<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns:vrda="http://vrda.jpcert.or.jp/mod_vrda/" xml:lang="en" xmlns="http://www.w3.org/2005/Atom" xmlns:sec="http://jvn.jp/rss/mod_sec/">
  <id>http://vrda.jpcert.or.jp/feed/en/atom.xml</id>
  <title>VRDA Feed : Provides information for vulnerability impact analysis</title>
  <subtitle>VRDA (Vulnerability Response Decision Assistance) Feed provides well-formatted analysis information on vulnerabilities for helping to make response decisions. These analysis information are provided in the two different formats: HTML for easy viewing and XML for automated processing.</subtitle>
  <link href="http://vrda.jpcert.or.jp/feed/en/atom.xml" rel="self" type="application/atom+xml"/>
  <link href="http://vrda.jpcert.or.jp/feed/ja/atom.xml" rel="alternate" hreflang="ja" type="application/atom+xml"/>
  <updated>2011-12-31T20:16:11+09:00</updated>
  <author>
    <name>JPCERT Coordination Center</name>
    <email>kengine@jpcert.or.jp</email>
    <uri>http://www.jpcert.or.jp/</uri>
  </author>
  <vrda:entrycount>7246</vrda:entrycount>
  <vrda:startentryno>1</vrda:startentryno>
  <entry>
    <title>CVE-2011-5033:configserver_security_firewall: Stack-based buffer overflow in CFS.c in ConfigServe...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5033_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5033_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5033_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in CFS.c in ConfigServer Security &amp; Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5033_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.00"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.01"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.02"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.03"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.04"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.05"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.06"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.07"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.08"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.09"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.10"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.11"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.12"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.13"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.14"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.15"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.16"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.17"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.18"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.19"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.20"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.21"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.22"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.30"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.31"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.32"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.33"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.34"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.35"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.36"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.37"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.38"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.39"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.40"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.41"/>
    <category term="cpe:/a:configserver:configserver_security_firewall:5.42 and previous versions"/>
    <category term="cpe:/h:directadmin:directadmin_server"/>
    <sec:identifier>CVE-2011-5033</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4462:plone: Plone 4.1.3 and earlier computes hash values for fo...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4462_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4462_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4462_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4462_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:plone:plone:1.0"/>
    <category term="cpe:/a:plone:plone:1.0.1"/>
    <category term="cpe:/a:plone:plone:1.0.2"/>
    <category term="cpe:/a:plone:plone:1.0.3"/>
    <category term="cpe:/a:plone:plone:1.0.4"/>
    <category term="cpe:/a:plone:plone:1.0.5"/>
    <category term="cpe:/a:plone:plone:1.0.6"/>
    <category term="cpe:/a:plone:plone:2.0"/>
    <category term="cpe:/a:plone:plone:2.0.1"/>
    <category term="cpe:/a:plone:plone:2.0.2"/>
    <category term="cpe:/a:plone:plone:2.0.3"/>
    <category term="cpe:/a:plone:plone:2.0.4"/>
    <category term="cpe:/a:plone:plone:2.0.5"/>
    <category term="cpe:/a:plone:plone:2.1"/>
    <category term="cpe:/a:plone:plone:2.1.1"/>
    <category term="cpe:/a:plone:plone:2.1.2"/>
    <category term="cpe:/a:plone:plone:2.1.3"/>
    <category term="cpe:/a:plone:plone:2.1.4"/>
    <category term="cpe:/a:plone:plone:2.5"/>
    <category term="cpe:/a:plone:plone:2.5.1"/>
    <category term="cpe:/a:plone:plone:2.5.2"/>
    <category term="cpe:/a:plone:plone:2.5.3"/>
    <category term="cpe:/a:plone:plone:2.5.4"/>
    <category term="cpe:/a:plone:plone:2.5.5"/>
    <category term="cpe:/a:plone:plone:3.0"/>
    <category term="cpe:/a:plone:plone:3.0.1"/>
    <category term="cpe:/a:plone:plone:3.0.2"/>
    <category term="cpe:/a:plone:plone:3.0.3"/>
    <category term="cpe:/a:plone:plone:3.0.4"/>
    <category term="cpe:/a:plone:plone:3.0.5"/>
    <category term="cpe:/a:plone:plone:3.0.6"/>
    <category term="cpe:/a:plone:plone:3.1"/>
    <category term="cpe:/a:plone:plone:3.1.1"/>
    <category term="cpe:/a:plone:plone:3.1.2"/>
    <category term="cpe:/a:plone:plone:3.1.3"/>
    <category term="cpe:/a:plone:plone:3.1.4"/>
    <category term="cpe:/a:plone:plone:3.1.5.1"/>
    <category term="cpe:/a:plone:plone:3.1.6"/>
    <category term="cpe:/a:plone:plone:3.1.7"/>
    <category term="cpe:/a:plone:plone:3.2"/>
    <category term="cpe:/a:plone:plone:3.2.1"/>
    <category term="cpe:/a:plone:plone:3.2.2"/>
    <category term="cpe:/a:plone:plone:3.2.3"/>
    <category term="cpe:/a:plone:plone:3.3"/>
    <category term="cpe:/a:plone:plone:3.3.1"/>
    <category term="cpe:/a:plone:plone:3.3.2"/>
    <category term="cpe:/a:plone:plone:3.3.3"/>
    <category term="cpe:/a:plone:plone:3.3.4"/>
    <category term="cpe:/a:plone:plone:3.3.5"/>
    <category term="cpe:/a:plone:plone:3.3.6"/>
    <category term="cpe:/a:plone:plone:4.0"/>
    <category term="cpe:/a:plone:plone:4.0.1"/>
    <category term="cpe:/a:plone:plone:4.0.2"/>
    <category term="cpe:/a:plone:plone:4.0.3"/>
    <category term="cpe:/a:plone:plone:4.0.4"/>
    <category term="cpe:/a:plone:plone:4.0.5"/>
    <category term="cpe:/a:plone:plone:4.0.7"/>
    <category term="cpe:/a:plone:plone:4.0.9"/>
    <category term="cpe:/a:plone:plone:4.1"/>
    <category term="cpe:/a:plone:plone:4.1.1"/>
    <category term="cpe:/a:plone:plone:4.1.2"/>
    <category term="cpe:/a:plone:plone:4.1.3 and previous versions"/>
    <sec:identifier>CVE-2011-4462</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4885:php: PHP before 5.3.9 computes hash values for form para...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4885_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4885_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4885_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4885_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:php:php:5.0.0"/>
    <category term="cpe:/a:php:php:5.0.0:beta1"/>
    <category term="cpe:/a:php:php:5.0.0:beta2"/>
    <category term="cpe:/a:php:php:5.0.0:beta3"/>
    <category term="cpe:/a:php:php:5.0.0:beta4"/>
    <category term="cpe:/a:php:php:5.0.0:rc1"/>
    <category term="cpe:/a:php:php:5.0.0:rc2"/>
    <category term="cpe:/a:php:php:5.0.0:rc3"/>
    <category term="cpe:/a:php:php:5.0.1"/>
    <category term="cpe:/a:php:php:5.0.2"/>
    <category term="cpe:/a:php:php:5.0.3"/>
    <category term="cpe:/a:php:php:5.0.4"/>
    <category term="cpe:/a:php:php:5.0.5"/>
    <category term="cpe:/a:php:php:5.1.1"/>
    <category term="cpe:/a:php:php:5.1.2"/>
    <category term="cpe:/a:php:php:5.1.3"/>
    <category term="cpe:/a:php:php:5.1.4"/>
    <category term="cpe:/a:php:php:5.1.5"/>
    <category term="cpe:/a:php:php:5.1.6"/>
    <category term="cpe:/a:php:php:5.2.0"/>
    <category term="cpe:/a:php:php:5.2.1"/>
    <category term="cpe:/a:php:php:5.2.10"/>
    <category term="cpe:/a:php:php:5.2.11"/>
    <category term="cpe:/a:php:php:5.2.12"/>
    <category term="cpe:/a:php:php:5.2.14"/>
    <category term="cpe:/a:php:php:5.2.15"/>
    <category term="cpe:/a:php:php:5.2.16"/>
    <category term="cpe:/a:php:php:5.2.17"/>
    <category term="cpe:/a:php:php:5.2.2"/>
    <category term="cpe:/a:php:php:5.2.3"/>
    <category term="cpe:/a:php:php:5.2.4"/>
    <category term="cpe:/a:php:php:5.2.5"/>
    <category term="cpe:/a:php:php:5.2.6"/>
    <category term="cpe:/a:php:php:5.2.7"/>
    <category term="cpe:/a:php:php:5.2.8"/>
    <category term="cpe:/a:php:php:5.2.9"/>
    <category term="cpe:/a:php:php:5.3.0"/>
    <category term="cpe:/a:php:php:5.3.1"/>
    <category term="cpe:/a:php:php:5.3.2"/>
    <category term="cpe:/a:php:php:5.3.3"/>
    <category term="cpe:/a:php:php:5.3.4"/>
    <category term="cpe:/a:php:php:5.3.5"/>
    <category term="cpe:/a:php:php:5.3.6"/>
    <category term="cpe:/a:php:php:5.3.7"/>
    <category term="cpe:/a:php:php:5.3.8 and previous versions"/>
    <sec:identifier>CVE-2011-4885</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4815:ruby: Ruby (aka CRuby) before 1.8.7-p357 computes hash va...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4815_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4815_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4815_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4815_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ruby-lang:ruby:1.8.7-p299"/>
    <category term="cpe:/a:ruby-lang:ruby:1.8.7-p302"/>
    <category term="cpe:/a:ruby-lang:ruby:1.8.7-p330"/>
    <category term="cpe:/a:ruby-lang:ruby:1.8.7-p334"/>
    <category term="cpe:/a:ruby-lang:ruby:1.8.7-p352 and previous versions"/>
    <sec:identifier>CVE-2011-4815</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4838:jruby: JRuby before 1.6.5.1 computes hash values without r...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4838_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4838_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4838_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4838_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:jruby:jruby:0.9.0"/>
    <category term="cpe:/a:jruby:jruby:0.9.1"/>
    <category term="cpe:/a:jruby:jruby:0.9.2"/>
    <category term="cpe:/a:jruby:jruby:0.9.8"/>
    <category term="cpe:/a:jruby:jruby:0.9.9"/>
    <category term="cpe:/a:jruby:jruby:1.0"/>
    <category term="cpe:/a:jruby:jruby:1.0.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.0.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.0.0:rc3"/>
    <category term="cpe:/a:jruby:jruby:1.0.1"/>
    <category term="cpe:/a:jruby:jruby:1.0.2"/>
    <category term="cpe:/a:jruby:jruby:1.0.3"/>
    <category term="cpe:/a:jruby:jruby:1.1"/>
    <category term="cpe:/a:jruby:jruby:1.1.1"/>
    <category term="cpe:/a:jruby:jruby:1.1.2"/>
    <category term="cpe:/a:jruby:jruby:1.1.3"/>
    <category term="cpe:/a:jruby:jruby:1.1.4"/>
    <category term="cpe:/a:jruby:jruby:1.1.5"/>
    <category term="cpe:/a:jruby:jruby:1.1.6"/>
    <category term="cpe:/a:jruby:jruby:1.1.6:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.1:b1"/>
    <category term="cpe:/a:jruby:jruby:1.1:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.1:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.1:rc3"/>
    <category term="cpe:/a:jruby:jruby:1.2.0"/>
    <category term="cpe:/a:jruby:jruby:1.2.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.2.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.3.0"/>
    <category term="cpe:/a:jruby:jruby:1.3.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.3.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.3.1"/>
    <category term="cpe:/a:jruby:jruby:1.4.0"/>
    <category term="cpe:/a:jruby:jruby:1.4.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.4.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.4.0:rc3"/>
    <category term="cpe:/a:jruby:jruby:1.4.1"/>
    <category term="cpe:/a:jruby:jruby:1.5.0"/>
    <category term="cpe:/a:jruby:jruby:1.5.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.5.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.5.0:rc3"/>
    <category term="cpe:/a:jruby:jruby:1.5.1"/>
    <category term="cpe:/a:jruby:jruby:1.5.2"/>
    <category term="cpe:/a:jruby:jruby:1.5.3"/>
    <category term="cpe:/a:jruby:jruby:1.5.4"/>
    <category term="cpe:/a:jruby:jruby:1.5.5"/>
    <category term="cpe:/a:jruby:jruby:1.5.6"/>
    <category term="cpe:/a:jruby:jruby:1.6.0"/>
    <category term="cpe:/a:jruby:jruby:1.6.0:rc1"/>
    <category term="cpe:/a:jruby:jruby:1.6.0:rc2"/>
    <category term="cpe:/a:jruby:jruby:1.6.0:rc3"/>
    <category term="cpe:/a:jruby:jruby:1.6.1"/>
    <category term="cpe:/a:jruby:jruby:1.6.2"/>
    <category term="cpe:/a:jruby:jruby:1.6.3"/>
    <category term="cpe:/a:jruby:jruby:1.6.4"/>
    <category term="cpe:/a:jruby:jruby:1.6.5 and previous versions"/>
    <sec:identifier>CVE-2011-4838</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3415:windows_7, windows_server_2003, windows_server_2008, windows_vista, windows_xp: Open redirect vulnerability in the Forms Authentica...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3415_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3415_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3415_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka &quot;Insecure Redirect in .NET Form Authentication Vulnerability.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3415_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_7:-:-:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:-:x64"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_vista:-:sp2"/>
    <category term="cpe:/o:microsoft:windows_vista::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
    <category term="cpe:/o:microsoft:windows_xp:sp3:unknown:english"/>
    <sec:identifier>CVE-2011-3415</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4461:jetty: Jetty 8.1.0.RC2 and earlier computes hash values fo...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4461_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4461_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4461_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4461_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:morbtay:jetty:6.1.0"/>
    <category term="cpe:/a:mortbay:jetty:1.0"/>
    <category term="cpe:/a:mortbay:jetty:1.0.1"/>
    <category term="cpe:/a:mortbay:jetty:1.1"/>
    <category term="cpe:/a:mortbay:jetty:1.1.1"/>
    <category term="cpe:/a:mortbay:jetty:1.2.0"/>
    <category term="cpe:/a:mortbay:jetty:1.3.0"/>
    <category term="cpe:/a:mortbay:jetty:1.3.1"/>
    <category term="cpe:/a:mortbay:jetty:1.3.2"/>
    <category term="cpe:/a:mortbay:jetty:1.3.3"/>
    <category term="cpe:/a:mortbay:jetty:1.3.4"/>
    <category term="cpe:/a:mortbay:jetty:1.3.5"/>
    <category term="cpe:/a:mortbay:jetty:2.0.0"/>
    <category term="cpe:/a:mortbay:jetty:2.0.1"/>
    <category term="cpe:/a:mortbay:jetty:2.0.2"/>
    <category term="cpe:/a:mortbay:jetty:2.0.3"/>
    <category term="cpe:/a:mortbay:jetty:2.0.4"/>
    <category term="cpe:/a:mortbay:jetty:2.0.5"/>
    <category term="cpe:/a:mortbay:jetty:2.0:alpha1"/>
    <category term="cpe:/a:mortbay:jetty:2.0:alpha2"/>
    <category term="cpe:/a:mortbay:jetty:2.0:beta1"/>
    <category term="cpe:/a:mortbay:jetty:2.0:beta2"/>
    <category term="cpe:/a:mortbay:jetty:2.1.0"/>
    <category term="cpe:/a:mortbay:jetty:2.1.1"/>
    <category term="cpe:/a:mortbay:jetty:2.1.2"/>
    <category term="cpe:/a:mortbay:jetty:2.1.3"/>
    <category term="cpe:/a:mortbay:jetty:2.1.4"/>
    <category term="cpe:/a:mortbay:jetty:2.1.5"/>
    <category term="cpe:/a:mortbay:jetty:2.1.6"/>
    <category term="cpe:/a:mortbay:jetty:2.1.7"/>
    <category term="cpe:/a:mortbay:jetty:2.1.b0"/>
    <category term="cpe:/a:mortbay:jetty:2.1.b1"/>
    <category term="cpe:/a:mortbay:jetty:2.2.0"/>
    <category term="cpe:/a:mortbay:jetty:2.2.1"/>
    <category term="cpe:/a:mortbay:jetty:2.2.2"/>
    <category term="cpe:/a:mortbay:jetty:2.2.3"/>
    <category term="cpe:/a:mortbay:jetty:2.2.4"/>
    <category term="cpe:/a:mortbay:jetty:2.2.5"/>
    <category term="cpe:/a:mortbay:jetty:2.2.6"/>
    <category term="cpe:/a:mortbay:jetty:2.2.7"/>
    <category term="cpe:/a:mortbay:jetty:2.2.8"/>
    <category term="cpe:/a:mortbay:jetty:2.2:alpha0"/>
    <category term="cpe:/a:mortbay:jetty:2.2:alpha1"/>
    <category term="cpe:/a:mortbay:jetty:2.2:beta0"/>
    <category term="cpe:/a:mortbay:jetty:2.2:beta1"/>
    <category term="cpe:/a:mortbay:jetty:2.2:beta2"/>
    <category term="cpe:/a:mortbay:jetty:2.2:beta3"/>
    <category term="cpe:/a:mortbay:jetty:2.2:beta4"/>
    <category term="cpe:/a:mortbay:jetty:2.3.0"/>
    <category term="cpe:/a:mortbay:jetty:2.3.0a"/>
    <category term="cpe:/a:mortbay:jetty:2.3.1"/>
    <category term="cpe:/a:mortbay:jetty:2.3.2"/>
    <category term="cpe:/a:mortbay:jetty:2.3.3"/>
    <category term="cpe:/a:mortbay:jetty:2.3.4"/>
    <category term="cpe:/a:mortbay:jetty:2.3.5"/>
    <category term="cpe:/a:mortbay:jetty:2.4.0"/>
    <category term="cpe:/a:mortbay:jetty:2.4.1"/>
    <category term="cpe:/a:mortbay:jetty:2.4.2"/>
    <category term="cpe:/a:mortbay:jetty:2.4.3"/>
    <category term="cpe:/a:mortbay:jetty:2.4.4"/>
    <category term="cpe:/a:mortbay:jetty:2.4.5"/>
    <category term="cpe:/a:mortbay:jetty:2.4.6"/>
    <category term="cpe:/a:mortbay:jetty:2.4.7"/>
    <category term="cpe:/a:mortbay:jetty:2.4.8"/>
    <category term="cpe:/a:mortbay:jetty:2.4.9"/>
    <category term="cpe:/a:mortbay:jetty:3.0"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc4"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc5"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc6"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc7"/>
    <category term="cpe:/a:mortbay:jetty:3.0.0:rc8"/>
    <category term="cpe:/a:mortbay:jetty:3.0.1"/>
    <category term="cpe:/a:mortbay:jetty:3.0.2"/>
    <category term="cpe:/a:mortbay:jetty:3.0.3"/>
