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_editions" vendor="adobe">
        <vers num="4.5.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11302" seq="2017-11302" published="2017-12-09" modified="2017-12-26" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101840" adv="1">101840</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039785" adv="1">1039785</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/indesign/apsb17-38.html" adv="1">https://helpx.adobe.com/security/products/indesign/apsb17-38.html</ref>
    </refs>
    <vuln_soft>
      <prod name="indesign" vendor="adobe">
        <vers num="12.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11303" seq="2017-11303" published="2017-12-09" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101829" adv="1">101829</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039786" adv="1">1039786</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/photoshop/apsb17-34.html" adv="1">https://helpx.adobe.com/security/products/photoshop/apsb17-34.html</ref>
    </refs>
    <vuln_soft>
      <prod name="photoshop" vendor="adobe">
        <vers num="18.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11304" seq="2017-11304" published="2017-12-09" modified="2017-12-14" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101829" adv="1">101829</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039786" adv="1">1039786</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/photoshop/apsb17-34.html" adv="1">https://helpx.adobe.com/security/products/photoshop/apsb17-34.html</ref>
    </refs>
    <vuln_soft>
      <prod name="photoshop" vendor="adobe">
        <vers num="18.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11305" seq="2017-11305" published="2017-12-13" modified="2018-01-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102139" adv="1">102139</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039986" adv="1">1039986</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0081">RHSA-2018:0081</ref>
      <ref source="CONFIRM" url="https://helpx.adobe.com/security/products/flash-player/apsb17-42.html" adv="1" patch="1">https://helpx.adobe.com/security/products/flash-player/apsb17-42.html</ref>
    </refs>
    <vuln_soft>
      <prod name="flash_player" vendor="adobe">
        <vers num="27.0.0.187" prev="1" edition=":~~~chrome~~"/>
        <vers num="27.0.0.187" prev="1" edition=":~~~edge~~"/>
        <vers num="27.0.0.187" prev="1" edition=":~~~internet_explorer_11~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11306" seq="2017-11306" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11307" seq="2017-11307" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11308" seq="2017-11308" published="2018-05-19" modified="2018-06-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://helpx.adobe.com/security/products/acrobat/apsb17-36.html" adv="1">https://helpx.adobe.com/security/products/acrobat/apsb17-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_reader_2017" vendor="adobe">
        <vers num="2017.011.30066" prev="1"/>
      </prod>
      <prod name="acrobat_reader_dc" vendor="adobe">
        <vers num="2015.006.30355" prev="1" edition=":~~classic~~~"/>
        <vers num="2017.012.20098" prev="1" edition=":~~continuous~~~"/>
      </prod>
      <prod name="acrobat_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
      <prod name="reader_xi" vendor="adobe">
        <vers num="11.0.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11309" seq="2017-11309" published="2017-11-09" modified="2019-05-01" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://downloads.avaya.com/css/P8/documents/101044086" adv="1">http://downloads.avaya.com/css/P8/documents/101044086</ref>
      <ref source="MISC" url="http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt" adv="1">http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-(IPO)-v9.1.0-10.1-SOFT-CONSOLE-REMOTE-BUFFER-OVERFLOW-0DAY.txt</ref>
      <ref source="MISC" url="http://packetstormsecurity.com/files/144883/Avaya-IP-Office-IPO-10.1-Soft-Console-Remote-Buffer-Overflow.html" adv="1">http://packetstormsecurity.com/files/144883/Avaya-IP-Office-IPO-10.1-Soft-Console-Remote-Buffer-Overflow.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/101674" adv="1">101674</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43121/" adv="1">43121</ref>
    </refs>
    <vuln_soft>
      <prod name="ip_office" vendor="avaya">
        <vers num="10.0" edition="sp7"/>
        <vers num="10.1" edition="sp2"/>
        <vers num="10.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1131" seq="2017-1131" published="2017-06-23" modified="2017-06-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004270" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004270</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99227">99227</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121375" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121375</ref>
    </refs>
    <vuln_soft>
      <prod name="sterling_b2b_integrator" vendor="ibm">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11310" seq="2017-11310" published="2017-07-13" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99585">99585</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/8ca35831e91c3db8c6d281d09b605001003bec08" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/8ca35831e91c3db8c6d281d09b605001003bec08</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/517" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/517</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11311" seq="2017-11311" published="2017-07-17" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.debian.org/867579" adv="1" patch="1">https://bugs.debian.org/867579</ref>
      <ref source="CONFIRM" url="https://lib.openmpt.org/libopenmpt/md_announce-2017-07-07.html" adv="1" patch="1">https://lib.openmpt.org/libopenmpt/md_announce-2017-07-07.html</ref>
      <ref source="CONFIRM" url="https://source.openmpt.org/browse/openmpt/branches/OpenMPT-1.26/?op=revision&amp;rev=8438" adv="1" patch="1">https://source.openmpt.org/browse/openmpt/branches/OpenMPT-1.26/?op=revision&amp;rev=8438</ref>
      <ref source="CONFIRM" url="https://source.openmpt.org/browse/openmpt/trunk/?rev=6800" adv="1" patch="1">https://source.openmpt.org/browse/openmpt/trunk/?rev=6800</ref>
    </refs>
    <vuln_soft>
      <prod name="libopenmpt" vendor="openmpt">
        <vers num="0.2.8414" prev="1" edition="beta25"/>
      </prod>
      <prod name="openmpt" vendor="openmpt">
        <vers num="1.26.12.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11317" seq="2017-11317" published="2017-08-23" modified="2018-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-upload" adv="1">http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-upload</ref>
      <ref source="CONFIRM" url="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43874/">43874</ref>
    </refs>
    <vuln_soft>
      <prod name="ui_for_asp.net_ajax" vendor="telerik">
        <vers num="2016.3.1027" prev="1"/>
        <vers num="2017.2.503"/>
        <vers num="2017.2.621"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11318" seq="2017-11318" published="2017-07-17" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abusing pre-backup events.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://www.tarlogic.com/advisories/Tarlogic-2017-002.txt" adv="1">https://www.tarlogic.com/advisories/Tarlogic-2017-002.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="cobian_backup" vendor="cobiansoft">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11319" seq="2017-11319" published="2017-12-11" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Perspective ICM Investigation &amp; Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstormsecurity.com/files/145230/Perspective-ICM-Investigation-And-Case-5.1.1.16-Privilege-Escalation.html" adv="1">http://packetstormsecurity.com/files/145230/Perspective-ICM-Investigation-And-Case-5.1.1.16-Privilege-Escalation.html</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43210/" adv="1">43210</ref>
    </refs>
    <vuln_soft>
      <prod name="perspective" vendor="resolver">
        <vers num="5.1.1.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1132" seq="2017-1132" published="2017-06-23" modified="2017-06-26" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121418.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22004199" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22004199</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99233">99233</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121418" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121418</ref>
    </refs>
    <vuln_soft>
      <prod name="sterling_b2b_integrator" vendor="ibm">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11320" seq="2017-11320" published="2017-08-03" modified="2017-08-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Aug/3" adv="1">http://seclists.org/fulldisclosure/2017/Aug/3</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42427/">42427</ref>
    </refs>
    <vuln_soft>
      <prod name="tc7337_firmware" vendor="technicolor">
        <vers num="08.89.17.20.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11321" seq="2017-11321" published="2017-10-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://sysdream.com/news/lab/2017-09-29-cve-2017-11321-ucopia-wireless-appliance-5-1-8-restricted-shell-escape/">https://sysdream.com/news/lab/2017-09-29-cve-2017-11321-ucopia-wireless-appliance-5-1-8-restricted-shell-escape/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42937/" adv="1">42937</ref>
    </refs>
    <vuln_soft>
      <prod name="ucopia_wireless_appliance" vendor="ucopia">
        <vers num="5.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11322" seq="2017-11322" published="2017-10-02" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://sysdream.com/news/lab/2017-09-29-cve-2017-11322-ucopia-wireless-appliance-5-1-8-privileges-escalation/" adv="1">https://sysdream.com/news/lab/2017-09-29-cve-2017-11322-ucopia-wireless-appliance-5-1-8-privileges-escalation/</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42936/" adv="1">42936</ref>
    </refs>
    <vuln_soft>
      <prod name="ucopia_wireless_appliance" vendor="ucopia">
        <vers num="5.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11323" seq="2017-11323" published="2017-08-19" modified="2017-08-26" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as the initial substring of a filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://exploit.kitploit.com/2017/08/alzip-851-buffer-overflow.html" adv="1">http://exploit.kitploit.com/2017/08/alzip-851-buffer-overflow.html</ref>
      <ref source="MISC" url="http://www.altools.com/ALTools/ALZip/Version-History.aspx" adv="1">http://www.altools.com/ALTools/ALZip/Version-History.aspx</ref>
    </refs>
    <vuln_soft>
      <prod name="alzip" vendor="altools">
        <vers num="8.51" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11324" seq="2017-11324" published="2017-07-24" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/" adv="1">https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/</ref>
    </refs>
    <vuln_soft>
      <prod name="tilde_cms" vendor="tilde_cms_project">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11325" seq="2017-11325" published="2017-07-24" modified="2017-07-31" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/" adv="1">https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/</ref>
    </refs>
    <vuln_soft>
      <prod name="tilde_cms" vendor="tilde_cms_project">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11326" seq="2017-11326" published="2017-07-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/" adv="1">https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/</ref>
    </refs>
    <vuln_soft>
      <prod name="tilde_cms" vendor="tilde_cms_project">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11327" seq="2017-11327" published="2017-07-24" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/content.php?method=ftp_upload.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/" adv="1">https://backbox.org/membership/sharing-board/tilde-cms-v1-01-multiple-vulnerabilities/</ref>
    </refs>
    <vuln_soft>
      <prod name="tilde_cms" vendor="tilde_cms_project">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11328" seq="2017-11328" published="2017-07-17" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/VirusTotal/yara/commit/4a342f01e5439b9bb901aff1c6c23c536baeeb3f" adv="1">https://github.com/VirusTotal/yara/commit/4a342f01e5439b9bb901aff1c6c23c536baeeb3f</ref>
    </refs>
    <vuln_soft>
      <prod name="yara" vendor="virustotal">
        <vers num="3.0.0"/>
        <vers num="3.1.0"/>
        <vers num="3.2.0"/>
        <vers num="3.3.0"/>
        <vers num="3.4.0"/>
        <vers num="3.5.0"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11329" seq="2017-11329" published="2017-07-17" modified="2017-07-26" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/issues/2456" adv="1">https://github.com/glpi-project/glpi/issues/2456</ref>
      <ref source="CONFIRM" url="https://github.com/glpi-project/glpi/releases/tag/9.1.5" adv="1">https://github.com/glpi-project/glpi/releases/tag/9.1.5</ref>
    </refs>
    <vuln_soft>
      <prod name="glpi" vendor="glpi-project">