    <category term="cpe:/a:mortbay:jetty:3.0.4"/>
    <category term="cpe:/a:mortbay:jetty:3.0.5"/>
    <category term="cpe:/a:mortbay:jetty:3.0.6"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a0"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a1"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a2"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a3"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a4"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a5"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a6"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a7"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a8"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a9"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a90"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a91"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a92"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a93"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a94"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a95"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a96"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a97"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a98"/>
    <category term="cpe:/a:mortbay:jetty:3.0.a99"/>
    <category term="cpe:/a:mortbay:jetty:3.0.b01"/>
    <category term="cpe:/a:mortbay:jetty:3.0.b02"/>
    <category term="cpe:/a:mortbay:jetty:3.0.b03"/>
    <category term="cpe:/a:mortbay:jetty:3.0.b04"/>
    <category term="cpe:/a:mortbay:jetty:3.0.b05"/>
    <category term="cpe:/a:mortbay:jetty:3.1.0"/>
    <category term="cpe:/a:mortbay:jetty:3.1.1"/>
    <category term="cpe:/a:mortbay:jetty:3.1.2"/>
    <category term="cpe:/a:mortbay:jetty:3.1.3"/>
    <category term="cpe:/a:mortbay:jetty:3.1.4"/>
    <category term="cpe:/a:mortbay:jetty:3.1.5"/>
    <category term="cpe:/a:mortbay:jetty:3.1.6"/>
    <category term="cpe:/a:mortbay:jetty:3.1.7"/>
    <category term="cpe:/a:mortbay:jetty:3.1.8"/>
    <category term="cpe:/a:mortbay:jetty:3.1.9"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc0"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc1"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc2"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc3"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc4"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc5"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc6"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc7"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc8"/>
    <category term="cpe:/a:mortbay:jetty:3.1:rc9"/>
    <category term="cpe:/a:mortbay:jetty:4.0.0"/>
    <category term="cpe:/a:mortbay:jetty:4.0.1"/>
    <category term="cpe:/a:mortbay:jetty:4.0.1:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.0.1:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.0.1:rc2"/>
    <category term="cpe:/a:mortbay:jetty:4.0.2"/>
    <category term="cpe:/a:mortbay:jetty:4.0.3"/>
    <category term="cpe:/a:mortbay:jetty:4.0.4"/>
    <category term="cpe:/a:mortbay:jetty:4.0.5"/>
    <category term="cpe:/a:mortbay:jetty:4.0.6"/>
    <category term="cpe:/a:mortbay:jetty:4.0.b0"/>
    <category term="cpe:/a:mortbay:jetty:4.0.b1"/>
    <category term="cpe:/a:mortbay:jetty:4.0.b2"/>
    <category term="cpe:/a:mortbay:jetty:4.0.d0"/>
    <category term="cpe:/a:mortbay:jetty:4.0.d1"/>
    <category term="cpe:/a:mortbay:jetty:4.0.d2"/>
    <category term="cpe:/a:mortbay:jetty:4.0.d3"/>
    <category term="cpe:/a:mortbay:jetty:4.0.d4"/>
    <category term="cpe:/a:mortbay:jetty:4.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:4.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc4"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc5"/>
    <category term="cpe:/a:mortbay:jetty:4.1.0:rc6"/>
    <category term="cpe:/a:mortbay:jetty:4.1.1"/>
    <category term="cpe:/a:mortbay:jetty:4.1.2"/>
    <category term="cpe:/a:mortbay:jetty:4.1.3"/>
    <category term="cpe:/a:mortbay:jetty:4.1.4"/>
    <category term="cpe:/a:mortbay:jetty:4.1.b0"/>
    <category term="cpe:/a:mortbay:jetty:4.1.b1"/>
    <category term="cpe:/a:mortbay:jetty:4.1.d0"/>
    <category term="cpe:/a:mortbay:jetty:4.1.d1"/>
    <category term="cpe:/a:mortbay:jetty:4.1.d2"/>
    <category term="cpe:/a:mortbay:jetty:4.2"/>
    <category term="cpe:/a:mortbay:jetty:4.2.0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.0:beta0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.0:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.10"/>
    <category term="cpe:/a:mortbay:jetty:4.2.10:pre0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.10:pre1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.10:pre2"/>
    <category term="cpe:/a:mortbay:jetty:4.2.11"/>
    <category term="cpe:/a:mortbay:jetty:4.2.12"/>
    <category term="cpe:/a:mortbay:jetty:4.2.14"/>
    <category term="cpe:/a:mortbay:jetty:4.2.14:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.14:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.15"/>
    <category term="cpe:/a:mortbay:jetty:4.2.15:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.16"/>
    <category term="cpe:/a:mortbay:jetty:4.2.17"/>
    <category term="cpe:/a:mortbay:jetty:4.2.18"/>
    <category term="cpe:/a:mortbay:jetty:4.2.19"/>
    <category term="cpe:/a:mortbay:jetty:4.2.2"/>
    <category term="cpe:/a:mortbay:jetty:4.2.20"/>
    <category term="cpe:/a:mortbay:jetty:4.2.20:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.21"/>
    <category term="cpe:/a:mortbay:jetty:4.2.22"/>
    <category term="cpe:/a:mortbay:jetty:4.2.23"/>
    <category term="cpe:/a:mortbay:jetty:4.2.23:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.24"/>
    <category term="cpe:/a:mortbay:jetty:4.2.24:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.24:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.25"/>
    <category term="cpe:/a:mortbay:jetty:4.2.26"/>
    <category term="cpe:/a:mortbay:jetty:4.2.27"/>
    <category term="cpe:/a:mortbay:jetty:4.2.3"/>
    <category term="cpe:/a:mortbay:jetty:4.2.4"/>
    <category term="cpe:/a:mortbay:jetty:4.2.4:rc0"/>
    <category term="cpe:/a:mortbay:jetty:4.2.5"/>
    <category term="cpe:/a:mortbay:jetty:4.2.6"/>
    <category term="cpe:/a:mortbay:jetty:4.2.7"/>
    <category term="cpe:/a:mortbay:jetty:4.2.8_01"/>
    <category term="cpe:/a:mortbay:jetty:4.2.9"/>
    <category term="cpe:/a:mortbay:jetty:4.2.9:rc1"/>
    <category term="cpe:/a:mortbay:jetty:4.2.9:rc2"/>
    <category term="cpe:/a:mortbay:jetty:5.0.0"/>
    <category term="cpe:/a:mortbay:jetty:5.0.0:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.0:alpha0"/>
    <category term="cpe:/a:mortbay:jetty:5.0:alpha1"/>
    <category term="cpe:/a:mortbay:jetty:5.0:alpha2"/>
    <category term="cpe:/a:mortbay:jetty:5.0:alpha3"/>
    <category term="cpe:/a:mortbay:jetty:5.0:beta0"/>
    <category term="cpe:/a:mortbay:jetty:5.0:beta1"/>
    <category term="cpe:/a:mortbay:jetty:5.0:beta2"/>
    <category term="cpe:/a:mortbay:jetty:5.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:5.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:5.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:5.0:rc4"/>
    <category term="cpe:/a:mortbay:jetty:5.1"/>
    <category term="cpe:/a:mortbay:jetty:5.1.0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.1"/>
    <category term="cpe:/a:mortbay:jetty:5.1.10"/>
    <category term="cpe:/a:mortbay:jetty:5.1.11"/>
    <category term="cpe:/a:mortbay:jetty:5.1.11:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.12"/>
    <category term="cpe:/a:mortbay:jetty:5.1.13"/>
    <category term="cpe:/a:mortbay:jetty:5.1.14"/>
    <category term="cpe:/a:mortbay:jetty:5.1.1:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.1:rc1"/>
    <category term="cpe:/a:mortbay:jetty:5.1.2"/>
    <category term="cpe:/a:mortbay:jetty:5.1.2:pre0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3:rc1"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3:rc2"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3:rc3"/>
    <category term="cpe:/a:mortbay:jetty:5.1.3:rc4"/>
    <category term="cpe:/a:mortbay:jetty:5.1.4"/>
    <category term="cpe:/a:mortbay:jetty:5.1.4:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.5"/>
    <category term="cpe:/a:mortbay:jetty:5.1.5:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.5:rc1"/>
    <category term="cpe:/a:mortbay:jetty:5.1.5:rc2"/>
    <category term="cpe:/a:mortbay:jetty:5.1.6"/>
    <category term="cpe:/a:mortbay:jetty:5.1.7"/>
    <category term="cpe:/a:mortbay:jetty:5.1.7:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1.8"/>
    <category term="cpe:/a:mortbay:jetty:5.1.9"/>
    <category term="cpe:/a:mortbay:jetty:5.1:rc0"/>
    <category term="cpe:/a:mortbay:jetty:5.1:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:alpha0"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:alpha1"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:alpha2"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:alpha3"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta0"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta1"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta10"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta11"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta12"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta14"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta15"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta16"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta17"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta2"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta3"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta4"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta5"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta6"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta7"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta8"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:beta9"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:betax"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:6.0.0:rc4"/>
    <category term="cpe:/a:mortbay:jetty:6.0.1"/>
    <category term="cpe:/a:mortbay:jetty:6.0.2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:pre0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:pre1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:pre2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:pre3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:rc2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.0:rc3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.10"/>
    <category term="cpe:/a:mortbay:jetty:6.1.11"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12:rc2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12:rc3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12:rc4"/>
    <category term="cpe:/a:mortbay:jetty:6.1.12:rc5"/>
    <category term="cpe:/a:mortbay:jetty:6.1.14"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15:pre0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15:rc2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15:rc3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15:rc4"/>
    <category term="cpe:/a:mortbay:jetty:6.1.15:rc5"/>
    <category term="cpe:/a:mortbay:jetty:6.1.16"/>
    <category term="cpe:/a:mortbay:jetty:6.1.19"/>
    <category term="cpe:/a:mortbay:jetty:6.1.1:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.20"/>
    <category term="cpe:/a:mortbay:jetty:6.1.21"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:pre0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:pre1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc2"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc4"/>
    <category term="cpe:/a:mortbay:jetty:6.1.2:rc5"/>
    <category term="cpe:/a:mortbay:jetty:6.1.3"/>
    <category term="cpe:/a:mortbay:jetty:6.1.4"/>
    <category term="cpe:/a:mortbay:jetty:6.1.4:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.4:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.5"/>
    <category term="cpe:/a:mortbay:jetty:6.1.5:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.6"/>
    <category term="cpe:/a:mortbay:jetty:6.1.6:rc0"/>
    <category term="cpe:/a:mortbay:jetty:6.1.6:rc1"/>
    <category term="cpe:/a:mortbay:jetty:6.1.7"/>
    <category term="cpe:/a:mortbay:jetty:6.1.8"/>
    <category term="cpe:/a:mortbay:jetty:6.1.9"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0:m1"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0:m2"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0:pre0"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0:pre1"/>
    <category term="cpe:/a:mortbay:jetty:7.0.0:pre3"/>
    <category term="cpe:/a:mortbay:jetty:8.1.0:rc2 and previous versions"/>
    <sec:identifier>CVE-2011-4461</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3417:windows_7, windows_server_2003, windows_server_2008, windows_vista, windows_xp: The Forms Authentication feature in the ASP.NET sub...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3417_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3417_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3417_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka &quot;ASP.NET Forms Authentication Ticket Caching Vulnerability.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3417_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_7:-:-:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:-:x64"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_vista:-:sp2"/>
    <category term="cpe:/o:microsoft:windows_vista::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
    <category term="cpe:/o:microsoft:windows_xp:sp3:unknown:english"/>
    <sec:identifier>CVE-2011-3417</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4084:tomcat: Apache Tomcat before 5.5.35, 6.x before 6.0.35, and...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4084_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4084_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4084_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 does not properly handle a large number of form parameters, which might allow remote attackers to cause a denial of service (CPU consumption) via a request that triggers storage of many parameters in a hash table.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4084_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:tomcat:5.5.35"/>
    <category term="cpe:/a:apache:tomcat:6.0.0"/>
    <category term="cpe:/a:apache:tomcat:6.0.1"/>
    <category term="cpe:/a:apache:tomcat:6.0.10"/>
    <category term="cpe:/a:apache:tomcat:6.0.11"/>
    <category term="cpe:/a:apache:tomcat:6.0.12"/>
    <category term="cpe:/a:apache:tomcat:6.0.13"/>
    <category term="cpe:/a:apache:tomcat:6.0.14"/>
    <category term="cpe:/a:apache:tomcat:6.0.15"/>
    <category term="cpe:/a:apache:tomcat:6.0.16"/>
    <category term="cpe:/a:apache:tomcat:6.0.17"/>
    <category term="cpe:/a:apache:tomcat:6.0.18"/>
    <category term="cpe:/a:apache:tomcat:6.0.19"/>
    <category term="cpe:/a:apache:tomcat:6.0.2"/>
    <category term="cpe:/a:apache:tomcat:6.0.20"/>
    <category term="cpe:/a:apache:tomcat:6.0.21"/>
    <category term="cpe:/a:apache:tomcat:6.0.22"/>
    <category term="cpe:/a:apache:tomcat:6.0.23"/>
    <category term="cpe:/a:apache:tomcat:6.0.24"/>
    <category term="cpe:/a:apache:tomcat:6.0.25"/>
    <category term="cpe:/a:apache:tomcat:6.0.26"/>
    <category term="cpe:/a:apache:tomcat:6.0.27"/>
    <category term="cpe:/a:apache:tomcat:6.0.28"/>
    <category term="cpe:/a:apache:tomcat:6.0.29"/>
    <category term="cpe:/a:apache:tomcat:6.0.3"/>
    <category term="cpe:/a:apache:tomcat:6.0.30"/>
    <category term="cpe:/a:apache:tomcat:6.0.31"/>
    <category term="cpe:/a:apache:tomcat:6.0.32"/>
    <category term="cpe:/a:apache:tomcat:6.0.33"/>
    <category term="cpe:/a:apache:tomcat:6.0.34"/>
    <category term="cpe:/a:apache:tomcat:6.0.4"/>
    <category term="cpe:/a:apache:tomcat:6.0.5"/>
    <category term="cpe:/a:apache:tomcat:6.0.6"/>
    <category term="cpe:/a:apache:tomcat:6.0.7"/>
    <category term="cpe:/a:apache:tomcat:6.0.8"/>
    <category term="cpe:/a:apache:tomcat:6.0.9"/>
    <category term="cpe:/a:apache:tomcat:7.0.0"/>
    <category term="cpe:/a:apache:tomcat:7.0.1"/>
    <category term="cpe:/a:apache:tomcat:7.0.10"/>
    <category term="cpe:/a:apache:tomcat:7.0.11"/>
    <category term="cpe:/a:apache:tomcat:7.0.12"/>
    <category term="cpe:/a:apache:tomcat:7.0.13"/>
    <category term="cpe:/a:apache:tomcat:7.0.14"/>
    <category term="cpe:/a:apache:tomcat:7.0.15"/>
    <category term="cpe:/a:apache:tomcat:7.0.16"/>
    <category term="cpe:/a:apache:tomcat:7.0.17"/>
    <category term="cpe:/a:apache:tomcat:7.0.18"/>
    <category term="cpe:/a:apache:tomcat:7.0.19"/>
    <category term="cpe:/a:apache:tomcat:7.0.2"/>
    <category term="cpe:/a:apache:tomcat:7.0.20"/>
    <category term="cpe:/a:apache:tomcat:7.0.21"/>
    <category term="cpe:/a:apache:tomcat:7.0.22"/>
    <category term="cpe:/a:apache:tomcat:7.0.3"/>
    <category term="cpe:/a:apache:tomcat:7.0.4"/>
    <category term="cpe:/a:apache:tomcat:7.0.5"/>
    <category term="cpe:/a:apache:tomcat:7.0.6"/>
    <category term="cpe:/a:apache:tomcat:7.0.7"/>
    <category term="cpe:/a:apache:tomcat:7.0.8"/>
    <category term="cpe:/a:apache:tomcat:7.0.9"/>
    <sec:identifier>CVE-2011-4084</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3416:windows_7, windows_server_2003, windows_server_2008, windows_vista, windows_xp: The Forms Authentication feature in the ASP.NET sub...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3416_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3416_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3416_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka &quot;ASP.Net Forms Authentication Bypass Vulnerability.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3416_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_7:-:-:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:-:x64"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_vista:-:sp2"/>
    <category term="cpe:/o:microsoft:windows_vista::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
    <category term="cpe:/o:microsoft:windows_xp:sp3:unknown:english"/>