        <vers num="9.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1133" seq="2017-1133" published="2017-03-07" modified="2017-03-31" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999534" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21999534</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97239">97239</ref>
    </refs>
    <vuln_soft>
      <prod name="qradar_incident_forensics" vendor="ibm">
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.2.8"/>
      </prod>
      <prod name="qradar_security_information_and_event_manager" vendor="ibm">
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="7.2.6"/>
        <vers num="7.2.7"/>
        <vers num="7.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11330" seq="2017-11330" published="2017-07-31" modified="2017-08-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted avi file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/79" adv="1">http://seclists.org/fulldisclosure/2017/Jul/79</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42396/">42396</ref>
    </refs>
    <vuln_soft>
      <prod name="divfix++" vendor="divfix">
        <vers num="0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11331" seq="2017-11331" published="2017-07-31" modified="2017-08-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/80" adv="1">http://seclists.org/fulldisclosure/2017/Jul/80</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42397/">42397</ref>
    </refs>
    <vuln_soft>
      <prod name="vorbis-tools" vendor="xiph.org">
        <vers num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11332" seq="2017-11332" published="2017-07-31" modified="2019-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/81" adv="1">http://seclists.org/fulldisclosure/2017/Jul/81</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html" adv="1">[debian-lts-announce] 20171130 [SECURITY] [DLA 1197-1] sox security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html" adv="1">[debian-lts-announce] 20190305 [SECURITY] [DLA 1705-1] sox security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201810-02" adv="1">GLSA-201810-02</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42398/" adv="1">42398</ref>
    </refs>
    <vuln_soft>
      <prod name="sound_exchange" vendor="sound_exchange_project">
        <vers num="14.4.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11333" seq="2017-11333" published="2017-07-31" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/82" adv="1">http://seclists.org/fulldisclosure/2017/Jul/82</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/04/msg00033.html">[debian-lts-announce] 20180430 [SECURITY] [DLA 1368-1] libvorbis security update</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42399/">42399</ref>
    </refs>
    <vuln_soft>
      <prod name="libvorbis" vendor="xiph.org">
        <vers num="1.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11334" seq="2017-11334" published="2017-08-02" modified="2018-03-15" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3925">DSA-3925</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/07/17/4" adv="1" patch="1">[oss-security] 20170717 CVE-2017-11334 Qemu: exec: oob access during dma operation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99895">99895</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3369">RHSA-2017:3369</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3466">RHSA-2017:3466</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3470">RHSA-2017:3470</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3471">RHSA-2017:3471</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3472">RHSA-2017:3472</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3473">RHSA-2017:3473</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2017:3474">RHSA-2017:3474</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1471638" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1471638</ref>
      <ref source="MLIST" url="https://lists.gnu.org/archive/html/qemu-devel/2017-07/msg03775.html" adv="1" patch="1">[qemu-devel] 20170713 [PULL 21/41] exec: use qemu_ram_ptr_length to access guest ram</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3575-1/">USN-3575-1</ref>
    </refs>
    <vuln_soft>
      <prod name="qemu" vendor="qemu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11335" seq="2017-11335" published="2017-07-17" modified="2018-03-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugzilla.maptools.org/show_bug.cgi?id=2715">http://bugzilla.maptools.org/show_bug.cgi?id=2715</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3602-1/">USN-3602-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4100">DSA-4100</ref>
    </refs>
    <vuln_soft>
      <prod name="libtiff" vendor="libtiff">
        <vers num="4.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11336" seq="2017-11336" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470729">https://bugzilla.redhat.com/show_bug.cgi?id=1470729</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11337" seq="2017-11337" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470737">https://bugzilla.redhat.com/show_bug.cgi?id=1470737</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11338" seq="2017-11338" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470913">https://bugzilla.redhat.com/show_bug.cgi?id=1470913</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11339" seq="2017-11339" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470946">https://bugzilla.redhat.com/show_bug.cgi?id=1470946</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1134" seq="2017-1134" published="2017-03-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21998459" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21998459</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96764" adv="1">96764</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038389">1038389</ref>
    </refs>
    <vuln_soft>
      <prod name="power_hardware_management_console" vendor="ibm">
        <vers num="3.3.2"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11340" seq="2017-11340" published="2017-07-17" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470950">https://bugzilla.redhat.com/show_bug.cgi?id=1470950</ref>
    </refs>
    <vuln_soft>
      <prod name="exiv2" vendor="exiv2">
        <vers num="0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11341" seq="2017-11341" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470714" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1470714</ref>
    </refs>
    <vuln_soft>
      <prod name="libsass" vendor="libsass">
        <vers num="3.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11342" seq="2017-11342" published="2017-07-17" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=1470722" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=1470722</ref>
    </refs>
    <vuln_soft>
      <prod name="libsass" vendor="libsass">
        <vers num="3.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11343" seq="2017-11343" published="2017-07-17" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, will result in O(n) lookup time.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.gnu.org/archive/html/chicken-announce/2017-07/msg00000.html" adv="1">http://lists.gnu.org/archive/html/chicken-announce/2017-07/msg00000.html</ref>
    </refs>
    <vuln_soft>
      <prod name="chicken" vendor="call-cc">
        <vers num="4.12.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11344" seq="2017-11344" published="2017-07-17" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openwall.com/lists/oss-security/2017/07/14/3" adv="1">http://www.openwall.com/lists/oss-security/2017/07/14/3</ref>
      <ref source="CONFIRM" url="https://asuswrt.lostrealm.ca/changelog">https://asuswrt.lostrealm.ca/changelog</ref>
    </refs>
    <vuln_soft>
      <prod name="rt-ac1200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
      <prod name="rt-ac3100_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac3200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac51u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac52u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.4180" prev="1"/>
      </prod>
      <prod name="rt-ac5300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac53_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9883" prev="1"/>
      </prod>
      <prod name="rt-ac55u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac58u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7485" prev="1"/>
      </prod>
      <prod name="rt-ac66u_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac88u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n12+_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12d1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12hp_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3479" prev="1"/>
      </prod>
      <prod name="rt-n12hp_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.2943" prev="1"/>
      </prod>
      <prod name="rt-n16_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n18u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.378.7177" prev="1"/>
      </prod>
      <prod name="rt-n66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt_ac1200g_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3167" prev="1"/>
      </prod>
      <prod name="rt_ac1200gu_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.5577" prev="1"/>
      </prod>
      <prod name="rt_ac1900p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt_n12+_pro_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11345" seq="2017-11345" published="2017-07-17" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openwall.com/lists/oss-security/2017/07/14/3" adv="1">http://www.openwall.com/lists/oss-security/2017/07/14/3</ref>
      <ref source="CONFIRM" url="https://asuswrt.lostrealm.ca/changelog">https://asuswrt.lostrealm.ca/changelog</ref>
    </refs>
    <vuln_soft>
      <prod name="rt-ac1200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
      <prod name="rt-ac3100_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac3200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac51u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac52u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.4180" prev="1"/>
      </prod>
      <prod name="rt-ac5300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac53_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9883" prev="1"/>
      </prod>
      <prod name="rt-ac55u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac58u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7485" prev="1"/>
      </prod>
      <prod name="rt-ac66u_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac88u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n12+_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12d1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12hp_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3479" prev="1"/>
      </prod>
      <prod name="rt-n12hp_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.2943" prev="1"/>
      </prod>
      <prod name="rt-n16_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n18u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.378.7177" prev="1"/>
      </prod>
      <prod name="rt-n66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt_ac1200g_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3167" prev="1"/>
      </prod>
      <prod name="rt_ac1200gu_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.5577" prev="1"/>
      </prod>
      <prod name="rt_ac1900p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt_n12+_pro_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11346" seq="2017-11346" published="2017-07-17" modified="2017-08-11" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42358/">42358</ref>
      <ref source="CONFIRM" url="https://www.manageengine.com/products/desktop-central/remote-code-execution.html" adv="1" patch="1">https://www.manageengine.com/products/desktop-central/remote-code-execution.html</ref>
    </refs>
    <vuln_soft>
      <prod name="manageengine_desktop_central" vendor="zohocorp">
        <vers num="10.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11347" seq="2017-11347" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/imp0wd3r/MetInfo_Vuln/blob/master/README.md">https://github.com/imp0wd3r/MetInfo_Vuln/blob/master/README.md</ref>
    </refs>
    <vuln_soft>
      <prod name="metinfo" vendor="metinfo">
        <vers num="5.3.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11348" seq="2017-11348" published="2017-07-17" modified="2017-08-08" severity="Medium" CVSS_version="2.0" CVSS_score="6.3" CVSS_base_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:C/A:N)">
    <desc>
      <descript source="cve">In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/OctopusDeploy/Issues/issues/3654" adv="1">https://github.com/OctopusDeploy/Issues/issues/3654</ref>
    </refs>
    <vuln_soft>
      <prod name="octopus_deploy" vendor="octopus">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.1.0" edition="beta0001"/>
        <vers num="3.1.0" edition="beta0002"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.2.0" edition="beta0001"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.19"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.3.0" edition="beta0001"/>
        <vers num="3.3.0" edition="beta0002"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.8"/>