    <sec:identifier>CVE-2011-3416</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3414:windows_7, windows_server_2003, windows_server_2008, windows_vista, windows_xp: The CaseInsensitiveHashProvider.getHashCode functio...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3414_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3414_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3414_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka &quot;Collisions in HashTable May Cause DoS Vulnerability.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3414_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/o:microsoft:windows_7:-:-:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:-:x64"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x32"/>
    <category term="cpe:/o:microsoft:windows_7:-:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2003::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x32"/>
    <category term="cpe:/o:microsoft:windows_server_2008:-:sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::r2:x64"/>
    <category term="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
    <category term="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
    <category term="cpe:/o:microsoft:windows_vista:-:sp2"/>
    <category term="cpe:/o:microsoft:windows_vista::sp2:x64"/>
    <category term="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
    <category term="cpe:/o:microsoft:windows_xp:sp3:unknown:english"/>
    <sec:identifier>CVE-2011-3414</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>[Update]CVE-2011-5021:phpids: PHPIDS before 0.7 does not properly implement Regul...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_2.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_2.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_2.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_2.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpids:phpids:0.6.4"/>
    <category term="cpe:/a:phpids:phpids:0.6.5 and previous versions"/>
    <sec:identifier>CVE-2011-5021</sec:identifier>
    <vrda:latestrevisionno>2</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>2</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5037:v8: Google V8 computes hash values for form parameters ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5037_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5037_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5037_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, as demonstrated by attacks against Node.js.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5037_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:google:v8"/>
    <sec:identifier>CVE-2011-5037</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5036:rack: Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x be...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5036_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5036_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5036_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5036_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rubyforge:rack:1.1.33"/>
    <category term="cpe:/a:rubyforge:rack:1.2.0"/>
    <category term="cpe:/a:rubyforge:rack:1.2.1"/>
    <category term="cpe:/a:rubyforge:rack:1.2.2"/>
    <category term="cpe:/a:rubyforge:rack:1.2.3"/>
    <category term="cpe:/a:rubyforge:rack:1.2.4"/>
    <category term="cpe:/a:rubyforge:rack:1.3.0"/>
    <category term="cpe:/a:rubyforge:rack:1.3.1"/>
    <category term="cpe:/a:rubyforge:rack:1.3.2"/>
    <category term="cpe:/a:rubyforge:rack:1.3.3"/>
    <category term="cpe:/a:rubyforge:rack:1.3.4"/>
    <category term="cpe:/a:rubyforge:rack:1.3.5"/>
    <sec:identifier>CVE-2011-5036</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5032:winmount: WMDrive.sys 3.4.181.224 in WinMount 3.5.1018 allows...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5032_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5032_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5032_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
WMDrive.sys 3.4.181.224 in WinMount 3.5.1018 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted 0x87342000 IOCTL request to the WMDriver device.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5032_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:winmount:winmount:3.5.1018"/>
    <sec:identifier>CVE-2011-5032</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5030:meta_tags_quick: Cross-site scripting (XSS) vulnerability in the Met...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5030_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5030_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5030_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in the Meta tags quick module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, probably related to &quot;names of entity bundles.&quot;&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5030_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:drupal:drupal"/>
    <category term="cpe:/a:valthbald:meta_tags_quick:7.x-2.1"/>
    <category term="cpe:/a:valthbald:meta_tags_quick:7.x-2.2"/>
    <sec:identifier>CVE-2011-5030</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5027:zabbix: Cross-site scripting (XSS) vulnerability in ZABBIX ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5027_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5027_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5027_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the profiler.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5027_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zabbix:zabbix:1.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta10"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta11"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta12"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta2"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta3"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta4"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta5"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta6"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta7"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta8"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta9"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.1:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.2:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.4:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.5:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.6:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.7:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.8:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.1:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.2:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.4:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.9"/>
    <category term="cpe:/a:zabbix:zabbix:1.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.10:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.10:rc2 and previous versions"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.5:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.7:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9:rc2"/>
    <sec:identifier>CVE-2011-5027</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5034:geronimo: Apache Geronimo 2.2.1 and earlier computes hash val...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5034_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5034_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5034_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.  NOTE: this might overlap CVE-2011-4461.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5034_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:geronimo:1.0"/>
    <category term="cpe:/a:apache:geronimo:1.1"/>
    <category term="cpe:/a:apache:geronimo:1.1.1"/>
    <category term="cpe:/a:apache:geronimo:1.2"/>
    <category term="cpe:/a:apache:geronimo:2.0.1"/>
    <category term="cpe:/a:apache:geronimo:2.0.2"/>
    <category term="cpe:/a:apache:geronimo:2.1"/>
    <category term="cpe:/a:apache:geronimo:2.1.1"/>
    <category term="cpe:/a:apache:geronimo:2.1.2"/>
    <category term="cpe:/a:apache:geronimo:2.1.3"/>
    <category term="cpe:/a:apache:geronimo:2.1.4"/>
    <category term="cpe:/a:apache:geronimo:2.1.5"/>
    <category term="cpe:/a:apache:geronimo:2.1.6"/>
    <category term="cpe:/a:apache:geronimo:2.1.7"/>
    <category term="cpe:/a:apache:geronimo:2.1.8"/>
    <category term="cpe:/a:apache:geronimo:2.2"/>
    <category term="cpe:/a:apache:geronimo:2.2.1 and previous versions"/>
    <sec:identifier>CVE-2011-5034</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5029:simple_php_blog: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5029_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5029_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5029_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5029_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:alexander_palmo:simple_php_blog:0.7.0 and previous versions"/>
    <sec:identifier>CVE-2011-5029</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4615:zabbix: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4615_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4615_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4615_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4615_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zabbix:zabbix:1.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.1.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta10"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta11"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta12"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta2"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta3"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta4"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta5"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta6"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta7"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta8"/>
    <category term="cpe:/a:zabbix:zabbix:1.1:beta9"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.1:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.2:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.4:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.5:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.6:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.7:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3.8:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.4.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.1:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.2:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.3:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5.4:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.5:beta"/>
    <category term="cpe:/a:zabbix:zabbix:1.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.6.9"/>
    <category term="cpe:/a:zabbix:zabbix:1.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.7.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.10:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.10:rc2 and previous versions"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.3:rc4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.4:rc4"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.5"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.5:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.6:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.7"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.7:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc2"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.8:rc3"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9:rc1"/>
    <category term="cpe:/a:zabbix:zabbix:1.8.9:rc2"/>
    <sec:identifier>CVE-2011-4615</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5035:glassfish_server: Oracle Glassfish 3.1.1 and earlier computes hash va...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5035_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5035_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5035_AD_1.html</id>
    <published>2011-12-30T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Oracle Glassfish 3.1.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5035_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:oracle:glassfish_server:1.0:ur1"/>
    <category term="cpe:/a:oracle:glassfish_server:2.0"/>
    <category term="cpe:/a:oracle:glassfish_server:2.1"/>
    <category term="cpe:/a:oracle:glassfish_server:2.1.1"/>
    <category term="cpe:/a:oracle:glassfish_server:2:ur1"/>
    <category term="cpe:/a:oracle:glassfish_server:2:ur2"/>
    <category term="cpe:/a:oracle:glassfish_server:3.0"/>
    <category term="cpe:/a:oracle:glassfish_server:3.0.1"/>
    <category term="cpe:/a:oracle:glassfish_server:3.1"/>
    <category term="cpe:/a:oracle:glassfish_server:3.1.1 and previous versions"/>
    <sec:identifier>CVE-2011-5035</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5028:sentinel_log_manager: Directory traversal vulnerability in novelllogmanag...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5028_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5028_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5028_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5028_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:novell:sentinel_log_manager:1.2.0.1_938 and previous versions"/>
    <sec:identifier>CVE-2011-5028</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5031:capexweb: Multiple SQL injection vulnerabilities in servlet/c...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5031_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5031_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5031_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-30T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) dfuserid and (2) dfpassword parameters.  NOTE: some of these details are obtained from third party information.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5031_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:shilpisoft:capexweb:1.1"/>
    <sec:identifier>CVE-2011-5031</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5023:pligg_cms: Cross-site scripting (XSS) vulnerability in Pligg C...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5023_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5023_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5023_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5023_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pligg:pligg_cms:1.1.4"/>
    <sec:identifier>CVE-2011-5023</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5021:phpids: PHPIDS before 0.7 does not properly implement Regul...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to an arbitrary file via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5021_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpids:phpids:0.6.4"/>
    <category term="cpe:/a:phpids:phpids:0.6.5 and previous versions"/>
    <sec:identifier>CVE-2011-5021</sec:identifier>
    <vrda:latestrevisionno>2</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4165:database_archiving_software: Unspecified vulnerability in HP Database Archiving ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4165_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4165_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4165_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1263.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4165_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:database_archiving_software:6.31"/>
    <sec:identifier>CVE-2011-4165</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4164:database_archiving_software: Unspecified vulnerability in HP Database Archiving ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4164_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4164_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4164_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1214.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4164_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:database_archiving_software:6.31"/>
    <sec:identifier>CVE-2011-4164</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4163:database_archiving_software: Unspecified vulnerability in HP Database Archiving ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4163_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4163_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4163_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1213.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4163_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:database_archiving_software:6.31"/>
    <sec:identifier>CVE-2011-4163</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5025:yaws: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5025_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5025_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5025_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5025_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:yaws:yaws:1.88"/>
    <sec:identifier>CVE-2011-5025</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5022:pligg_cms: SQL injection vulnerability in search.php in Pligg ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5022_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5022_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5022_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5022_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pligg:pligg_cms:1.1.2"/>
    <sec:identifier>CVE-2011-5022</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5026:winn_guestbook: Cross-site scripting (XSS) vulnerability in Winn Gu...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5026_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5026_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5026_AD_1.html</id>
    <published>2011-12-29T00:00:00+09:00</published>
    <updated>2011-12-29T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5026_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:winn:winn_guestbook:2.4.1:beta"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.2"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.3"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.4"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.5"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.6"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.7"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.8b"/>
    <category term="cpe:/a:winn:winn_guestbook:2.4.8c and previous versions"/>