        <vers num="3.3.9"/>
        <vers num="3.3.10"/>
        <vers num="3.3.11"/>
        <vers num="3.3.12"/>
        <vers num="3.3.14"/>
        <vers num="3.3.15"/>
        <vers num="3.3.16"/>
        <vers num="3.3.17"/>
        <vers num="3.3.18"/>
        <vers num="3.3.19"/>
        <vers num="3.3.20"/>
        <vers num="3.3.21"/>
        <vers num="3.3.22"/>
        <vers num="3.3.24"/>
        <vers num="3.3.25"/>
        <vers num="3.3.26"/>
        <vers num="3.3.27"/>
        <vers num="3.4.0" edition="beta0001"/>
        <vers num="3.4.0" edition="beta0002"/>
        <vers num="3.4.1"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.7.0"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.7.10"/>
        <vers num="3.7.11"/>
        <vers num="3.7.12"/>
        <vers num="3.7.13"/>
        <vers num="3.7.14"/>
        <vers num="3.7.15"/>
        <vers num="3.7.16"/>
        <vers num="3.7.17"/>
        <vers num="3.7.18"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers num="3.8.8"/>
        <vers num="3.8.9"/>
        <vers num="3.9.0"/>
        <vers num="3.10.0"/>
        <vers num="3.10.1"/>
        <vers num="3.11.0"/>
        <vers num="3.11.1"/>
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.11.6"/>
        <vers num="3.11.7"/>
        <vers num="3.11.9"/>
        <vers num="3.11.10"/>
        <vers num="3.11.11"/>
        <vers num="3.11.12"/>
        <vers num="3.11.13"/>
        <vers num="3.11.14"/>
        <vers num="3.11.15"/>
        <vers num="3.11.16"/>
        <vers num="3.11.17"/>
        <vers num="3.11.18"/>
        <vers num="3.12.0"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers num="3.12.3"/>
        <vers num="3.12.4"/>
        <vers num="3.12.5"/>
        <vers num="3.12.6"/>
        <vers num="3.12.7"/>
        <vers num="3.12.9"/>
        <vers num="3.13.0"/>
        <vers num="3.13.1"/>
        <vers num="3.13.2"/>
        <vers num="3.13.3"/>
        <vers num="3.13.5"/>
        <vers num="3.13.6"/>
        <vers num="3.13.7"/>
        <vers num="3.13.9"/>
        <vers num="3.13.10"/>
        <vers num="3.14.1"/>
        <vers num="3.14.15"/>
        <vers num="3.14.159"/>
        <vers num="3.14.1592"/>
        <vers num="3.14.15926"/>
        <vers num="3.15.0"/>
        <vers num="3.15.1"/>
        <vers num="3.15.2"/>
        <vers num="3.15.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11349" seq="2017-11349" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://nullku7.github.io/stuff/exposure/industrial/2017/05/02/Thermofisher-dataTaker.html" adv="1">https://nullku7.github.io/stuff/exposure/industrial/2017/05/02/Thermofisher-dataTaker.html</ref>
      <ref source="MISC" url="https://twitter.com/nullku7/status/859238295959609344" adv="1">https://twitter.com/nullku7/status/859238295959609344</ref>
    </refs>
    <vuln_soft>
      <prod name="dt8x_firmware" vendor="datataker">
        <vers num="1.72.007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11350" seq="2017-11350" published="2017-09-13" modified="2017-09-21" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://iscouncil.blogspot.com/2017/08/multiple-vulnerabilities-in-axesstel.html" adv="1">https://iscouncil.blogspot.com/2017/08/multiple-vulnerabilities-in-axesstel.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mu553s_firmware" vendor="axesstel">
        <vers num="mu553s-v1.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11351" seq="2017-11351" published="2017-09-13" modified="2017-09-21" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://iscouncil.blogspot.com/2017/08/multiple-vulnerabilities-in-axesstel.html" adv="1">https://iscouncil.blogspot.com/2017/08/multiple-vulnerabilities-in-axesstel.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mu553s_firmware" vendor="axesstel">
        <vers num="mu553s-v1.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11352" seq="2017-11352" published="2017-07-17" modified="2018-06-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99600" adv="1">99600</ref>
      <ref source="CONFIRM" url="https://bugs.debian.org/868469" adv="1" patch="1">https://bugs.debian.org/868469</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/502" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/502</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3681-1/">USN-3681-1</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4040">DSA-4040</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.5-9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11353" seq="2017-11353" published="2017-07-17" modified="2017-07-25" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">yadm (yet another dotfile manager) 1.10.0 has a race condition (related to the behavior of git commands in setting permissions for new files and directories), which potentially allows access to SSH and PGP keys.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.debian.org/868300" adv="1" patch="1">https://bugs.debian.org/868300</ref>
      <ref source="CONFIRM" url="https://github.com/TheLocehiliosan/yadm/issues/74" adv="1" patch="1">https://github.com/TheLocehiliosan/yadm/issues/74</ref>
    </refs>
    <vuln_soft>
      <prod name="yadm" vendor="yadm_project">
        <vers num="1.10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11354" seq="2017-11354" published="2017-07-17" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/4" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/4</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11355" seq="2017-11355" published="2017-08-02" modified="2017-09-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2017/Jul/28" adv="1">20170717 PEGA Platform &lt;= 7.2 ML0 - Multiple vulnerabilities</ref>
      <ref source="CONFIRM" url="https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve">https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42335/">42335</ref>
    </refs>
    <vuln_soft>
      <prod name="pega_platform" vendor="pega">
        <vers num="7.2_ml0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11356" seq="2017-11356" published="2017-08-02" modified="2017-09-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2017/Jul/28" adv="1">20170717 PEGA Platform &lt;= 7.2 ML0 - Multiple vulnerabilities</ref>
      <ref source="CONFIRM" url="https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve">https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42335/">42335</ref>
    </refs>
    <vuln_soft>
      <prod name="pega_platform" vendor="pega">
        <vers num="7.2_ml0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11357" seq="2017-11357" published="2017-08-23" modified="2018-01-27" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference" adv="1">http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43874/">43874</ref>
    </refs>
    <vuln_soft>
      <prod name="ui_for_asp.net_ajax" vendor="telerik">
        <vers num="2017.2.621" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11358" seq="2017-11358" published="2017-07-31" modified="2019-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/81" adv="1">http://seclists.org/fulldisclosure/2017/Jul/81</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html" adv="1">[debian-lts-announce] 20171130 [SECURITY] [DLA 1197-1] sox security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html" adv="1">[debian-lts-announce] 20190305 [SECURITY] [DLA 1705-1] sox security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201810-02" adv="1">GLSA-201810-02</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42398/" adv="1">42398</ref>
    </refs>
    <vuln_soft>
      <prod name="sound_exchange" vendor="sound_exchange_project">
        <vers num="14.4.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11359" seq="2017-11359" published="2017-07-31" modified="2019-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://seclists.org/fulldisclosure/2017/Jul/81" adv="1">http://seclists.org/fulldisclosure/2017/Jul/81</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/11/msg00043.html" adv="1">[debian-lts-announce] 20171130 [SECURITY] [DLA 1197-1] sox security update</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/03/msg00007.html" adv="1">[debian-lts-announce] 20190305 [SECURITY] [DLA 1705-1] sox security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201810-02" adv="1">GLSA-201810-02</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42398/" adv="1">42398</ref>
    </refs>
    <vuln_soft>
      <prod name="sound_exchange" vendor="sound_exchange_project">
        <vers num="14.4.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="7.0"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11360" seq="2017-11360" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/518" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/518</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11361" seq="2017-11361" published="2017-07-17" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://neonsea.uk/blog/2017/07/17/cve-2017-11361.html" adv="1">https://neonsea.uk/blog/2017/07/17/cve-2017-11361.html</ref>
    </refs>
    <vuln_soft>
      <prod name="inteno_router_firmware" vendor="intenogroup">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11362" seq="2017-11362" published="2017-07-17" modified="2019-05-22" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:1296">RHSA-2018:1296</ref>
      <ref source="MISC" url="https://bugs.php.net/bug.php?id=73473" adv="1">https://bugs.php.net/bug.php?id=73473</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201709-21">GLSA-201709-21</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20180112-0001/">https://security.netapp.com/advisory/ntap-20180112-0001/</ref>
      <ref source="UBUNTU" url="https://usn.ubuntu.com/3566-2/">USN-3566-2</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.20"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11364" seq="2017-11364" published="2017-08-02" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039015" adv="1">1039015</ref>
      <ref source="CONFIRM" url="https://developer.joomla.org/security-centre/700-20170704-core-installer-lack-of-ownership-verification.html" adv="1">https://developer.joomla.org/security-centre/700-20170704-core-installer-lack-of-ownership-verification.html</ref>
      <ref source="MISC" url="https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Hanno-Boeck-Abusing-Certificate-Transparency-Logs.pdf" adv="1">https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Hanno-Boeck-Abusing-Certificate-Transparency-Logs.pdf</ref>
      <ref source="MISC" url="https://twitter.com/hanno/status/890281330906247168" adv="1">https://twitter.com/hanno/status/890281330906247168</ref>
    </refs>
    <vuln_soft>
      <prod name="joomla!" vendor="joomla">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.14"/>
        <vers num="1.5.15" edition="rc"/>
        <vers num="1.5.16"/>
        <vers num="1.5.17"/>
        <vers num="1.5.18"/>
        <vers num="1.5.19"/>
        <vers num="1.5.20"/>
        <vers num="1.5.21"/>
        <vers num="1.5.22"/>
        <vers num="1.5.23"/>
        <vers num="1.5.24"/>
        <vers num="1.5.25"/>
        <vers num="1.5.26"/>
        <vers num="1.6" edition="alpha"/>
        <vers num="1.6" edition="alpha2"/>
        <vers num="1.6" edition="beta1"/>
        <vers num="1.6" edition="beta10"/>
        <vers num="1.6" edition="beta11"/>
        <vers num="1.6" edition="beta12"/>
        <vers num="1.6" edition="beta13"/>
        <vers num="1.6" edition="beta14"/>
        <vers num="1.6" edition="beta15"/>
        <vers num="1.6" edition="beta2"/>
        <vers num="1.6" edition="beta3"/>
        <vers num="1.6" edition="beta4"/>
        <vers num="1.6" edition="beta5"/>
        <vers num="1.6" edition="beta6"/>
        <vers num="1.6" edition="beta7"/>
        <vers num="1.6" edition="beta8"/>
        <vers num="1.6" edition="beta9"/>
        <vers num="1.6" edition="rc1"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.4.0" edition="alpha"/>
        <vers num="3.4.0" edition="beta1"/>
        <vers num="3.4.0" edition="beta2"/>
        <vers num="3.4.0" edition="beta3"/>
        <vers num="3.4.0" edition="rc1"/>
        <vers num="3.4.1" edition="rc1"/>
        <vers num="3.4.1" edition="rc2"/>
        <vers num="3.4.2" edition="rc1"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8" edition="rc"/>
        <vers num="3.5.0" edition="beta"/>
        <vers num="3.5.0" edition="beta2"/>
        <vers num="3.5.0" edition="beta3"/>
        <vers num="3.5.0" edition="beta4"/>
        <vers num="3.5.0" edition="beta5"/>
        <vers num="3.5.0" edition="rc"/>
        <vers num="3.5.0" edition="rc2"/>
        <vers num="3.5.0" edition="rc3"/>
        <vers num="3.5.0" edition="rc4"/>
        <vers num="3.5.1" edition="rc"/>
        <vers num="3.6.0" edition="alpha"/>
        <vers num="3.6.0" edition="beta1"/>
        <vers num="3.6.0" edition="beta2"/>
        <vers num="3.6.0" edition="rc"/>
        <vers num="3.6.0" edition="rc2"/>
        <vers num="3.6.1" edition="rc1"/>
        <vers num="3.6.1" edition="rc2"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3" edition="rc1"/>
        <vers num="3.6.3" edition="rc2"/>
        <vers num="3.6.3" edition="rc3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.7.0"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11365" seq="2017-11365" published="2019-05-23" modified="2019-05-24" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/symfony/symfony/commit/878198cefae028386c6dc800ccbf18f2b9cbff3f" adv="1" patch="1">https://github.com/symfony/symfony/commit/878198cefae028386c6dc800ccbf18f2b9cbff3f</ref>
      <ref source="MISC" url="https://github.com/symfony/symfony/pull/23507" adv="1" patch="1">https://github.com/symfony/symfony/pull/23507</ref>
    </refs>
    <vuln_soft>
      <prod name="symfony" vendor="sensiolabs">
        <vers num="2.7.30"/>
        <vers num="2.8.23"/>
        <vers num="3.2.10"/>
        <vers num="3.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11366" seq="2017-11366" published="2017-08-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.jianshu.com/p/41ac7ac2a7af" adv="1">http://www.jianshu.com/p/41ac7ac2a7af</ref>
      <ref source="MISC" url="https://github.com/Codiad/Codiad/issues/1011" adv="1">https://github.com/Codiad/Codiad/issues/1011</ref>
      <ref source="MISC" url="https://github.com/Codiad/Codiad/pull/1013" adv="1">https://github.com/Codiad/Codiad/pull/1013</ref>
      <ref source="MISC" url="https://github.com/Codiad/Codiad/pull/1013/commits/b3645b4c6718cef6de7003f41aafe7bfcc0395d1" adv="1" patch="1">https://github.com/Codiad/Codiad/pull/1013/commits/b3645b4c6718cef6de7003f41aafe7bfcc0395d1</ref>
    </refs>
    <vuln_soft>
      <prod name="codiad" vendor="codiad">
        <vers num="2.8.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11367" seq="2017-11367" published="2017-07-17" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/Ed-von-Schleck/shoco/issues/28" adv="1">https://github.com/Ed-von-Schleck/shoco/issues/28</ref>
    </refs>
    <vuln_soft>
      <prod name="shoco" vendor="shoco_project">
        <vers num="2017-07-17" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11368" seq="2017-11368" published="2017-08-09" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100291" adv="1">100291</ref>
      <ref source="REDHAT" url="https://access.redhat.com/errata/RHSA-2018:0666">RHSA-2018:0666</ref>
      <ref source="CONFIRM" url="https://github.com/krb5/krb5/commit/ffb35baac6981f9e8914f8f3bffd37f284b85970" adv="1" patch="1">https://github.com/krb5/krb5/commit/ffb35baac6981f9e8914f8f3bffd37f284b85970</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4HNWXM6OQU7G23MG7XWIOBRGP43ECLDT/" adv="1">FEDORA-2017-e5b36383f4</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBUTXMNZWMVJLQ4NDX5OQFPUVCJRLV3W/" adv="1">FEDORA-2017-8e9d9771c4</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.7"/>
        <vers num="5-1.7.1"/>
        <vers num="5-1.8"/>
        <vers num="5-1.8.1"/>
        <vers num="5-1.8.2"/>
        <vers num="5-1.8.3"/>
        <vers num="5-1.8.4"/>
        <vers num="5-1.8.5"/>
        <vers num="5-1.8.6"/>
        <vers num="5-1.9"/>
        <vers num="5-1.9.1"/>
        <vers num="5-1.9.2"/>
        <vers num="5-1.9.3"/>
        <vers num="5-1.9.4"/>
        <vers num="5-1.10"/>
        <vers num="5-1.10.1"/>
        <vers num="5-1.10.2"/>
        <vers num="5-1.10.3"/>
        <vers num="5-1.10.4"/>
        <vers num="5-1.11"/>
        <vers num="5-1.11.1"/>
        <vers num="5-1.11.2"/>
        <vers num="5-1.11.3"/>
        <vers num="5-1.11.4"/>
        <vers num="5-1.11.5"/>
        <vers num="5-1.12"/>
        <vers num="5-1.12.1"/>
        <vers num="5-1.12.2"/>
        <vers num="5-1.12.3"/>
        <vers num="5-1.13"/>
        <vers num="5-1.13.1"/>
        <vers num="5-1.13.2"/>
        <vers num="5-1.13.3"/>
        <vers num="5-1.13.5"/>
        <vers num="5-1.13.6"/>
        <vers num="5-1.13.7"/>
        <vers num="5-1.14" edition="alpha1"/>
        <vers num="5-1.14" edition="beta1"/>
        <vers num="5-1.14" edition="beta2"/>
        <vers num="5-1.14.1"/>
        <vers num="5-1.14.2"/>
        <vers num="5-1.14.3"/>
        <vers num="5-1.14.4"/>
        <vers num="5-1.14.5"/>
        <vers num="5-1.15"/>
        <vers num="5-1.15.1" edition="beta1"/>
        <vers num="5-1.15.1" edition="beta2"/>
      </prod>
      <prod name="fedora" vendor="fedoraproject">
        <vers num="25"/>
        <vers num="26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1137" seq="2017-1137" published="2017-05-10" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21998469" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21998469</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038464">1038464</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="8.0"/>
        <vers num="8.5"/>
        <vers num="8.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11379" seq="2017-11379" published="2017-08-01" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1117663" adv="1" patch="1">https://success.trendmicro.com/solution/1117663</ref>
      <ref source="MISC" url="https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities" adv="1">https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="deep_discovery_director" vendor="trendmicro">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11380" seq="2017-11380" published="2017-08-01" modified="2017-08-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1117663" adv="1" patch="1">https://success.trendmicro.com/solution/1117663</ref>
      <ref source="MISC" url="https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities" adv="1">https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="deep_discovery_director" vendor="trendmicro">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11381" seq="2017-11381" published="2017-08-01" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1117663" adv="1" patch="1">https://success.trendmicro.com/solution/1117663</ref>
      <ref source="MISC" url="https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities" adv="1">https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="deep_discovery_director" vendor="trendmicro">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11382" seq="2017-11382" published="2017-08-03" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100076">100076</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-503" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-503</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1116750" adv="1" patch="1">https://success.trendmicro.com/solution/1116750</ref>
    </refs>
    <vuln_soft>
      <prod name="deep_discovery_email_inspector" vendor="trendmicro">
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11383" seq="2017-11383" published="2017-08-02" modified="2017-08-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-493" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-493</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11384" seq="2017-11384" published="2017-08-02" modified="2017-08-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-494" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-494</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11385" seq="2017-11385" published="2017-08-02" modified="2017-08-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-495" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-495</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11386" seq="2017-11386" published="2017-08-02" modified="2017-08-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-496" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-496</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11387" seq="2017-11387" published="2017-08-02" modified="2017-08-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-497" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-497</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11388" seq="2017-11388" published="2017-08-02" modified="2017-08-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-498" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-498</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-499" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-499</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11389" seq="2017-11389" published="2017-08-02" modified="2017-08-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039049">1039049</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-500" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-500</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11390" seq="2017-11390" published="2017-08-02" modified="2017-08-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100078">100078</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-501" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-501</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117722" adv="1" patch="1">https://success.trendmicro.com/solution/1117722</ref>
    </refs>
    <vuln_soft>
      <prod name="control_manager" vendor="trendmicro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11391" seq="2017-11391" published="2017-08-03" modified="2017-08-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100075" adv="1">100075</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-502" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-502</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117723" adv="1">https://success.trendmicro.com/solution/1117723</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_messaging_security_virtual_appliance" vendor="trendmicro">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11392" seq="2017-11392" published="2017-08-03" modified="2017-08-04" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100075">100075</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-504" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-504</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117723" adv="1">https://success.trendmicro.com/solution/1117723</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_messaging_security_virtual_appliance" vendor="trendmicro">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11393" seq="2017-11393" published="2017-08-03" modified="2017-08-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100127">100127</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-522" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-522</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117769" adv="1" patch="1">https://success.trendmicro.com/solution/1117769</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trendmicro">
        <vers num="11.0" edition="sp1"/>
        <vers num="12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11394" seq="2017-11394" published="2017-08-03" modified="2017-10-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100130" adv="1">100130</ref>
      <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-17-521" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-17-521</ref>
      <ref source="MISC" url="https://success.trendmicro.com/solution/1117769" adv="1" patch="1">https://success.trendmicro.com/solution/1117769</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/42971/">42971</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trendmicro">
        <vers num="11.0" edition="sp1"/>
        <vers num="12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11395" seq="2017-11395" published="2017-09-22" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.coresecurity.com/advisories/trend-micro-smart-protection-os-command-injection" adv="1">http://www.coresecurity.com/advisories/trend-micro-smart-protection-os-command-injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100461" adv="1">100461</ref>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1117933" adv="1" patch="1">https://success.trendmicro.com/solution/1117933</ref>
    </refs>
    <vuln_soft>
      <prod name="smart_protection_server" vendor="trendmicro">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11396" seq="2017-11396" published="2017-09-22" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1117412" adv="1" patch="1">https://success.trendmicro.com/solution/1117412</ref>
    </refs>
    <vuln_soft>
      <prod name="web_security_virtual_appliance" vendor="trendmicro">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11397" seq="2017-11397" published="2017-12-15" modified="2017-12-29" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://fortiguard.com/zeroday/FG-VD-17-079" adv="1">https://fortiguard.com/zeroday/FG-VD-17-079</ref>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1118796" adv="1" patch="1">https://success.trendmicro.com/solution/1118796</ref>
    </refs>
    <vuln_soft>
      <prod name="encryption_for_email" vendor="trendmicro">
        <vers num="5.6.0.1073" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11398" seq="2017-11398" published="2018-01-19" modified="2019-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/102275" adv="1">102275</ref>
      <ref source="CONFIRM" url="https://success.trendmicro.com/solution/1118992" adv="1">https://success.trendmicro.com/solution/1118992</ref>
      <ref source="MISC" url="https://www.coresecurity.com/advisories/trend-micro-smart-protection-server-multiple-vulnerabilities" adv="1">https://www.coresecurity.com/advisories/trend-micro-smart-protection-server-multiple-vulnerabilities</ref>
      <ref source="EXPLOIT-DB" url="https://www.exploit-db.com/exploits/43388/" adv="1">43388</ref>
    </refs>
    <vuln_soft>
      <prod name="smart_protection_server" vendor="trendmicro">