    <sec:identifier>CVE-2011-5026</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003556:IDA Pro &#12398; IDAPython &#12503;&#12521;&#12464;&#12452;&#12531;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003556_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003556_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003556_AD_1.html</id>
    <published>2011-12-28T16:47:56+09:00</published>
    <updated>2011-12-28T16:47:56+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IDA Pro の IDAPython プラグインには、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003556_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:google:idapython"/>
    <category term="cpe:/a:hex-rays:ida"/>
    <sec:identifier>JVNDB-2011-003556</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003555:NVIDIA Stereoscopic 3D &#12489;&#12521;&#12452;&#12496;&#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003555_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003555_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003555_AD_1.html</id>
    <published>2011-12-28T16:44:29+09:00</published>
    <updated>2011-12-28T16:44:29+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
NVIDIA Stereoscopic 3D ドライバは、名前付きパイプへ送られたコマンドを適切に処理しないため、権限を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003555_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:nvidia:stereoscopic_3d_driver"/>
    <sec:identifier>JVNDB-2011-003555</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003554:WordPress &#29992;&#12398; WP Symposium &#12503;&#12521;&#12464;&#12452;&#12531;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003554_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003554_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003554_AD_1.html</id>
    <published>2011-12-28T16:40:58+09:00</published>
    <updated>2011-12-28T16:40:58+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WordPress 用の WP Symposium プラグインの uploadify/get_profile_avatar.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003554_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wpsymposium:wp_symposium"/>
    <sec:identifier>JVNDB-2011-003554</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003553:IBM Lotus Domino &#12398;&#35469;&#35388;&#27231;&#33021;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#29366;&#24907;&#12392;&#12394;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003553_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003553_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003553_AD_1.html</id>
    <published>2011-12-28T16:40:17+09:00</published>
    <updated>2011-12-28T16:40:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IBM Lotus Domino の認証機能には、サービス運用妨害 (デーモンクラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003553_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:lotus_domino"/>
    <sec:identifier>JVNDB-2011-003553</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003552:7-Technologies Interactive Graphical SCADA System &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003552_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003552_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003552_AD_1.html</id>
    <published>2011-12-28T15:58:39+09:00</published>
    <updated>2011-12-28T15:58:39+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
7-Technologies (7T) Interactive Graphical SCADA System (IGSS) には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003552_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss"/>
    <sec:identifier>JVNDB-2011-003552</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003551:7-Technologies &#12398; Interactive Graphical SCADA System &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003551_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003551_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003551_AD_1.html</id>
    <published>2011-12-28T15:57:23+09:00</published>
    <updated>2011-12-28T15:57:23+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
7-Technologies (7T) の Interactive Graphical SCADA System (IGSS) には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003551_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss"/>
    <sec:identifier>JVNDB-2011-003551</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2010-002874:WellinTech KingView &#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002874_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002874_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002874_AD_1.html</id>
    <published>2011-12-28T15:55:33+09:00</published>
    <updated>2011-12-28T15:55:33+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WellinTech KingView 内の HistorySvr.exe (HistoryServer.exe) の nettransdll.dll には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002874_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wellintek:kingview"/>
    <sec:identifier>JVNDB-2010-002874</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003550:HP Managed Printing Administration &#12395;&#12362;&#12369;&#12427;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003550_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003550_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003550_AD_1.html</id>
    <published>2011-12-28T15:53:07+09:00</published>
    <updated>2011-12-28T15:53:07+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HP Managed Printing Administration には、重要な情報を取得される、データを変更される、またはサービス運用妨害 (DoS) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003550_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration"/>
    <sec:identifier>JVNDB-2011-003550</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003549:HP Managed Printing Administration &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003549_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003549_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003549_AD_1.html</id>
    <published>2011-12-28T15:51:16+09:00</published>
    <updated>2011-12-28T15:51:16+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HP Managed Printing Administration の hpmpa/jobDelivery/Default.asp には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003549_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration"/>
    <sec:identifier>JVNDB-2011-003549</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003548:HP Managed Printing Administration &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003548_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003548_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003548_AD_1.html</id>
    <published>2011-12-28T15:50:37+09:00</published>
    <updated>2011-12-28T15:50:37+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HP Managed Printing Administration の MPAUploader.dll には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003548_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration"/>
    <sec:identifier>JVNDB-2011-003548</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003547:HP Managed Printing Administration &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003547_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003547_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003547_AD_1.html</id>
    <published>2011-12-28T15:49:19+09:00</published>
    <updated>2011-12-28T15:49:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HP Managed Printing Administration の MPAUploader.Uploader.1.UploadFiles メソッドには、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003547_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration"/>
    <sec:identifier>JVNDB-2011-003547</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003546:Trend Micro Control Manager &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003546_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003546_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003546_AD_1.html</id>
    <published>2011-12-28T15:37:49+09:00</published>
    <updated>2011-12-28T15:37:49+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Trend Micro Control Manager の CmdProcessor.exe 内の cmdHandlerRedAlertController.dll の CGenericScheduler::AddTask 関数には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003546_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:trend_micro:control_manager"/>
    <sec:identifier>JVNDB-2011-003546</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003545:FreeBSD &#12398; telnetd &#12398; libtelnet/encrypt.c &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003545_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003545_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003545_AD_1.html</id>
    <published>2011-12-28T15:36:37+09:00</published>
    <updated>2011-12-28T15:36:37+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
FreeBSD の telnetd の libtelnet/encrypt.c には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003545_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:h5l:heimdal"/>
    <category term="cpe:/a:mit:kerberos"/>
    <category term="cpe:/o:freebsd:freebsd"/>
    <sec:identifier>JVNDB-2011-003545</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003544:Pidgin &#12398; family_feedbag.c &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003544_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003544_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003544_AD_1.html</id>
    <published>2011-12-28T15:35:46+09:00</published>
    <updated>2011-12-28T15:35:46+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Pidgin の libpurple 内の oscar protocol プラグインの family_feedbag.c は、メッセージデータにおける UTF-8 の検証を実行しないため、サービス運用妨害 (アプリケーションクラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003544_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pidgin:pidgin"/>
    <sec:identifier>JVNDB-2011-003544</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003543:Mini-Stream RM-MP3 Converter &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003543_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003543_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003543_AD_1.html</id>
    <published>2011-12-28T15:32:16+09:00</published>
    <updated>2011-12-28T15:32:16+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Mini-Stream RM-MP3 Converter には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003543_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ministream:rmmp3_converter"/>
    <sec:identifier>JVNDB-2011-003543</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003542:Mini-Stream Ripper &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003542_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003542_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003542_AD_1.html</id>
    <published>2011-12-28T15:31:40+09:00</published>
    <updated>2011-12-28T15:31:40+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Mini-Stream Ripper には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003542_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ministream:ripper"/>
    <sec:identifier>JVNDB-2011-003542</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003541:lighttpd &#12398; base64_decode &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#31526;&#21495;&#12456;&#12521;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003541_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003541_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003541_AD_1.html</id>
    <published>2011-12-28T15:31:04+09:00</published>
    <updated>2011-12-28T15:31:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
lighttpd の HTTP 認証機能 (http_auth.c) 内の base64_decode 関数には、整数符号エラーの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003541_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:lighttpd:lighttpd"/>
    <sec:identifier>JVNDB-2011-003541</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003540:QQPlayer &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003540_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003540_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003540_AD_1.html</id>
    <published>2011-12-28T14:30:30+09:00</published>
    <updated>2011-12-28T14:30:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
QQPlayer には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003540_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:qqplayer:qqplayer"/>
    <sec:identifier>JVNDB-2011-003540</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003539:QuiXplorer &#12395;&#12362;&#12369;&#12427;&#12501;&#12449;&#12452;&#12523;&#12434;&#12450;&#12483;&#12503;&#12525;&#12540;&#12489;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003539_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003539_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003539_AD_1.html</id>
    <published>2011-12-28T14:29:23+09:00</published>
    <updated>2011-12-28T14:29:23+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
QuiXplorer には、index.php の upload アクションを利用する実行可能な拡張子を持つファイルがアップロード後にアクセスされることで、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003539_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:claudio_klingler:quixplorer"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer"/>
    <sec:identifier>JVNDB-2011-003539</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003538:Joomla! &#29992; Fabrik &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12398; models/importcsv.php &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003538_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003538_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003538_AD_1.html</id>
    <published>2011-12-28T14:28:31+09:00</published>
    <updated>2011-12-28T14:28:31+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Joomla! 用 Fabrik (com_fabrik) コンポーネントの models/importcsv.php には、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003538_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:fabrikar:com_fabrikar"/>
    <sec:identifier>JVNDB-2011-003538</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003537:Avid Media Composer &#12398; Phonetic Indexer &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003537_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003537_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003537_AD_1.html</id>
    <published>2011-12-28T14:27:36+09:00</published>
    <updated>2011-12-28T14:27:36+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Avid Media Composer の Phonetic Indexer には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003537_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:avid:media_composer"/>
    <sec:identifier>JVNDB-2011-003537</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003536:Final Draft &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003536_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003536_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003536_AD_1.html</id>
    <published>2011-12-28T14:24:39+09:00</published>
    <updated>2011-12-28T14:24:39+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Final Draft には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003536_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:finaldraft:finaldraft"/>
    <sec:identifier>JVNDB-2011-003536</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003535:Reflection FTP &#12463;&#12521;&#12452;&#12450;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003535_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003535_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003535_AD_1.html</id>
    <published>2011-12-28T11:44:23+09:00</published>
    <updated>2011-12-28T11:44:23+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Attachmate Reflection で使用される Reflection FTP クライアント (rftpcom.dll) には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003535_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:attachmate:reflection"/>
    <sec:identifier>JVNDB-2011-003535</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003534:xt:Commerce &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003534_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003534_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003534_AD_1.html</id>
    <published>2011-12-28T11:41:19+09:00</published>
    <updated>2011-12-28T11:41:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
xt:Commerce には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003534_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:xt-commerce:xt%3Acommerce"/>
    <sec:identifier>JVNDB-2011-003534</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003533:Ctek SkyRouter &#12398; apps/a3/cfg_ethping.cgi &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12510;&#12531;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003533_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003533_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003533_AD_1.html</id>
    <published>2011-12-28T11:40:28+09:00</published>
    <updated>2011-12-28T11:40:28+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Ctek SkyRouter の apps/a3/cfg_ethping.cgi には、任意のコマンドを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003533_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:ctekproducts:skyrouter"/>
    <sec:identifier>JVNDB-2011-003533</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003532:3S CoDeSys &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (NULL &#12509;&#12452;&#12531;&#12479;&#12487;&#12522;&#12501;&#12449;&#12524;&#12531;&#12473;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003532_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003532_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003532_AD_1.html</id>
    <published>2011-12-28T11:36:37+09:00</published>
    <updated>2011-12-28T11:36:37+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
3S CoDeSys の Control サービス内にある CmpWebServer.dll モジュールには、サービス運用妨害 (NULL ポインタデリファレンス) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003532_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys"/>
    <sec:identifier>JVNDB-2011-003532</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003531:3S CoDeSys &#12398; GatewayService &#12467;&#12531;&#12509;&#12540;&#12493;&#12531;&#12488;&#12395;&#12362;&#12369;&#12427;&#25972;&#25968;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003531_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003531_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003531_AD_1.html</id>
    <published>2011-12-28T11:35:22+09:00</published>
    <updated>2011-12-28T11:35:22+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
3S CoDeSys の GatewayService コンポーネントには、整数オーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003531_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys"/>