        <vers num="3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11399" seq="2017-11399" published="2017-07-17" modified="2017-11-06" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) or possibly have unspecified other impact via a crafted APE file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3957">DSA-3957</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/100019">100019</ref>
      <ref source="CONFIRM" url="https://github.com/FFmpeg/FFmpeg/commit/ba4beaf6149f7241c8bd85fe853318c2f6837ad0" adv="1" patch="1">https://github.com/FFmpeg/FFmpeg/commit/ba4beaf6149f7241c8bd85fe853318c2f6837ad0</ref>
    </refs>
    <vuln_soft>
      <prod name="ffmpeg" vendor="ffmpeg">
        <vers num="3.3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1140" seq="2017-1140" published="2017-06-08" modified="2017-06-13" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999133" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21999133</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97322" adv="1">97322</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/121905" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/121905</ref>
    </refs>
    <vuln_soft>
      <prod name="business_process_manager" vendor="ibm">
        <vers num="8.0.0.0"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.0.1.2"/>
        <vers num="8.0.1.3"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.5.0"/>
        <vers num="8.5.6.0" edition="cf1"/>
        <vers num="8.5.6.0" edition="cf2"/>
        <vers num="8.5.7.0" edition="cf2016.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11400" seq="2017-11400" published="2017-11-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlled, data. This occurs because the appliance_config file is signed but the .tar.sec file is unsigned.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt" adv="1">https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt</ref>
      <ref source="MISC" url="https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf" adv="1">https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="tofino_xenon_security_appliance_firmware" vendor="belden">
        <vers num="3.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11401" seq="2017-11401" published="2017-11-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt" adv="1">https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt</ref>
      <ref source="MISC" url="https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf" adv="1">https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="tofino_xenon_security_appliance_firmware" vendor="belden">
        <vers num="3.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11402" seq="2017-11402" published="2017-11-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OPC classic and in custom netfilter modules allow an attacker to remotely activate rules on the firewall and to connect to any TCP port of a protected asset, thus bypassing the firewall. The attack methodology is a crafted OPC dynamic port shift.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt" adv="1">https://github.com/airbus-seclab/security-advisories/blob/master/belden/tofino.txt</ref>
      <ref source="MISC" url="https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf" adv="1">https://www.belden.com/hubfs/support/security/bulletins/Belden-Security-Bulletin-BSECV-2017-14-1v1-1.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="tofino_xenon_security_appliance_firmware" vendor="belden">
        <vers num="3.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11403" seq="2017-11403" published="2017-07-17" modified="2018-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://hg.code.sf.net/p/graphicsmagick/code/rev/d0a76868ca37" adv="1" patch="1">http://hg.code.sf.net/p/graphicsmagick/code/rev/d0a76868ca37</ref>
      <ref source="MISC" url="https://blogs.gentoo.org/ago/2017/07/12/graphicsmagick-use-after-free-in-closeblob-blob-c/" adv="1" patch="1">https://blogs.gentoo.org/ago/2017/07/12/graphicsmagick-use-after-free-in-closeblob-blob-c/</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html">[debian-lts-announce] 20180803 [SECURITY] [DLA 1456-1] graphicsmagick security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2018/dsa-4321">DSA-4321</ref>
    </refs>
    <vuln_soft>
      <prod name="graphicsmagick" vendor="graphicsmagick">
        <vers num="1.3.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11404" seq="2017-11404" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/CMSMadeSimple/upl0advul123/images/upload_vulnerability_yuesec.html" adv="1">http://www.yuesec.com/img/cccccve/CMSMadeSimple/upl0advul123/images/upload_vulnerability_yuesec.html</ref>
    </refs>
    <vuln_soft>
      <prod name="cms_made_simple" vendor="cmsmadesimple">
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11405" seq="2017-11405" published="2017-07-17" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.yuesec.com/img/cccccve/CMSMadeSimple/upl0advul123/filepickerimages/FilePicker_upload_vulnerability.html" adv="1">http://www.yuesec.com/img/cccccve/CMSMadeSimple/upl0advul123/filepickerimages/FilePicker_upload_vulnerability.html</ref>
    </refs>
    <vuln_soft>
      <prod name="cms_made_simple" vendor="cmsmadesimple">
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11406" seq="2017-11406" published="2017-07-18" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99903" adv="1">99903</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038966" adv="1">1038966</ref>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13797" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13797</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=250216263c3a3f2c651e80d9c6b3dc0adc53dc2c" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=250216263c3a3f2c651e80d9c6b3dc0adc53dc2c</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/01/msg00010.html" adv="1">[debian-lts-announce] 20190115 [SECURITY] [DLA 1634-1] wireshark security update</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-36.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-36.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11407" seq="2017-11407" published="2017-07-18" modified="2019-03-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99910" adv="1">99910</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038966" adv="1">1038966</ref>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13792" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13792</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=4e54dae7f0d7840836ee6d5ce1e688f152ab2978" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=4e54dae7f0d7840836ee6d5ce1e688f152ab2978</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/01/msg00010.html" adv="1">[debian-lts-announce] 20190115 [SECURITY] [DLA 1634-1] wireshark security update</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-35.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-35.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11408" seq="2017-11408" published="2017-07-18" modified="2018-02-03" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99894">99894</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038966">1038966</ref>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13780" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13780</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a102c172b0b2fe231fdb49f4f6694603f5b93b0c" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a102c172b0b2fe231fdb49f4f6694603f5b93b0c</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=e57c86ef8e3b57b7f90c224f6053d1eacf20e1ba" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=e57c86ef8e3b57b7f90c224f6053d1eacf20e1ba</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2017/12/msg00029.html">[debian-lts-announce] 20171231 [SECURITY] [DLA 1226-1] wireshark security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4060">DSA-4060</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-34.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-34.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11409" seq="2017-11409" published="2017-07-18" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99914" adv="1">99914</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038966" adv="1">1038966</ref>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13603" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13603</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=57b83bbbd76f543eb8d108919f13b662910bff9a" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=57b83bbbd76f543eb8d108919f13b662910bff9a</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/01/msg00010.html" adv="1">[debian-lts-announce] 20190115 [SECURITY] [DLA 1634-1] wireshark security update</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-37.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-37.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1141" seq="2017-1141" published="2017-04-28" modified="2017-05-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22002620" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg22002620</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98161" adv="1">98161</ref>
    </refs>
    <vuln_soft>
      <prod name="insights_foundation_for_energy" vendor="ibm">
        <vers num="1.0"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11410" seq="2017-11410" published="2017-07-18" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13796" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13796</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=3c7168cc5f044b4da8747d35da0b2b204dabf398" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=3c7168cc5f044b4da8747d35da0b2b204dabf398</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-13.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-13.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11411" seq="2017-11411" published="2017-07-18" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13755" adv="1" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13755</ref>
      <ref source="CONFIRM" url="https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a83a324acdfc07a0ca8b65e6ebaba3374ab19c76" adv="1" patch="1">https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a83a324acdfc07a0ca8b65e6ebaba3374ab19c76</ref>
      <ref source="CONFIRM" url="https://www.wireshark.org/security/wnpa-sec-2017-28.html" adv="1">https://www.wireshark.org/security/wnpa-sec-2017-28.html</ref>
    </refs>
    <vuln_soft>
      <prod name="wireshark" vendor="wireshark">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11412" seq="2017-11412" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11413" seq="2017-11413" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11414" seq="2017-11414" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11415" seq="2017-11415" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11416" seq="2017-11416" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11417" seq="2017-11417" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11418" seq="2017-11418" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11419" seq="2017-11419" published="2017-07-18" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://github.com/FiyoCMS/FiyoCMS/issues/5" adv="1" patch="1">https://github.com/FiyoCMS/FiyoCMS/issues/5</ref>
    </refs>
    <vuln_soft>
      <prod name="fiyo_cms" vendor="fiyo">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1142" seq="2017-1142" published="2017-03-27" modified="2017-03-31" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM Reference #: 1998874.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21998874" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21998874</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97081" adv="1">97081</ref>
    </refs>
    <vuln_soft>
      <prod name="kenexa_lcms_premier" vendor="ibm">
        <vers num="9.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.3"/>
        <vers num="9.4"/>
        <vers num="9.5"/>
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11420" seq="2017-11420" published="2017-07-18" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code via long device information that is mishandled during a strcat to a device list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openwall.com/lists/oss-security/2017/07/13/1" adv="1">http://www.openwall.com/lists/oss-security/2017/07/13/1</ref>
      <ref source="CONFIRM" url="https://asuswrt.lostrealm.ca/changelog">https://asuswrt.lostrealm.ca/changelog</ref>
    </refs>
    <vuln_soft>
      <prod name="rt-ac1200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
      <prod name="rt-ac3100_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac3200_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac51u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac52u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.4180" prev="1"/>
      </prod>
      <prod name="rt-ac5300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac53_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9883" prev="1"/>
      </prod>
      <prod name="rt-ac55u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-ac56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac58u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7485" prev="1"/>
      </prod>
      <prod name="rt-ac66u_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac68u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-ac88u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n12+_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12d1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n12hp_b1_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3479" prev="1"/>