    <sec:identifier>JVNDB-2011-003531</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003530:3S CoDeSys &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003530_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003530_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003530_AD_1.html</id>
    <published>2011-12-28T11:34:30+09:00</published>
    <updated>2011-12-28T11:34:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
3S CoDeSys の CmpWebServer コンポーネントには、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003530_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys"/>
    <sec:identifier>JVNDB-2011-003530</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003529:Wuzly &#12398;&#31649;&#29702;&#27231;&#33021;&#12395;&#12362;&#12369;&#12427;&#35469;&#35388;&#12434;&#22238;&#36991;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003529_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003529_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003529_AD_1.html</id>
    <published>2011-12-28T11:31:34+09:00</published>
    <updated>2011-12-28T11:31:34+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Wuzly の管理機能には、認証を回避される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003529_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly"/>
    <sec:identifier>JVNDB-2011-003529</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003528:Wuzly &#12395;&#12362;&#12369;&#12427; SQL &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003528_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003528_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003528_AD_1.html</id>
    <published>2011-12-28T11:31:02+09:00</published>
    <updated>2011-12-28T11:31:02+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Wuzly には、SQL インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003528_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly"/>
    <sec:identifier>JVNDB-2011-003528</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003527:Wuzly &#12398; blog_system/data_functions.php &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003527_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003527_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003527_AD_1.html</id>
    <published>2011-12-28T11:30:36+09:00</published>
    <updated>2011-12-28T11:30:36+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Wuzly の blog_system/data_functions.php には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003527_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly"/>
    <sec:identifier>JVNDB-2011-003527</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003526:Wuzly &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003526_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003526_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003526_AD_1.html</id>
    <published>2011-12-28T11:30:07+09:00</published>
    <updated>2011-12-28T11:30:07+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Wuzly には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003526_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly"/>
    <sec:identifier>JVNDB-2011-003526</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003525:Wuzly &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003525_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003525_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003525_AD_1.html</id>
    <published>2011-12-28T11:29:40+09:00</published>
    <updated>2011-12-28T11:29:40+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Wuzly には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003525_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly"/>
    <sec:identifier>JVNDB-2011-003525</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003524:RPM &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12513;&#12514;&#12522;&#30772;&#25613;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003524_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003524_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003524_AD_1.html</id>
    <published>2011-12-28T11:23:47+09:00</published>
    <updated>2011-12-28T11:23:47+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
RPM には、rpmio/rpmpgp.c の (1) regionSwab 関数、(2) headerLoad 関数、および (3) multiple 関数に関する処理に不備があるため、サービス運用妨害 (メモリ破損) 状態となる、および任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003524_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:redhat:rhel_server_eus:6.0.z"/>
    <category term="cpe:/a:redhat:rhel_server_eus:6.1.z"/>
    <category term="cpe:/a:rpm:rpm"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::as"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::es"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::ws"/>
    <category term="cpe:/o:redhat:enterprise_linux:5::server"/>
    <category term="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
    <category term="cpe:/o:redhat:enterprise_linux_desktop:5.0::client"/>
    <category term="cpe:/o:redhat:enterprise_linux_desktop:6"/>
    <category term="cpe:/o:redhat:enterprise_linux_els:3"/>
    <category term="cpe:/o:redhat:enterprise_linux_eus:5.6.z::server"/>
    <category term="cpe:/o:redhat:enterprise_linux_hpc_node:6"/>
    <category term="cpe:/o:redhat:enterprise_linux_long_life"/>
    <category term="cpe:/o:redhat:enterprise_linux_server:6"/>
    <category term="cpe:/o:redhat:enterprise_linux_workstation:6"/>
    <category term="cpe:/o:redhat:rhel_desktop_workstation:5::client"/>
    <sec:identifier>JVNDB-2011-003524</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003523:Cyrus IMAPd &#12398; NNTP &#12469;&#12540;&#12496; (nntpd) &#20869;&#12398; imap/nntpd.c &#12395;&#12362;&#12369;&#12427;&#35469;&#35388;&#12434;&#22238;&#36991;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003523_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003523_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003523_AD_1.html</id>
    <published>2011-12-28T11:12:57+09:00</published>
    <updated>2011-12-28T11:12:57+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Cyrus IMAPd の NNTP サーバ (nntpd) 内の imap/nntpd.c には、認証を回避される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003523_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cyrus:imapd"/>
    <category term="cpe:/a:redhat:rhel_server_eus:6.1.z"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::as"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::es"/>
    <category term="cpe:/o:redhat:enterprise_linux:4::ws"/>
    <category term="cpe:/o:redhat:enterprise_linux:5::server"/>
    <category term="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
    <category term="cpe:/o:redhat:enterprise_linux_server:6"/>
    <category term="cpe:/o:redhat:enterprise_linux_workstation:6"/>
    <category term="cpe:/o:redhat:rhel_desktop_workstation:5::client"/>
    <sec:identifier>JVNDB-2011-003523</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003522:OpenStack Compute (Nova)  &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003522_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003522_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003522_AD_1.html</id>
    <published>2011-12-28T11:08:54+09:00</published>
    <updated>2011-12-28T11:08:54+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
OpenStack Compute (Nova) には、EC2 API および S3/RegisterImage メソッドが有効であるとき、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003522_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openstack:compute"/>
    <sec:identifier>JVNDB-2011-003522</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5001:control_manager: Stack-based buffer overflow in the CGenericSchedule...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5001_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5001_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5001_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-28T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5001_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:trend_micro:control_manager:5.5 and previous versions"/>
    <sec:identifier>CVE-2011-5001</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2009-5111:goahead_webserver: GoAhead WebServer allows remote attackers to cause ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5111_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5111_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5111_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-28T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5111_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:goahead:goahead_webserver"/>
    <sec:identifier>CVE-2009-5111</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2009-5110:dhttpd: dhttpd allows remote attackers to cause a denial of...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5110_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5110_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5110_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-28T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5110_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:dhttpd:dhttpd"/>
    <sec:identifier>CVE-2009-5110</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2007-6750:http_server: The Apache HTTP Server 1.x and 2.x allows remote at...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2007-6750_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2007-6750_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2007-6750_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-28T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2007-6750_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:http_server:1.0"/>
    <category term="cpe:/a:apache:http_server:1.0.2"/>
    <category term="cpe:/a:apache:http_server:1.0.3"/>
    <category term="cpe:/a:apache:http_server:1.0.5"/>
    <category term="cpe:/a:apache:http_server:1.1"/>
    <category term="cpe:/a:apache:http_server:1.1.1"/>
    <category term="cpe:/a:apache:http_server:1.2"/>
    <category term="cpe:/a:apache:http_server:1.2.4"/>
    <category term="cpe:/a:apache:http_server:1.2.5"/>
    <category term="cpe:/a:apache:http_server:1.2.6"/>
    <category term="cpe:/a:apache:http_server:1.2.9"/>
    <category term="cpe:/a:apache:http_server:1.3"/>
    <category term="cpe:/a:apache:http_server:1.3.0"/>
    <category term="cpe:/a:apache:http_server:1.3.1"/>
    <category term="cpe:/a:apache:http_server:1.3.1.1"/>
    <category term="cpe:/a:apache:http_server:1.3.10"/>
    <category term="cpe:/a:apache:http_server:1.3.11"/>
    <category term="cpe:/a:apache:http_server:1.3.12"/>
    <category term="cpe:/a:apache:http_server:1.3.13"/>
    <category term="cpe:/a:apache:http_server:1.3.14"/>
    <category term="cpe:/a:apache:http_server:1.3.15"/>
    <category term="cpe:/a:apache:http_server:1.3.16"/>
    <category term="cpe:/a:apache:http_server:1.3.17"/>
    <category term="cpe:/a:apache:http_server:1.3.18"/>
    <category term="cpe:/a:apache:http_server:1.3.19"/>
    <category term="cpe:/a:apache:http_server:1.3.2"/>
    <category term="cpe:/a:apache:http_server:1.3.20"/>
    <category term="cpe:/a:apache:http_server:1.3.22"/>
    <category term="cpe:/a:apache:http_server:1.3.23"/>
    <category term="cpe:/a:apache:http_server:1.3.24"/>
    <category term="cpe:/a:apache:http_server:1.3.25"/>
    <category term="cpe:/a:apache:http_server:1.3.26"/>
    <category term="cpe:/a:apache:http_server:1.3.27"/>
    <category term="cpe:/a:apache:http_server:1.3.28"/>
    <category term="cpe:/a:apache:http_server:1.3.29"/>
    <category term="cpe:/a:apache:http_server:1.3.3"/>
    <category term="cpe:/a:apache:http_server:1.3.30"/>
    <category term="cpe:/a:apache:http_server:1.3.31"/>
    <category term="cpe:/a:apache:http_server:1.3.32"/>
    <category term="cpe:/a:apache:http_server:1.3.33"/>
    <category term="cpe:/a:apache:http_server:1.3.34"/>
    <category term="cpe:/a:apache:http_server:1.3.35"/>
    <category term="cpe:/a:apache:http_server:1.3.36"/>
    <category term="cpe:/a:apache:http_server:1.3.37"/>
    <category term="cpe:/a:apache:http_server:1.3.38"/>
    <category term="cpe:/a:apache:http_server:1.3.39"/>
    <category term="cpe:/a:apache:http_server:1.3.4"/>
    <category term="cpe:/a:apache:http_server:1.3.41"/>
    <category term="cpe:/a:apache:http_server:1.3.42"/>
    <category term="cpe:/a:apache:http_server:1.3.5"/>
    <category term="cpe:/a:apache:http_server:1.3.6"/>
    <category term="cpe:/a:apache:http_server:1.3.65"/>
    <category term="cpe:/a:apache:http_server:1.3.68"/>
    <category term="cpe:/a:apache:http_server:1.3.7"/>
    <category term="cpe:/a:apache:http_server:1.3.8"/>
    <category term="cpe:/a:apache:http_server:1.3.9"/>
    <category term="cpe:/a:apache:http_server:1.4.0"/>
    <category term="cpe:/a:apache:http_server:1.99"/>
    <category term="cpe:/a:apache:http_server:2.0"/>
    <category term="cpe:/a:apache:http_server:2.0.28"/>
    <category term="cpe:/a:apache:http_server:2.0.28:beta"/>
    <category term="cpe:/a:apache:http_server:2.0.32"/>
    <category term="cpe:/a:apache:http_server:2.0.32:beta"/>
    <category term="cpe:/a:apache:http_server:2.0.34:beta"/>
    <category term="cpe:/a:apache:http_server:2.0.35"/>
    <category term="cpe:/a:apache:http_server:2.0.36"/>
    <category term="cpe:/a:apache:http_server:2.0.37"/>
    <category term="cpe:/a:apache:http_server:2.0.38"/>
    <category term="cpe:/a:apache:http_server:2.0.39"/>
    <category term="cpe:/a:apache:http_server:2.0.40"/>
    <category term="cpe:/a:apache:http_server:2.0.41"/>
    <category term="cpe:/a:apache:http_server:2.0.42"/>
    <category term="cpe:/a:apache:http_server:2.0.43"/>
    <category term="cpe:/a:apache:http_server:2.0.44"/>
    <category term="cpe:/a:apache:http_server:2.0.45"/>
    <category term="cpe:/a:apache:http_server:2.0.46"/>
    <category term="cpe:/a:apache:http_server:2.0.47"/>
    <category term="cpe:/a:apache:http_server:2.0.48"/>
    <category term="cpe:/a:apache:http_server:2.0.49"/>
    <category term="cpe:/a:apache:http_server:2.0.50"/>
    <category term="cpe:/a:apache:http_server:2.0.51"/>
    <category term="cpe:/a:apache:http_server:2.0.52"/>
    <category term="cpe:/a:apache:http_server:2.0.53"/>
    <category term="cpe:/a:apache:http_server:2.0.54"/>
    <category term="cpe:/a:apache:http_server:2.0.55"/>
    <category term="cpe:/a:apache:http_server:2.0.56"/>
    <category term="cpe:/a:apache:http_server:2.0.57"/>
    <category term="cpe:/a:apache:http_server:2.0.58"/>
    <category term="cpe:/a:apache:http_server:2.0.59"/>
    <category term="cpe:/a:apache:http_server:2.0.60"/>
    <category term="cpe:/a:apache:http_server:2.0.61"/>
    <category term="cpe:/a:apache:http_server:2.0.63"/>
    <category term="cpe:/a:apache:http_server:2.0.9"/>
    <category term="cpe:/a:apache:http_server:2.1"/>
    <category term="cpe:/a:apache:http_server:2.1.1"/>
    <category term="cpe:/a:apache:http_server:2.1.2"/>
    <category term="cpe:/a:apache:http_server:2.1.3"/>
    <category term="cpe:/a:apache:http_server:2.1.4"/>
    <category term="cpe:/a:apache:http_server:2.1.5"/>
    <category term="cpe:/a:apache:http_server:2.1.6"/>
    <category term="cpe:/a:apache:http_server:2.1.7"/>
    <category term="cpe:/a:apache:http_server:2.1.8"/>
    <category term="cpe:/a:apache:http_server:2.1.9"/>
    <category term="cpe:/a:apache:http_server:2.2"/>
    <category term="cpe:/a:apache:http_server:2.2.0"/>
    <category term="cpe:/a:apache:http_server:2.2.1"/>
    <category term="cpe:/a:apache:http_server:2.2.10"/>
    <category term="cpe:/a:apache:http_server:2.2.11"/>
    <category term="cpe:/a:apache:http_server:2.2.12"/>
    <category term="cpe:/a:apache:http_server:2.2.13"/>
    <category term="cpe:/a:apache:http_server:2.2.14 and previous versions"/>
    <category term="cpe:/a:apache:http_server:2.2.2"/>
    <category term="cpe:/a:apache:http_server:2.2.3"/>
    <category term="cpe:/a:apache:http_server:2.2.4"/>
    <category term="cpe:/a:apache:http_server:2.2.6"/>
    <category term="cpe:/a:apache:http_server:2.2.8"/>
    <category term="cpe:/a:apache:http_server:2.2.9"/>
    <sec:identifier>CVE-2007-6750</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>[Update]CVE-2010-5081:rm-mp3_converter: Stack-based buffer overflow in Mini-Stream RM-MP3 C...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_2.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_2.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_2.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-28T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_2.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mini-stream:rm-mp3_converter:3.1.2.1"/>
    <sec:identifier>CVE-2010-5081</sec:identifier>
    <vrda:latestrevisionno>2</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>2</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003521:Blueberry BB FlashBack &#12398; ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003521_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003521_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003521_AD_1.html</id>
    <published>2011-12-27T16:46:16+09:00</published>
    <updated>2011-12-27T16:46:16+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IBM Rational Rhapsody およびその他の製品で使用される Blueberry BB FlashBack の Recorder.dll に含まれる Blueberry FlashBack ActiveX コントロールは、TestCompatibilityRecordMode メソッドを適切に実装していないため、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003521_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody"/>
    <sec:identifier>JVNDB-2011-003521</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003520:Blueberry BB FlashBack &#12398; ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003520_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003520_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003520_AD_1.html</id>
    <published>2011-12-27T16:45:17+09:00</published>
    <updated>2011-12-27T16:45:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IBM Rational Rhapsody およびその他の製品で使用される Blueberry BB FlashBack の Recorder.dll に含まれる Blueberry FlashBack ActiveX コントロールは、InsertMarker メソッドを適切に実装していないため、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003520_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody"/>
    <sec:identifier>JVNDB-2011-003520</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003519:Blueberry BB FlashBack &#12398; ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003519_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003519_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003519_AD_1.html</id>