      </prod>
      <prod name="rt-n12hp_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.2943" prev="1"/>
      </prod>
      <prod name="rt-n16_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n18u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt-n300_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt-n56u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.378.7177" prev="1"/>
      </prod>
      <prod name="rt-n66u_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7378" prev="1"/>
      </prod>
      <prod name="rt_ac1200g_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.3167" prev="1"/>
      </prod>
      <prod name="rt_ac1200gu_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.5577" prev="1"/>
      </prod>
      <prod name="rt_ac1900p_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.7743" prev="1"/>
      </prod>
      <prod name="rt_n12+_pro_firmware" vendor="asuswrt-merlin_project">
        <vers num="3.0.0.4.380.9880" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11421" seq="2017-11421" published="2017-07-18" modified="2017-07-26" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html" adv="1">http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99922">99922</ref>
      <ref source="MISC" url="https://bugs.debian.org/868705" adv="1">https://bugs.debian.org/868705</ref>
      <ref source="MISC" url="https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5" adv="1" patch="1">https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome-exe-thumbnailer" vendor="gnome-exe-thumbnailer_project">
        <vers num="0.9.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11422" seq="2017-11422" published="2017-07-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://gist.github.com/rambo691/3714c8c09cf894d574d37c294711c49e" adv="1">https://gist.github.com/rambo691/3714c8c09cf894d574d37c294711c49e</ref>
    </refs>
    <vuln_soft>
      <prod name="framework_cms" vendor="statamic">
        <vers num="2.5.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11423" seq="2017-11423" published="2017-07-18" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3946">DSA-3946</ref>
      <ref source="MISC" url="https://bugzilla.clamav.net/show_bug.cgi?id=11873">https://bugzilla.clamav.net/show_bug.cgi?id=11873</ref>
      <ref source="MISC" url="https://github.com/hackerlib/hackerlib-vul/tree/master/clamav-vul" adv="1">https://github.com/hackerlib/hackerlib-vul/tree/master/clamav-vul</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/02/msg00014.html">[debian-lts-announce] 20180212 [SECURITY] [DLA 1279-1] clamav security update</ref>
      <ref source="GENTOO" url="https://security.gentoo.org/glsa/201804-16">GLSA-201804-16</ref>
    </refs>
    <vuln_soft>
      <prod name="libmspack" vendor="libmspack_project">
        <vers num="0.5" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11424" seq="2017-11424" published="2017-08-24" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA PUBLIC KEY-----` which is not accounted for. This enables symmetric/asymmetric key confusion attacks against users using the PKCS1 PEM encoded public keys, which would allow an attacker to craft JWTs from scratch.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3979" adv="1">DSA-3979</ref>
      <ref source="CONFIRM" url="https://github.com/jpadilla/pyjwt/pull/277" adv="1" patch="1">https://github.com/jpadilla/pyjwt/pull/277</ref>
    </refs>
    <vuln_soft>
      <prod name="pyjwt" vendor="pyjwt_project">
        <vers num="1.5.0" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11427" seq="2017-11427" published="2019-04-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations" adv="1">https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations</ref>
      <ref source="MISC" url="https://www.kb.cert.org/vuls/id/475445" adv="1">https://www.kb.cert.org/vuls/id/475445</ref>
    </refs>
    <vuln_soft>
      <prod name="pythonsaml" vendor="onelogin">
        <vers num="2.3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11428" seq="2017-11428" published="2019-04-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations" adv="1">https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations</ref>
      <ref source="MISC" url="https://www.kb.cert.org/vuls/id/475445" adv="1">https://www.kb.cert.org/vuls/id/475445</ref>
    </refs>
    <vuln_soft>
      <prod name="ruby-saml" vendor="onelogin">
        <vers num="1.6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11429" seq="2017-11429" published="2019-04-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations" adv="1">https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations</ref>
      <ref source="MISC" url="https://www.kb.cert.org/vuls/id/475445" adv="1">https://www.kb.cert.org/vuls/id/475445</ref>
    </refs>
    <vuln_soft>
      <prod name="saml2-js" vendor="clever">
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1143" seq="2017-1143" published="2017-03-27" modified="2017-03-31" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21998874" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21998874</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97079" adv="1">97079</ref>
    </refs>
    <vuln_soft>
      <prod name="kenexa_lcms_premier" vendor="ibm">
        <vers num="9.1"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.3"/>
        <vers num="9.4"/>
        <vers num="9.5"/>
        <vers num="10.0"/>
        <vers num="10.2"/>
        <vers num="10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11430" seq="2017-11430" published="2019-04-17" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations" adv="1">https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations</ref>
      <ref source="MISC" url="https://www.kb.cert.org/vuls/id/475445" adv="1">https://www.kb.cert.org/vuls/id/475445</ref>
    </refs>
    <vuln_soft>
      <prod name="omnitauth-saml" vendor="omnitauth-saml_project">
        <vers num="1.9.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11434" seq="2017-11434" published="2017-07-25" modified="2018-09-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2017/dsa-3925">DSA-3925</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2017/07/19/2" adv="1" patch="1">[oss-security] 20170719 CVE-2017-11434 Qemu: slirp: out-of-bounds read while parsing dhcp options</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99923" adv="1">99923</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1472611" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1472611</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html">[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update</ref>
      <ref source="MLIST" url="https://lists.gnu.org/archive/html/qemu-devel/2017-07/msg05001.html" adv="1" patch="1">[qemu-devel] 20170717 [PATCH] slirp: check len against dhcp options array end</ref>
    </refs>
    <vuln_soft>
      <prod name="qemu" vendor="qemu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11435" seq="2017-11435" published="2017-07-19" modified="2017-07-25" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://hackertor.com/2017/07/19/na-cve-2017-11435-the-humax-wi-fi-router-model-hg100r-2-0-6-is/" adv="1">https://hackertor.com/2017/07/19/na-cve-2017-11435-the-humax-wi-fi-router-model-hg100r-2-0-6-is/</ref>
    </refs>
    <vuln_soft>
      <prod name="hg100r_firmware" vendor="humax">
        <vers num="2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11436" seq="2017-11436" published="2017-07-19" modified="2017-08-15" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_RELEASE_NOTES_20.12PTB04.pdf" adv="1">ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_RELEASE_NOTES_20.12PTB04.pdf</ref>
      <ref source="MISC" url="http://www.rootlabs.com.br/backdoor-dlink-dir-615/" adv="1">http://www.rootlabs.com.br/backdoor-dlink-dir-615/</ref>
    </refs>
    <vuln_soft>
      <prod name="dir-615" vendor="dlink">
        <vers num="20.12ptb01" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11437" seq="2017-11437" published="2017-08-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/" adv="1">https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="8.5.0" edition=":~~enterprise~~~"/>
        <vers num="8.5.1" edition=":~~enterprise~~~"/>
        <vers num="8.5.2" edition=":~~enterprise~~~"/>
        <vers num="8.5.3" edition=":~~enterprise~~~"/>
        <vers num="8.5.4" edition=":~~enterprise~~~"/>
        <vers num="8.5.5" edition=":~~enterprise~~~"/>
        <vers num="8.5.6" edition=":~~enterprise~~~"/>
        <vers num="8.5.7" edition=":~~enterprise~~~"/>
        <vers num="8.5.8" edition=":~~enterprise~~~"/>
        <vers num="8.5.9" edition=":~~enterprise~~~"/>
        <vers num="8.5.10" edition=":~~enterprise~~~"/>
        <vers num="8.5.11" edition=":~~enterprise~~~"/>
        <vers num="8.5.12" edition=":~~enterprise~~~"/>
        <vers num="8.5.13" edition=":~~enterprise~~~"/>
        <vers num="8.6.0" edition=":~~enterprise~~~"/>
        <vers num="8.6.1" edition=":~~enterprise~~~"/>
        <vers num="8.6.2" edition=":~~enterprise~~~"/>
        <vers num="8.6.3" edition=":~~enterprise~~~"/>
        <vers num="8.6.4" edition=":~~enterprise~~~"/>
        <vers num="8.6.5" edition=":~~enterprise~~~"/>
        <vers num="8.6.6" edition=":~~enterprise~~~"/>
        <vers num="8.6.7" edition=":~~enterprise~~~"/>
        <vers num="8.6.8" edition=":~~enterprise~~~"/>
        <vers num="8.6.9" edition=":~~enterprise~~~"/>
        <vers num="8.7.0" edition=":~~enterprise~~~"/>
        <vers num="8.7.1" edition=":~~enterprise~~~"/>
        <vers num="8.7.2" edition=":~~enterprise~~~"/>
        <vers num="8.7.3" edition=":~~enterprise~~~"/>
        <vers num="8.7.4" edition=":~~enterprise~~~"/>
        <vers num="8.7.5" edition=":~~enterprise~~~"/>
        <vers num="8.7.6" edition=":~~enterprise~~~"/>
        <vers num="8.7.7" edition=":~~enterprise~~~"/>
        <vers num="8.7.8" edition=":~~enterprise~~~"/>
        <vers num="8.7.9" edition=":~~enterprise~~~"/>
        <vers num="8.8.0" edition=":~~enterprise~~~"/>
        <vers num="8.8.1" edition=":~~enterprise~~~"/>
        <vers num="8.8.2" edition=":~~enterprise~~~"/>
        <vers num="8.8.3" edition=":~~enterprise~~~"/>
        <vers num="8.8.4" edition=":~~enterprise~~~"/>
        <vers num="8.8.5" edition=":~~enterprise~~~"/>
        <vers num="8.8.6" edition=":~~enterprise~~~"/>
        <vers num="8.8.7" edition=":~~enterprise~~~"/>
        <vers num="8.8.8" edition=":~~enterprise~~~"/>
        <vers num="8.8.9" edition=":~~enterprise~~~"/>
        <vers num="8.9.0" edition=":~~enterprise~~~"/>
        <vers num="8.9.1" edition=":~~enterprise~~~"/>
        <vers num="8.9.2" edition=":~~enterprise~~~"/>
        <vers num="8.9.3" edition=":~~enterprise~~~"/>
        <vers num="8.9.4" edition=":~~enterprise~~~"/>
        <vers num="8.9.5" edition=":~~enterprise~~~"/>
        <vers num="8.9.6" edition=":~~enterprise~~~"/>
        <vers num="8.9.7" edition=":~~enterprise~~~"/>
        <vers num="8.9.10" edition=":~~enterprise~~~"/>
        <vers num="8.9.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.0" edition=":~~enterprise~~~"/>
        <vers num="8.10.1" edition=":~~enterprise~~~"/>
        <vers num="8.10.2" edition=":~~enterprise~~~"/>
        <vers num="8.10.3" edition=":~~enterprise~~~"/>
        <vers num="8.10.4" edition=":~~enterprise~~~"/>
        <vers num="8.10.5" edition=":~~enterprise~~~"/>
        <vers num="8.10.6" edition=":~~enterprise~~~"/>
        <vers num="8.10.7" edition=":~~enterprise~~~"/>
        <vers num="8.10.8" edition=":~~enterprise~~~"/>
        <vers num="8.10.9" edition=":~~enterprise~~~"/>
        <vers num="8.10.10" edition=":~~enterprise~~~"/>
        <vers num="8.10.11" edition=":~~enterprise~~~"/>
        <vers num="8.10.12" edition=":~~enterprise~~~"/>
        <vers num="8.10.13" edition=":~~enterprise~~~"/>
        <vers num="8.11.0" edition=":~~enterprise~~~"/>
        <vers num="8.11.1" edition=":~~enterprise~~~"/>
        <vers num="8.11.2" edition=":~~enterprise~~~"/>
        <vers num="8.11.3" edition=":~~enterprise~~~"/>
        <vers num="8.11.4" edition=":~~enterprise~~~"/>
        <vers num="8.11.5" edition=":~~enterprise~~~"/>
        <vers num="8.11.6" edition=":~~enterprise~~~"/>
        <vers num="8.11.7" edition=":~~enterprise~~~"/>
        <vers num="8.11.8" edition=":~~enterprise~~~"/>
        <vers num="8.11.9" edition=":~~enterprise~~~"/>
        <vers num="8.11.10" edition=":~~enterprise~~~"/>
        <vers num="8.11.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.0" edition=":~~enterprise~~~"/>
        <vers num="8.12.1" edition=":~~enterprise~~~"/>
        <vers num="8.12.2" edition=":~~enterprise~~~"/>
        <vers num="8.12.3" edition=":~~enterprise~~~"/>
        <vers num="8.12.4" edition=":~~enterprise~~~"/>
        <vers num="8.12.5" edition=":~~enterprise~~~"/>
        <vers num="8.12.6" edition=":~~enterprise~~~"/>
        <vers num="8.12.7" edition=":~~enterprise~~~"/>
        <vers num="8.12.8" edition=":~~enterprise~~~"/>
        <vers num="8.12.9" edition=":~~enterprise~~~"/>
        <vers num="8.12.10" edition=":~~enterprise~~~"/>
        <vers num="8.12.11" edition=":~~enterprise~~~"/>
        <vers num="8.12.12" edition=":~~enterprise~~~"/>
        <vers num="8.13.0" edition=":~~enterprise~~~"/>
        <vers num="8.13.1" edition=":~~enterprise~~~"/>
        <vers num="8.13.2" edition=":~~enterprise~~~"/>
        <vers num="8.13.3" edition=":~~enterprise~~~"/>
        <vers num="8.13.4" edition=":~~enterprise~~~"/>
        <vers num="8.13.5" edition=":~~enterprise~~~"/>
        <vers num="8.13.6" edition=":~~enterprise~~~"/>
        <vers num="8.13.7" edition=":~~enterprise~~~"/>
        <vers num="8.13.8" edition=":~~enterprise~~~"/>
        <vers num="8.13.9" edition=":~~enterprise~~~"/>
        <vers num="8.13.10" edition=":~~enterprise~~~"/>
        <vers num="8.13.11" edition=":~~enterprise~~~"/>
        <vers num="8.14.0" edition=":~~enterprise~~~"/>
        <vers num="8.14.1" edition=":~~enterprise~~~"/>
        <vers num="8.14.2" edition=":~~enterprise~~~"/>
        <vers num="8.14.3" edition=":~~enterprise~~~"/>
        <vers num="8.14.4" edition=":~~enterprise~~~"/>
        <vers num="8.14.5" edition=":~~enterprise~~~"/>
        <vers num="8.14.6" edition=":~~enterprise~~~"/>
        <vers num="8.14.8" edition=":~~enterprise~~~"/>
        <vers num="8.14.9" edition=":~~enterprise~~~"/>
        <vers num="8.14.10" edition=":~~enterprise~~~"/>
        <vers num="8.15.0" edition=":~~enterprise~~~"/>
        <vers num="8.15.1" edition=":~~enterprise~~~"/>
        <vers num="8.15.2" edition=":~~enterprise~~~"/>
        <vers num="8.15.3" edition=":~~enterprise~~~"/>
        <vers num="8.15.4" edition=":~~enterprise~~~"/>
        <vers num="8.15.6" edition=":~~enterprise~~~"/>
        <vers num="8.15.7" edition=":~~enterprise~~~"/>
        <vers num="8.15.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.0" edition=":~~enterprise~~~"/>
        <vers num="8.16.1" edition=":~~enterprise~~~"/>
        <vers num="8.16.2" edition=":~~enterprise~~~"/>
        <vers num="8.16.3" edition=":~~enterprise~~~"/>
        <vers num="8.16.4" edition=":~~enterprise~~~"/>
        <vers num="8.16.5" edition=":~~enterprise~~~"/>
        <vers num="8.16.6" edition=":~~enterprise~~~"/>
        <vers num="8.16.7" edition=":~~enterprise~~~"/>
        <vers num="8.16.8" edition=":~~enterprise~~~"/>
        <vers num="8.16.9" edition=":~~enterprise~~~"/>
        <vers num="8.17.0" edition=":~~enterprise~~~"/>
        <vers num="8.17.1" edition=":~~enterprise~~~"/>
        <vers num="8.17.2" edition=":~~enterprise~~~"/>
        <vers num="8.17.3" edition=":~~enterprise~~~"/>
        <vers num="8.17.4" edition=":~~enterprise~~~"/>
        <vers num="8.17.5" edition=":~~enterprise~~~"/>
        <vers num="8.17.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
        <vers num="9.3.0" edition=":~~enterprise~~~"/>
        <vers num="9.3.1" edition=":~~enterprise~~~"/>
        <vers num="9.3.2" edition=":~~enterprise~~~"/>
        <vers num="9.3.3" edition=":~~enterprise~~~"/>
        <vers num="9.3.4" edition=":~~enterprise~~~"/>
        <vers num="9.3.5" edition=":~~enterprise~~~"/>
        <vers num="9.3.6" edition=":~~enterprise~~~"/>
        <vers num="9.3.7" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11438" seq="2017-11438" published="2017-08-02" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/" adv="1">https://about.gitlab.com/2017/07/19/gitlab-9-dot-3-dot-8-released/</ref>
    </refs>
    <vuln_soft>
      <prod name="gitlab" vendor="gitlab">
        <vers num="9.0.0" edition=":~~community~~~"/>
        <vers num="9.0.0" edition=":~~enterprise~~~"/>
        <vers num="9.0.1" edition=":~~community~~~"/>
        <vers num="9.0.1" edition=":~~enterprise~~~"/>
        <vers num="9.0.2" edition=":~~community~~~"/>
        <vers num="9.0.2" edition=":~~enterprise~~~"/>
        <vers num="9.0.3" edition=":~~community~~~"/>
        <vers num="9.0.3" edition=":~~enterprise~~~"/>
        <vers num="9.0.4" edition=":~~community~~~"/>
        <vers num="9.0.4" edition=":~~enterprise~~~"/>
        <vers num="9.0.5" edition=":~~community~~~"/>
        <vers num="9.0.5" edition=":~~enterprise~~~"/>
        <vers num="9.0.6" edition=":~~community~~~"/>
        <vers num="9.0.6" edition=":~~enterprise~~~"/>
        <vers num="9.0.7" edition=":~~community~~~"/>
        <vers num="9.0.7" edition=":~~enterprise~~~"/>
        <vers num="9.0.8" edition=":~~community~~~"/>
        <vers num="9.0.8" edition=":~~enterprise~~~"/>
        <vers num="9.0.9" edition=":~~community~~~"/>
        <vers num="9.0.9" edition=":~~enterprise~~~"/>
        <vers num="9.0.10" edition=":~~community~~~"/>
        <vers num="9.0.10" edition=":~~enterprise~~~"/>
        <vers num="9.1.0" edition=":~~community~~~"/>
        <vers num="9.1.0" edition=":~~enterprise~~~"/>
        <vers num="9.1.1" edition=":~~community~~~"/>
        <vers num="9.1.1" edition=":~~enterprise~~~"/>
        <vers num="9.1.2" edition=":~~community~~~"/>
        <vers num="9.1.2" edition=":~~enterprise~~~"/>
        <vers num="9.1.3" edition=":~~community~~~"/>
        <vers num="9.1.3" edition=":~~enterprise~~~"/>
        <vers num="9.1.4" edition=":~~community~~~"/>
        <vers num="9.1.4" edition=":~~enterprise~~~"/>
        <vers num="9.1.5" edition=":~~community~~~"/>
        <vers num="9.1.5" edition=":~~enterprise~~~"/>
        <vers num="9.1.6" edition=":~~community~~~"/>
        <vers num="9.1.6" edition=":~~enterprise~~~"/>
        <vers num="9.1.7" edition=":~~community~~~"/>
        <vers num="9.1.7" edition=":~~enterprise~~~"/>
        <vers num="9.2.0" edition=":~~community~~~"/>
        <vers num="9.2.0" edition=":~~enterprise~~~"/>
        <vers num="9.2.1" edition=":~~community~~~"/>
        <vers num="9.2.1" edition=":~~enterprise~~~"/>
        <vers num="9.2.2" edition=":~~community~~~"/>
        <vers num="9.2.2" edition=":~~enterprise~~~"/>
        <vers num="9.2.3" edition=":~~community~~~"/>
        <vers num="9.2.3" edition=":~~enterprise~~~"/>
        <vers num="9.2.4" edition=":~~community~~~"/>
        <vers num="9.2.4" edition=":~~enterprise~~~"/>
        <vers num="9.2.5" edition=":~~community~~~"/>
        <vers num="9.2.5" edition=":~~enterprise~~~"/>
        <vers num="9.2.6" edition=":~~community~~~"/>
        <vers num="9.2.6" edition=":~~enterprise~~~"/>
        <vers num="9.2.7" edition=":~~community~~~"/>
        <vers num="9.2.7" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11439" seq="2017-11439" published="2017-07-19" modified="2017-07-21" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143357/Sitecore-CMS-8.2-Cross-Site-Scripting-File-Disclosure.html" adv="1">https://packetstormsecurity.com/files/143357/Sitecore-CMS-8.2-Cross-Site-Scripting-File-Disclosure.html</ref>
      <ref source="MISC" url="https://xc0re.net/2017/07/03/sitecore-cms-v-8-2-multiple-vulnerabilties/" adv="1">https://xc0re.net/2017/07/03/sitecore-cms-v-8-2-multiple-vulnerabilties/</ref>
    </refs>
    <vuln_soft>
      <prod name="cms" vendor="sitecore">
        <vers num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1144" seq="2017-1144" published="2017-07-05" modified="2017-07-18" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg22005383" adv="1">http://www.ibm.com/support/docview.wss?uid=swg22005383</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99365" adv="1">99365</ref>
      <ref source="MISC" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/122033" adv="1">https://exchange.xforce.ibmcloud.com/vulnerabilities/122033</ref>
    </refs>
    <vuln_soft>
      <prod name="integration_bus" vendor="ibm">
        <vers num="9.0"/>
        <vers num="9.0.0.1"/>
        <vers num="9.0.0.2"/>
        <vers num="9.0.0.3"/>
        <vers num="9.0.0.4"/>
        <vers num="9.0.0.5"/>
        <vers num="9.0.0.6"/>
        <vers num="9.0.0.7"/>
        <vers num="10.0"/>
        <vers num="10.0.0.1"/>
        <vers num="10.0.0.2"/>
        <vers num="10.0.0.3"/>
        <vers num="10.0.0.4"/>
        <vers num="10.0.0.5"/>
        <vers num="10.0.0.6"/>
        <vers num="10.0.0.7"/>
      </prod>
      <prod name="websphere_message_broker" vendor="ibm">
        <vers num="8.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.0.0.6"/>
        <vers num="8.0.0.7"/>
        <vers num="8.0.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11440" seq="2017-11440" published="2017-07-19" modified="2017-07-21" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://packetstormsecurity.com/files/143357/Sitecore-CMS-8.2-Cross-Site-Scripting-File-Disclosure.html" adv="1">https://packetstormsecurity.com/files/143357/Sitecore-CMS-8.2-Cross-Site-Scripting-File-Disclosure.html</ref>
      <ref source="MISC" url="https://xc0re.net/2017/07/03/sitecore-cms-v-8-2-multiple-vulnerabilties/" adv="1">https://xc0re.net/2017/07/03/sitecore-cms-v-8-2-multiple-vulnerabilties/</ref>
    </refs>
    <vuln_soft>
      <prod name="cms" vendor="sitecore">
        <vers num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11441" seq="2017-11441" published="2017-07-19" modified="2017-08-15" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://news.cpanel.com/cpanel-tsr-2017-0004-full-disclosure/" adv="1">https://news.cpanel.com/cpanel-tsr-2017-0004-full-disclosure/</ref>
    </refs>
    <vuln_soft>
      <prod name="whm" vendor="cpanel">
        <vers num="56.0.50" prev="1"/>
        <vers num="58.0.3"/>
        <vers num="58.0.4"/>
        <vers num="58.0.5"/>
        <vers num="58.0.6"/>
        <vers num="58.0.7"/>
        <vers num="58.0.8"/>
        <vers num="58.0.11"/>
        <vers num="58.0.12"/>
        <vers num="58.0.13"/>
        <vers num="58.0.17"/>
        <vers num="58.0.19"/>
        <vers num="58.0.20"/>
        <vers num="58.0.23"/>
        <vers num="58.0.24"/>
        <vers num="58.0.25"/>
        <vers num="58.0.26"/>
        <vers num="58.0.27"/>
        <vers num="58.0.28"/>
        <vers num="58.0.29"/>
        <vers num="58.0.30"/>
        <vers num="58.0.31"/>
        <vers num="58.0.32"/>
        <vers num="58.0.34"/>
        <vers num="58.0.36"/>
        <vers num="58.0.37"/>
        <vers num="58.0.41"/>
        <vers num="58.0.43"/>
        <vers num="58.0.44"/>
        <vers num="58.0.45"/>
        <vers num="58.0.46"/>
        <vers num="58.0.47"/>
        <vers num="58.0.48"/>
        <vers num="58.0.49"/>
        <vers num="58.0.50"/>
        <vers num="58.0.51"/>
        <vers num="60.0.3"/>
        <vers num="60.0.4"/>
        <vers num="60.0.5"/>
        <vers num="60.0.6"/>
        <vers num="60.0.8"/>
        <vers num="60.0.9"/>
        <vers num="60.0.10"/>
        <vers num="60.0.11"/>
        <vers num="60.0.12"/>
        <vers num="60.0.13"/>
        <vers num="60.0.14"/>
        <vers num="60.0.15"/>
        <vers num="60.0.17"/>
        <vers num="60.0.18"/>
        <vers num="60.0.19"/>
        <vers num="60.0.22"/>
        <vers num="60.0.24"/>
        <vers num="60.0.25"/>
        <vers num="60.0.26"/>
        <vers num="60.0.27"/>
        <vers num="60.0.28"/>
        <vers num="60.0.31"/>
        <vers num="60.0.32"/>
        <vers num="60.0.34"/>
        <vers num="60.0.35"/>
        <vers num="60.0.36"/>
        <vers num="60.0.37"/>
        <vers num="60.0.38"/>
        <vers num="60.0.39"/>
        <vers num="60.0.42"/>
        <vers num="60.0.43"/>
        <vers num="60.0.44"/>
        <vers num="62.0.1"/>
        <vers num="62.0.2"/>
        <vers num="62.0.4"/>
        <vers num="62.0.5"/>
        <vers num="62.0.6"/>
        <vers num="62.0.7"/>
        <vers num="62.0.8"/>
        <vers num="62.0.9"/>
        <vers num="62.0.10"/>
        <vers num="62.0.11"/>
        <vers num="62.0.12"/>
        <vers num="62.0.14"/>
        <vers num="62.0.15"/>
        <vers num="62.0.16"/>
        <vers num="62.0.17"/>
        <vers num="62.0.19"/>
        <vers num="62.0.20"/>
        <vers num="62.0.23"/>
        <vers num="62.0.24"/>
        <vers num="62.0.26"/>
        <vers num="64.0.0"/>
        <vers num="64.0.1"/>
        <vers num="64.0.2"/>
        <vers num="64.0.3"/>
        <vers num="64.0.4"/>
        <vers num="64.0.7"/>
        <vers num="64.0.9"/>
        <vers num="64.0.11"/>
        <vers num="64.0.12"/>
        <vers num="64.0.13"/>
        <vers num="64.0.14"/>
        <vers num="64.0.15"/>
        <vers num="64.0.17"/>
        <vers num="64.0.18"/>
        <vers num="64.0.19"/>
        <vers num="64.0.20"/>
        <vers num="64.0.21"/>
        <vers num="64.0.22"/>
        <vers num="64.0.24"/>
        <vers num="64.0.27"/>
        <vers num="64.0.28"/>
        <vers num="64.0.29"/>
        <vers num="64.0.30"/>
        <vers num="64.0.31"/>
        <vers num="64.0.32"/>
        <vers num="66.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11444" seq="2017-11444" published="2017-07-19" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/intelliants/subrion/issues/479" adv="1">https://github.com/intelliants/subrion/issues/479</ref>
    </refs>
    <vuln_soft>
      <prod name="subrion_cms" vendor="intelliants">
        <vers num="4.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11445" seq="2017-11445" published="2017-07-19" modified="2017-07-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://github.com/intelliants/subrion/issues/480" adv="1">https://github.com/intelliants/subrion/issues/480</ref>
    </refs>
    <vuln_soft>
      <prod name="subrion_cms" vendor="intelliants">
        <vers num="4.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11446" seq="2017-11446" published="2017-07-19" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99964">99964</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/537" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/537</ref>