    <published>2011-12-27T16:44:29+09:00</published>
    <updated>2011-12-27T16:44:29+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
IBM Rational Rhapsody およびその他の製品で使用される Blueberry BB FlashBack の Recorder.dll に含まれる Blueberry FlashBack ActiveX コントロールは、(1) Start、(2) PauseAndSave、(3) InsertMarker、および (4) InsertSoundToFBRAtMarker メソッドを適切に実装していないため、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003519_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody"/>
    <sec:identifier>JVNDB-2011-003519</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003518:Tor &#12395;&#12362;&#12369;&#12427;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003518_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003518_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003518_AD_1.html</id>
    <published>2011-12-27T11:17:04+09:00</published>
    <updated>2011-12-27T11:17:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor には、ニックネーム設定オプション無しでリレーとして構成され、ローカルホスト名をニックネームの値として使う場合、重要な情報を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003518_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003518</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003517:Tor &#12395;&#12362;&#12369;&#12427;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003517_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003517_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003517_AD_1.html</id>
    <published>2011-12-27T11:13:42+09:00</published>
    <updated>2011-12-27T11:13:42+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor には、以前に構成され、現在は構成されていない到達可能なブリッジを使い続けることによって、重要な情報を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003517_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003517</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003516:Tor &#12395;&#12362;&#12369;&#12427;&#12502;&#12522;&#12483;&#12472;&#12434;&#21015;&#25369;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003516_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003516_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003516_AD_1.html</id>
    <published>2011-12-27T11:10:22+09:00</published>
    <updated>2011-12-27T11:10:22+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor には、ブリッジとして構成され、クライアントとは異なるプロセスで回路をセットアップするとき、ブリッジを列挙される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003516_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003516</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003515:Tor &#12395;&#12362;&#12369;&#12427;&#12502;&#12522;&#12483;&#12472;&#12434;&#21015;&#25369;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003515_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003515_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003515_AD_1.html</id>
    <published>2011-12-27T11:06:31+09:00</published>
    <updated>2011-12-27T11:06:31+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor には、ブリッジとして構成され、ディレクトリ取得のための Tor TLS 接続の代わりに、直接的な DirPort アクセスを利用する場合、ブリッジを列挙される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003515_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003515</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003514:Tor &#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003514_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003514_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003514_AD_1.html</id>
    <published>2011-12-27T11:04:57+09:00</published>
    <updated>2011-12-27T11:04:57+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003514_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003514</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003513:Tor &#12395;&#12362;&#12369;&#12427;&#12502;&#12522;&#12483;&#12472;&#12434;&#21015;&#25369;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003513_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003513_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003513_AD_1.html</id>
    <published>2011-12-27T11:01:47+09:00</published>
    <updated>2011-12-27T11:01:47+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor は、ブリッジとして構成される場合、開始した OR 接続内のセルの Command フィールドで CREATE および CREATE_FAST の値を受け取るため、ブリッジを列挙される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003513_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003513</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003512:Tor &#12395;&#12362;&#12369;&#12427;&#21311;&#21517;&#21270;&#12398;&#12383;&#12417;&#12398;&#12503;&#12525;&#12497;&#12486;&#12451;&#12434;&#28961;&#21177;&#12395;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003512_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003512_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003512_AD_1.html</id>
    <published>2011-12-27T10:54:48+09:00</published>
    <updated>2011-12-27T10:54:48+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Tor は、クライアントまたはブリッジとして構成されるとき、OR 接続中に発信されるデータに TLS の証明書チェーンが含まれるため、匿名化のためのプロパティを無効にされる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003512_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor"/>
    <sec:identifier>JVNDB-2011-003512</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003511:PmWiki &#12398; PageListSort &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003511_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003511_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003511_AD_1.html</id>
    <published>2011-12-27T10:46:30+09:00</published>
    <updated>2011-12-27T10:46:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
PmWiki の scripts/pagelist.php 内の PageListSort 関数には、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003511_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pmwiki:pmwiki"/>
    <sec:identifier>JVNDB-2011-003511</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003510:Power2Go &#12395;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003510_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003510_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003510_AD_1.html</id>
    <published>2011-12-27T09:43:17+09:00</published>
    <updated>2011-12-27T09:43:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Power2Go には、バッファオーバーフローの脆弱性が存在します。  Power2Go には、プロジェクトファイルの解析処理に問題があり、バッファオーバーフローの脆弱性が存在します。  なお、本脆弱性を使用した攻撃コードが公開されています。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003510_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cyberlink:power2go"/>
    <sec:identifier>JVNDB-2011-003510</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003509:Support Incident Tracker &#12395;&#35079;&#25968;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003509_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003509_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003509_AD_1.html</id>
    <published>2011-12-27T09:42:42+09:00</published>
    <updated>2011-12-27T09:42:42+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Support Incident Tracker (SiT!) には、複数の脆弱性が存在します。  SiT! には、悪意あるファイルのアップロード、SQL インジェクション、クロスサイトスクリプティング、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003509_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:the_support_incident_tracker_project:freichatpure"/>
    <sec:identifier>JVNDB-2011-003509</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3841:wp_symposium, wp_symposium0.1.11.1, wp_symposium0.1.14.1, wp_symposium0.1.29.3, w...: Cross-site scripting (XSS) vulnerability in uploadi...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3841_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3841_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3841_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3841_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wordpress:wordpress"/>
    <category term="cpe:/a:wpsymposium:wp_symposium0.1.11.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium0.1.14.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium0.1.29.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium0.57"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.10"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.10.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.11"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.12"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.12.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.13"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.14"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.14.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.15"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.16"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.16.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.16.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.16.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.17"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.18"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.18.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.19"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.20"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.20.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.21"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.22"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.23"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.24"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.25"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.26"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.26.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.27"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.27.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.28"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.29"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.29.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.29.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.29.4"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.30"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.30.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.31"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.32"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33.4"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.33.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.34"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.34.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.34.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.4"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.6"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.7"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.7.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.8"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.8.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.8.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.1.9"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.35"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.36"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.36.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.37"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.38"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.38.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.38.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.39"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.39.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.40.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.41"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.42"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.43"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.44"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.45"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.46"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.46.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.47.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.48.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.48.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49.6"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49.8"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.49.9"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.50"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.51"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.51.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.51.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.52"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.52.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.52.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.52.4"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.52.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.10"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.4"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.6"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.8"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.53.9"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.54"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.55"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.55.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.56"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.56.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.56.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.56.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.57.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.57.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.58"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.58.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.59"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.59.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.59.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.59.5"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.59.6"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.60"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.61"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.61.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.62"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.62.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.62.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.63"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.63.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.63.2"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.63.2.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.63.3"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:0.64"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.11.26 and previous versions"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.8.18"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.8.19"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.8.19.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.8.21"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.8.27"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.9.1"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.9.10"/>
    <category term="cpe:/a:wpsymposium:wp_symposium:11.9.4"/>
    <sec:identifier>CVE-2011-3841</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4537:igss: Multiple buffer overflows in 7-Technologies (7T) In...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4537_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4537_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4537_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple buffer overflows in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11355 and earlier allow remote attackers to execute arbitrary code or cause a denial of service via a crafted packet to TCP port (1) 12397 or (2) 12399.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4537_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss:9.0.0.11355 and previous versions"/>
    <sec:identifier>CVE-2011-4537</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4167:managed_printing_administration: Stack-based buffer overflow in MPAUploader.dll in H...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4167_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4167_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4167_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in MPAUploader.dll in HP Managed Printing Administration before 2.6.4 allows remote attackers to execute arbitrary code via a long filename parameter in an uploadfile action to Default.asp.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4167_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration:2.6.3 and previous versions"/>
    <sec:identifier>CVE-2011-4167</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4166:managed_printing_administration: Directory traversal vulnerability in the MPAUploade...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4166_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4166_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4166_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4166_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration:2.6.3 and previous versions"/>
    <sec:identifier>CVE-2011-4166</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4169:managed_printing_administration: Unspecified vulnerability in HP Managed Printing Ad...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4169_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4169_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4169_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unspecified vulnerability in HP Managed Printing Administration before 2.6.4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4169_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration:2.6.3 and previous versions"/>
    <sec:identifier>CVE-2011-4169</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4168:managed_printing_administration: Directory traversal vulnerability in hpmpa/jobDeliv...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4168_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4168_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4168_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Directory traversal vulnerability in hpmpa/jobDelivery/Default.asp in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4168_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:hp:managed_printing_administration:2.6.3 and previous versions"/>
    <sec:identifier>CVE-2011-4168</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4536:kingview: Heap-based buffer overflow in nettransdll.dll in Hi...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4536_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4536_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4536_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allows remote attackers to execute arbitrary code via a crafted op-code 3 packet.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4536_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wellintech:kingview:6.53"/>
    <category term="cpe:/a:wellintech:kingview:65.30.2010.18018"/>
    <sec:identifier>CVE-2011-4536</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4784:stereoscopic_3d_driver: The NVIDIA Stereoscopic 3D driver before 7.17.12.75...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4784_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4784_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4784_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The NVIDIA Stereoscopic 3D driver before 7.17.12.7565 does not properly handle commands sent to a named pipe, which allows local users to gain privileges via a crafted application.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4784_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:nvidia:stereoscopic_3d_driver:7.17.12.7536 and previous versions"/>
    <sec:identifier>CVE-2011-4784</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4783:idapython: The IDAPython plugin before 1.5.2.3 in IDA Pro allo...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4783_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4783_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4783_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_runtime_data files in the current working directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4783_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:google:idapython:1.2.0"/>
    <category term="cpe:/a:google:idapython:1.4.0"/>
    <category term="cpe:/a:google:idapython:1.4.1"/>
    <category term="cpe:/a:google:idapython:1.4.2"/>
    <category term="cpe:/a:google:idapython:1.4.3"/>
    <category term="cpe:/a:google:idapython:1.5.0"/>
    <category term="cpe:/a:google:idapython:1.5.1"/>
    <category term="cpe:/a:google:idapython:1.5.2 and previous versions"/>
    <category term="cpe:/a:hex-rays:ida:6.0::pro"/>
    <sec:identifier>CVE-2011-4783</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4050:igss: Buffer overflow in 7-Technologies (7T) Interactive ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4050_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4050_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4050_AD_1.html</id>
    <published>2011-12-27T00:00:00+09:00</published>
    <updated>2011-12-27T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to cause a denial of service via a crafted packet to TCP port 12401.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4050_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss:9.0.0.11200"/>
    <sec:identifier>CVE-2011-4050</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003508:Sielco Sistemi Winlog PRO &#12362;&#12424;&#12403; Winlog Lite &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003508_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003508_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003508_AD_1.html</id>
    <published>2011-12-26T16:32:41+09:00</published>
    <updated>2011-12-26T16:32:41+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Sielco Sistemi Winlog PRO および Winlog Lite には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003508_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sielcosistemi:winlog_lite"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro"/>
    <sec:identifier>JVNDB-2011-003508</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003507:Moodle &#12398; calendar/set.php &#12395;&#12362;&#12369;&#12427; CRLF &#12452;&#12531;&#12472;&#12455;&#12463;&#12471;&#12519;&#12531;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003507_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003507_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003507_AD_1.html</id>
    <published>2011-12-26T16:32:03+09:00</published>
    <updated>2011-12-26T16:32:03+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Moodle の Calendar コンポーネント内の calendar/set.php には、CRLF インジェクションの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003507_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:moodle:moodle"/>
    <sec:identifier>JVNDB-2011-003507</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003506:phpMyAdmin &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003506_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003506_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003506_AD_1.html</id>
    <published>2011-12-26T16:31:10+09:00</published>
    <updated>2011-12-26T16:31:10+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
phpMyAdmin には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003506_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin"/>
    <sec:identifier>JVNDB-2011-003506</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003505:phpMyAdmin &#12398; libraries/display_export.lib.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003505_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003505_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003505_AD_1.html</id>
    <published>2011-12-26T16:30:22+09:00</published>
    <updated>2011-12-26T16:30:22+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
phpMyAdmin の libraries/display_export.lib.php には、(1) server、(2) database、および (3) table セクションのエクスポートパネルに関する処理に不備があるため、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003505_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin"/>
    <sec:identifier>JVNDB-2011-003505</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003504:phpMyAdmin &#12398; libraries/config/ConfigFile.class.php &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003504_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003504_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003504_AD_1.html</id>
    <published>2011-12-26T16:29:36+09:00</published>
    <updated>2011-12-26T16:29:36+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
phpMyAdmin のセットアップインターフェース内にある libraries/config/ConfigFile.class.php には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003504_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin"/>
    <sec:identifier>JVNDB-2011-003504</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-000110:WordPress &#26085;&#26412;&#35486;&#29256;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000110_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000110_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000110_AD_1.html</id>
    <published>2011-12-26T12:01:50+09:00</published>
    <updated>2011-12-26T12:01:50+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WordPress 日本語版には、クロスサイトスクリプティングの脆弱性が存在します。  WordPress.Org が提供する WordPress は、ウェブログシステムです。 WordPress 日本語版には、クロスサイトスクリプティングの脆弱性が存在します。  この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方が IPA に報告し、JPCERT/CC が開発者との調整を行いました。 報告者: 川原 勝広 氏、株式会社神戸デジタル・ラボ 福井 公三 氏、三井物産セキュアディレクション株式会社 吉田 裕也 氏&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000110_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wordpress:wordpress"/>
    <sec:identifier>JVNDB-2011-000110</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-000109:WordPress &#12395;&#12362;&#12356;&#12390;&#20219;&#24847;&#12398; PHP &#12467;&#12540;&#12489;&#12364;&#23455;&#34892;&#21487;&#33021;&#12394;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000109_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000109_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000109_AD_1.html</id>
    <published>2011-12-26T12:01:21+09:00</published>
    <updated>2011-12-26T12:01:21+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WordPress には、任意の PHP コードが実行可能な脆弱性が存在します。  WordPress.Org が提供する WordPress は、ウェブログシステムです。 WordPress には、任意の PHP コードが実行可能な脆弱性が存在します。  この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方が IPA に報告し、JPCERT/CC が開発者との調整を行いました。 報告者: 三井物産セキュアディレクション株式会社 寺田 健 氏&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000109_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wordpress:wordpress"/>
    <sec:identifier>JVNDB-2011-000109</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-000108:Movable Type &#29992;&#12513;&#12540;&#12523;&#12501;&#12457;&#12540;&#12512;&#12503;&#12521;&#12464;&#12452;&#12531;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000108_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000108_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000108_AD_1.html</id>
    <published>2011-12-26T12:00:41+09:00</published>
    <updated>2011-12-26T12:00:41+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
メールフォームプラグインには、クロスサイトスクリプティングの脆弱性が存在します。  メールフォームプラグインは、Movable Type 用のプラグインです。メールフォームプラグインには、クロスサイトスクリプティングの脆弱性が存在します。  この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方が IPA に報告し、JPCERT/CC が開発者との調整を行いました。 報告者: 株式会社　サイバーディフェンス研究所 福森 大喜 氏&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000108_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:misc:h-fj_mail_form_plugin"/>
    <sec:identifier>JVNDB-2011-000108</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5011:xt:commerce: Multiple cross-site request forgery (CSRF) vulnerab...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5011_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5011_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5011_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authentication of Amins for requests that (1) set a New user to Adim via the cID parameter to a statusconfirm action in admin/customers.php and (2) grant permissions to users via the cID parameter to a save action in admin/accounting.php.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5011_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:xt-commerce:xt%3Acommerce:3.0.4:sp2.1"/>
    <sec:identifier>CVE-2011-5011</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4862:freebsd, heimdal, krb5-appl: Buffer overflow in libtelnet/encrypt.c in telnetd i...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4862_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4862_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4862_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, and Heimdal 1.5.1 and earlier allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4862_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:h5l:heimdal:1.5.1 and previous versions"/>
    <category term="cpe:/a:mit:krb5-appl:1.02 and previous versions"/>
    <category term="cpe:/o:freebsd:freebsd:7.3"/>
    <category term="cpe:/o:freebsd:freebsd:8.0"/>
    <category term="cpe:/o:freebsd:freebsd:8.1"/>
    <category term="cpe:/o:freebsd:freebsd:8.2"/>
    <category term="cpe:/o:freebsd:freebsd:9.0"/>
    <sec:identifier>CVE-2011-4862</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5006:qqplayer: Stack-based buffer overflow in QQPlayer 3.2.845 all...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5006_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5006_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5006_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5006_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:qqplayer:qqplayer:3.2.845"/>
    <sec:identifier>CVE-2011-5006</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5005:quixplorer, t3quixplorer: Unrestricted file upload vulnerability in QuiXplore...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5005_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5005_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5005_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5005_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.0"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.1"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.2"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.4"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.5"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:1.6"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:2.0"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:2.1.1"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:2.2"/>
    <category term="cpe:/a:claudio_klingler:quixplorer:2.3 and previous versions"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.0.0:-"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.0.1"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.0.2"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.2.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.3.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.4.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.5.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.6.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.7.0"/>
    <category term="cpe:/a:mads_brunn:t3quixplorer:1.7.1"/>
    <sec:identifier>CVE-2011-5005</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3838:wuzly: Multiple SQL injection vulnerabilities in Wuzly 2.0...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3838_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3838_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3838_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple SQL injection vulnerabilities in Wuzly 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to fp.php, (2) epage parameter to newpage.php, (3) epost parameter to newpost.php, and (4) username parameter to login.php in admin/; or the (5) username parameter to mobile/login.php.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3838_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly:2.0"/>
    <sec:identifier>CVE-2011-3838</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5004:com_fabrikar: Unrestricted file upload vulnerability in models/im...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5004_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5004_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5004_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5004_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:fabrikar:com_fabrikar:2.1 and previous versions"/>
    <category term="cpe:/a:joomla:joomla%21"/>
    <sec:identifier>CVE-2011-5004</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5003:media_composer: Stack-based buffer overflow in the Phonetic Indexer...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5003_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5003_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5003_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5003_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:avid:media_composer:5.5.3 and previous versions"/>
    <sec:identifier>CVE-2011-5003</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3839:wuzly: The administration functionality in Wuzly 2.0 allow...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3839_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3839_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3839_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3839_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly:2.0"/>
    <sec:identifier>CVE-2011-3839</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5009:codesys: The CmpWebServer.dll module in the Control service ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5009_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5009_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5009_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5009_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys:3.4:sp4"/>
    <sec:identifier>CVE-2011-5009</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5008:codesys: Integer overflow in the GatewayService component in...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5008_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5008_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5008_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5008_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys:3.4:sp4"/>
    <sec:identifier>CVE-2011-5008</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5010:skyrouter: apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5010_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5010_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5010_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a &quot;u&quot; action.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5010_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:ctekproducts:skyrouter:4200"/>
    <category term="cpe:/h:ctekproducts:skyrouter:4300"/>
    <sec:identifier>CVE-2011-5010</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4362:lighttpd: Integer signedness error in the base64_decode funct...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4362_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4362_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4362_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4362_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:lighttpd:lighttpd:1.0.2"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.0.3"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.0"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.1"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.2"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.3"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.4"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.5"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.6"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.7"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.8"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.1.9"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.0"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.1"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.2"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.3"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.5"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.6"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.7"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.2.8"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.0"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.1"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.10"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.11"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.12"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.13"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.14"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.15"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.16"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.2"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.3"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.4"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.5"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.6"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.8"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.3.9"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.0"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.10"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.11"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.12"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.13"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.14"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.15"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.16"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.17"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.18"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.19"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.2"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.20"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.21"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.22"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.23"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.24"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.25"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.3"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.4"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.5"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.6"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.7"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.8"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.4.9"/>