      <ref source="MLIST" url="https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html">[debian-lts-announce] 20190514 [SECURITY] [DLA 1785-1] imagemagick security update</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2017/dsa-4019">DSA-4019</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11447" seq="2017-11447" published="2017-07-19" modified="2019-10-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99948">99948</ref>
      <ref source="CONFIRM" url="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867897" adv="1" patch="1">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867897</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/8c10b9247509c0484b55330458846115131ec2ae" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/8c10b9247509c0484b55330458846115131ec2ae</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/556" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/556</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11448" seq="2017-11448" published="2017-07-19" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867893" adv="1" patch="1">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867893</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/1737ac82b335e53376382c07b9a500d73dd2aa11" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/1737ac82b335e53376382c07b9a500d73dd2aa11</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/556" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/556</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11449" seq="2017-11449" published="2017-07-19" modified="2017-07-27" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99958">99958</ref>
      <ref source="CONFIRM" url="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867896" adv="1" patch="1">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867896</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/529ff26b68febb2ac03062c58452ea0b4c6edbc1" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/529ff26b68febb2ac03062c58452ea0b4c6edbc1</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/b007dd3a048097d8f58949297f5b434612e1e1a3" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/b007dd3a048097d8f58949297f5b434612e1e1a3</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/556" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/556</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1145" seq="2017-1145" published="2017-03-20" modified="2019-10-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">IBM WebSphere MQ 8.0.0.6 does not properly terminate channel agents when they are no longer needed, which could allow a user to cause a denial of service through resource exhaustion. IBM Reference #: 1999672.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999672" adv="1" patch="1">http://www.ibm.com/support/docview.wss?uid=swg21999672</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96759" adv="1">96759</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1038068">1038068</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_mq" vendor="ibm">
        <vers num="8.0.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11450" seq="2017-11450" published="2017-07-19" modified="2017-07-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867894" adv="1" patch="1">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867894</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/commit/948356eec65aea91995d4b7cc487d197d2c5f602" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/commit/948356eec65aea91995d4b7cc487d197d2c5f602</ref>
      <ref source="CONFIRM" url="https://github.com/ImageMagick/ImageMagick/issues/556" adv="1" patch="1">https://github.com/ImageMagick/ImageMagick/issues/556</ref>
      <ref source="CONFIRM" url="https://security-tracker.debian.org/tracker/CVE-2017-11450" adv="1" patch="1">https://security-tracker.debian.org/tracker/CVE-2017-11450</ref>
    </refs>
    <vuln_soft>
      <prod name="imagemagick" vendor="imagemagick">
        <vers num="7.0.6-0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11455" seq="2017-11455" published="2017-08-29" modified="2017-09-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/100530" adv="1">100530</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1039242" adv="1">1039242</ref>
      <ref source="CONFIRM" url="https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40793" adv="1">https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40793</ref>
    </refs>
    <vuln_soft>
      <prod name="pulse_connect_secure" vendor="pulsesecure">
        <vers num="8.1r1.0"/>
        <vers num="8.1r1.1"/>
        <vers num="8.1r2.0"/>
        <vers num="8.1r3.0"/>
        <vers num="8.1r3.1"/>
        <vers num="8.1r3.2"/>
        <vers num="8.1r4.0"/>
        <vers num="8.1r4.1"/>
        <vers num="8.1r5.0"/>
        <vers num="8.1r6.0"/>
        <vers num="8.1r7.0"/>
        <vers num="8.1r8.0"/>
        <vers num="8.1r9.0"/>
        <vers num="8.1r9.1"/>
        <vers num="8.1r9.2"/>
        <vers num="8.1r10.0"/>
        <vers num="8.2r1.0"/>
        <vers num="8.2r1.1"/>
        <vers num="8.2r2.0"/>
        <vers num="8.2r3.0"/>
        <vers num="8.2r3.1"/>
        <vers num="8.2r4.0"/>
        <vers num="8.2r4.1"/>
        <vers num="8.2r5.0"/>
      </prod>
      <prod name="pulse_policy_secure" vendor="pulsesecure">
        <vers num="5.1r1.0"/>
        <vers num="5.1r1.1"/>
        <vers num="5.1r2.0"/>
        <vers num="5.1r2.1"/>
        <vers num="5.1r3.0"/>
        <vers num="5.1r3.2"/>
        <vers num="5.1r4.0"/>
        <vers num="5.1r5.0"/>
        <vers num="5.1r6.0"/>
        <vers num="5.1r7.0"/>
        <vers num="5.1r7.1"/>
        <vers num="5.1r8.0"/>
        <vers num="5.1r9.1"/>
        <vers num="5.1r10"/>
        <vers num="5.2r1.0"/>
        <vers num="5.2r2.0"/>
        <vers num="5.2r3.0"/>
        <vers num="5.2r3.2"/>
        <vers num="5.2r4.0"/>
        <vers num="5.2r5.0"/>
        <vers num="5.2r6.0"/>
        <vers num="5.2r7.0"/>
        <vers num="5.2r7.1"/>
        <vers num="5.2r8.0"/>
        <vers num="5.3r1.0"/>
        <vers num="5.3r1.1"/>
        <vers num="5.3r2.0"/>
        <vers num="5.3r3.0"/>
        <vers num="5.3r3.1"/>
        <vers num="5.3r4.0"/>
        <vers num="5.3r4.1"/>
        <vers num="5.3r5.0"/>
        <vers num="5.3r5.1"/>
        <vers num="5.3r5.2"/>
        <vers num="5.3r6.0"/>
        <vers num="5.3r7.0"/>
        <vers num="5.3r8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11456" seq="2017-11456" published="2017-07-19" modified="2017-07-25" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://blogs.securiteam.com/index.php/archives/3317#more-3317">https://blogs.securiteam.com/index.php/archives/3317#more-3317</ref>
    </refs>
    <vuln_soft>
      <prod name="gwr202_gprs_router_firmware" vendor="geneko">
        <vers num="-"/>
      </prod>
      <prod name="gwr252_edge_router_firmware" vendor="geneko">
        <vers num="-"/>
      </prod>
      <prod name="gwr352_3g_router_firmware" vendor="geneko">
        <vers num="-"/>
      </prod>
      <prod name="gwr352wv_wide_voltage_3g_router_firmware" vendor="geneko">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11457" seq="2017-11457" published="2017-07-25" modified="2018-12-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97572">97572</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-018-sap-netweaver-java-7-5-xxe-com-sap-km-cm-ice/">https://erpscan.io/advisories/erpscan-17-018-sap-netweaver-java-7-5-xxe-com-sap-km-cm-ice/</ref>
    </refs>
    <vuln_soft>
      <prod name="netweaver" vendor="sap">
        <vers num="7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11458" seq="2017-11458" published="2017-07-25" modified="2018-12-10" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/97566">97566</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-017-sap-netweaver-java-7-3-java-xss-ctcprotocolprotocol-servlet/">https://erpscan.io/advisories/erpscan-17-017-sap-netweaver-java-7-3-java-xss-ctcprotocolprotocol-servlet/</ref>
    </refs>
    <vuln_soft>
      <prod name="netweaver" vendor="sap">
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11459" seq="2017-11459" published="2017-07-25" modified="2018-12-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-019-sap-trex-rce/">https://erpscan.io/advisories/erpscan-17-019-sap-trex-rce/</ref>
    </refs>
    <vuln_soft>
      <prod name="trex" vendor="sap">
        <vers num="7.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-1146" seq="2017-1146" published="2017-03-20" modified="2017-03-23" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999736.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ibm.com/support/docview.wss?uid=swg21999736" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21999736</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/96761" adv="1">96761</ref>
    </refs>
    <vuln_soft>
      <prod name="content_navigator" vendor="ibm">
        <vers num="2.0.3"/>
        <vers num="3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11460" seq="2017-11460" published="2017-07-25" modified="2018-12-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101826">101826</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/97565" adv="1">97565</ref>
      <ref source="MISC" url="https://erpscan.io/advisories/erpscan-17-016-sap-netweaver-java-7-4-dataarchivingservice-servlet-xss/">https://erpscan.io/advisories/erpscan-17-016-sap-netweaver-java-7-4-dataarchivingservice-servlet-xss/</ref>
    </refs>
    <vuln_soft>
      <prod name="netweaver_portal" vendor="sap">
        <vers num="7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11461" seq="2017-11461" published="2017-11-09" modified="2017-11-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or "UI redress attack" which could be used to cause a user to perform an unintended action in the user interface.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/101778" adv="1">101778</ref>
      <ref source="CONFIRM" url="https://security.netapp.com/advisory/ntap-20171107-0001/" adv="1">https://security.netapp.com/advisory/ntap-20171107-0001/</ref>
    </refs>
    <vuln_soft>
      <prod name="oncommand_unified_manager" vendor="netapp">
        <vers num="-" edition=":~~~vsphere~~"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11462" seq="2017-11462" published="2017-09-13" modified="2017-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://krbdev.mit.edu/rt/Ticket/Display.html?id=8598" adv="1">http://krbdev.mit.edu/rt/Ticket/Display.html?id=8598</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=1488873" adv="1" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=1488873</ref>
      <ref source="CONFIRM" url="https://github.com/krb5/krb5/commit/56f7b1bc95a2a3eeb420e069e7655fb181ade5cf" adv="1" patch="1">https://github.com/krb5/krb5/commit/56f7b1bc95a2a3eeb420e069e7655fb181ade5cf</ref>
      <ref source="FEDORA" url="https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2FPRUP4YVOEBGEROUYWZFEQ64HTMGNED/" adv="1">FEDORA-2017-10c74147f9</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.14" edition="alpha1"/>
        <vers num="5-1.14" edition="beta1"/>
        <vers num="5-1.14" edition="beta2"/>
        <vers num="5-1.14.1"/>
        <vers num="5-1.14.2"/>
        <vers num="5-1.14.3"/>
        <vers num="5-1.14.4"/>
        <vers num="5-1.14.5"/>
        <vers num="5-1.15"/>
        <vers num="5-1.15.1" edition="beta1"/>
        <vers num="5-1.15.1" edition="beta2"/>
      </prod>
      <prod name="fedora" vendor="fedoraproject">
        <vers num="25"/>
        <vers num="26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11463" seq="2017-11463" published="2017-12-11" modified="2018-03-27" severity="Medium" CVSS_version="2.0" CVSS_score="6.5" CVSS_base_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="https://community.ivanti.com/docs/DOC-66252">https://community.ivanti.com/docs/DOC-66252</ref>
      <ref source="MISC" url="https://gist.github.com/lazyhack3r/439e92419c552b5dc82b2f5e832c8bfb" adv="1">https://gist.github.com/lazyhack3r/439e92419c552b5dc82b2f5e832c8bfb</ref>
    </refs>
    <vuln_soft>
      <prod name="endpoint_manager" vendor="ivanti">
        <vers num="2016.4"/>
        <vers num="2017.1"/>
        <vers num="2017.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11464" seq="2017-11464" published="2017-07-19" modified="2017-07-27" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/99956">99956</ref>
      <ref source="CONFIRM" url="https://bugzilla.gnome.org/show_bug.cgi?id=783835">https://bugzilla.gnome.org/show_bug.cgi?id=783835</ref>
      <ref source="CONFIRM" url="https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef2232511972a" adv="1" patch="1">https://git.gnome.org/browse/librsvg/commit/?id=ecf9267a24b2c3c0cd211dbdfa9ef2232511972a</ref>
      <ref source="CONFIRM" url="https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972a" adv="1" patch="1">https://github.com/GNOME/librsvg/commit/ecf9267a24b2c3c0cd211dbdfa9ef2232511972a</ref>
    </refs>
    <vuln_soft>
      <prod name="librsvg" vendor="gnome">
        <vers num="2.40.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2017-11465" seq="2017-11465" published="2017-07-19" modified="2017-07-25" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security rel