    <category term="cpe:/a:lighttpd:lighttpd:1.5.0 and previous versions"/>
    <sec:identifier>CVE-2011-4362</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2010-5081:ripper: Stack-based buffer overflow in Mini-Stream RM-MP3 C...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2010-5081_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ministream:ripper:rmmp3_converter:3.1.2.1"/>
    <sec:identifier>CVE-2010-5081</sec:identifier>
    <vrda:latestrevisionno>2</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4601:pidgin: family_feedbag.c in the oscar protocol plugin in li...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4601_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4601_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4601_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4601_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pidgin:pidgin:2.0.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.0.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.0.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.1.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.1.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.10.0 and previous versions"/>
    <category term="cpe:/a:pidgin:pidgin:2.2.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.2.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.2.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.3.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.3.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.4.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.4.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.4.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.4.3"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.3"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.4"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.5"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.6"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.7"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.8"/>
    <category term="cpe:/a:pidgin:pidgin:2.5.9"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.3"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.4"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.5"/>
    <category term="cpe:/a:pidgin:pidgin:2.6.6"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.1"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.10"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.11"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.2"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.3"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.4"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.5"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.6"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.7"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.8"/>
    <category term="cpe:/a:pidgin:pidgin:2.7.9"/>
    <category term="cpe:/a:pidgin:pidgin:2.8.0"/>
    <category term="cpe:/a:pidgin:pidgin:2.9.0"/>
    <sec:identifier>CVE-2011-4601</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3378:rpm: RPM 4.4.x through 4.9.x, probably before 4.9.1.2, a...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3378_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3378_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3378_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3378_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rpm:rpm:4.4.2"/>
    <category term="cpe:/a:rpm:rpm:4.4.2."/>
    <category term="cpe:/a:rpm:rpm:4.4.2.1"/>
    <category term="cpe:/a:rpm:rpm:4.4.2.2"/>
    <category term="cpe:/a:rpm:rpm:4.4.2.3"/>
    <category term="cpe:/a:rpm:rpm:4.6.0"/>
    <category term="cpe:/a:rpm:rpm:4.6.1"/>
    <category term="cpe:/a:rpm:rpm:4.7.0"/>
    <category term="cpe:/a:rpm:rpm:4.7.1"/>
    <category term="cpe:/a:rpm:rpm:4.7.2"/>
    <category term="cpe:/a:rpm:rpm:4.8.0"/>
    <category term="cpe:/a:rpm:rpm:4.9.1.1 and previous versions"/>
    <sec:identifier>CVE-2011-3378</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5002:finaldraft: Multiple stack-based buffer overflows in Final Draf...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5002_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5002_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5002_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5002_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:finaldraft:finaldraft:8.01 and previous versions"/>
    <sec:identifier>CVE-2011-5002</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5012:reflection, reflection_2008, reflection_2008r1, reflection_2008r2, reflection_2011r1: Heap-based buffer overflow in the Reflection FTP Cl...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5012_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5012_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5012_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206 allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5012_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:attachmate:reflection:14.1:sp1"/>
    <category term="cpe:/a:attachmate:reflection:7.2:sp1:windows_client"/>
    <category term="cpe:/a:attachmate:reflection_2008"/>
    <category term="cpe:/a:attachmate:reflection_2008r1:sp1"/>
    <category term="cpe:/a:attachmate:reflection_2008r2"/>
    <category term="cpe:/a:attachmate:reflection_2011r1"/>
    <sec:identifier>CVE-2011-5012</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3372:imapd: imap/nntpd.c in the NNTP server (nntpd) for Cyrus I...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3372_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3372_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3372_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3372_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:cyrus:imapd:2.4.11 and previous versions"/>
    <sec:identifier>CVE-2011-3372</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3837:wuzly: Directory traversal vulnerability in blog_system/da...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3837_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3837_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3837_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Directory traversal vulnerability in blog_system/data_functions.php in Wuzly 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the preview parameter to index.php.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3837_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly:2.0"/>
    <sec:identifier>CVE-2011-3837</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3836:wuzly: Multiple cross-site request forgery (CSRF) vulnerab...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3836_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3836_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3836_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator, (2) perform cross-site scripting (XSS), (3) perform SQL injection, or have other unspecified impact via unknown vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3836_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly:2.0"/>
    <sec:identifier>CVE-2011-3836</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3835:wuzly: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3835_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3835_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3835_AD_1.html</id>
    <published>2011-12-24T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow remote attackers to inject arbitrary web script or HTML via the Referer header to (1) admin/login.php and (2) admin/404.php; the (3) q parameter to search.php; the (4) theme_name parameter to theme_settings.php, (5) extension_name parameter to extension_settings.php, (6) q parameter to search.php, (7) type parameter to comments.php, sort parameter to (8) pages.php and (9) posts.php, and the (10) type and (11) q parameter t...&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3835_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wuzly:wuzly:2.0"/>
    <sec:identifier>CVE-2011-3835</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-1388:bb_flashback: The Blueberry FlashBack ActiveX control in BB Flash...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1388_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1388_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1388_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the TestCompatibilityRecordMode method, which allows remote attackers to execute arbitrary code via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1388_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:.bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody:7.6.1 and previous versions"/>
    <sec:identifier>CVE-2011-1388</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-1391:bb_flashback: The Blueberry FlashBack ActiveX control in BB Flash...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1391_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1391_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1391_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the InsertMarker method, which allows remote attackers to execute arbitrary code via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1391_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:.bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody:7.6.1 and previous versions"/>
    <sec:identifier>CVE-2011-1391</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-1392:bb_flashback: The Blueberry FlashBack ActiveX control in BB Flash...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1392_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1392_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1392_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-1392_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:.bbsoftware:bb_flashback"/>
    <category term="cpe:/a:ibm:rational_rhapsody:7.6.1 and previous versions"/>
    <sec:identifier>CVE-2011-1392</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2009-5109:ripper: Stack-based buffer overflow in Mini-Stream Ripper 3...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5109_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5109_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5109_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2009-5109_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ministream:ripper:3.0.1.1"/>
    <sec:identifier>CVE-2009-5109</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4596:compute: Multiple directory traversal vulnerabilities in Ope...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4596_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4596_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4596_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4596_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:openstack:compute:2011.3 and previous versions"/>
    <sec:identifier>CVE-2011-4596</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-5007:codesys: Stack-based buffer overflow in the CmpWebServer com...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5007_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5007_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5007_AD_1.html</id>
    <published>2011-12-25T00:00:00+09:00</published>
    <updated>2011-12-26T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-5007_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:3ssoftware:codesys:3.4:sp4 and previous versions"/>
    <sec:identifier>CVE-2011-5007</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-2769:tor: Tor before 0.2.2.34, when configured as a bridge, a...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2769_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2769_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2769_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2769_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.29"/>
    <category term="cpe:/a:tor:tor:0.2.2.29:beta"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.32"/>
    <category term="cpe:/a:tor:tor:0.2.2.33 and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-2769</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4897:tor: Tor before 0.2.2.25-alpha, when configured as a rel...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4897_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4897_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4897_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4897_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.24:alpha and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-4897</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4894:tor: Tor before 0.2.2.34, when configured as a bridge, u...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4894_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4894_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4894_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4894_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.29"/>
    <category term="cpe:/a:tor:tor:0.2.2.29:beta"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.32"/>
    <category term="cpe:/a:tor:tor:0.2.2.33 and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-4894</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-2768:tor: Tor before 0.2.2.34, when configured as a client or...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2768_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2768_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2768_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2768_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.29"/>
    <category term="cpe:/a:tor:tor:0.2.2.29:beta"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.32"/>
    <category term="cpe:/a:tor:tor:0.2.2.33 and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-2768</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-2778:tor: Multiple heap-based buffer overflows in Tor before ...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2778_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2778_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2778_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by (1) establishing a SOCKS connection to SocksPort or (2) leveraging a SOCKS proxy configuration.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-2778_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.29"/>
    <category term="cpe:/a:tor:tor:0.2.2.29:beta"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.32"/>
    <category term="cpe:/a:tor:tor:0.2.2.33"/>
    <category term="cpe:/a:tor:tor:0.2.2.34 and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-2778</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3990:pukiwiki_plus!: Cross-site scripting (XSS) vulnerability in plugin/...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3990_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3990_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3990_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in plugin/comment.inc.php in PukiWiki Plus! 1.4.7plus-u2-i18n and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3990_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pukiwiki:pukiwiki_plus%21:1.47:plus-u2-i18n and previous versions"/>
    <sec:identifier>CVE-2011-3990</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4895:tor: Tor before 0.2.2.34, when configured as a bridge, s...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4895_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4895_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4895_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4895_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.29"/>
    <category term="cpe:/a:tor:tor:0.2.2.29:beta"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.32"/>
    <category term="cpe:/a:tor:tor:0.2.2.33 and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-4895</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4896:tor: Tor before 0.2.2.24-alpha continues to use a reacha...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4896_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4896_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4896_AD_1.html</id>
    <published>2011-12-23T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4896_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:tor:tor:0.0.2"/>
    <category term="cpe:/a:tor:tor:0.0.3"/>
    <category term="cpe:/a:tor:tor:0.0.4"/>
    <category term="cpe:/a:tor:tor:0.0.5"/>
    <category term="cpe:/a:tor:tor:0.0.6"/>
    <category term="cpe:/a:tor:tor:0.0.6.1"/>
    <category term="cpe:/a:tor:tor:0.0.6.2"/>
    <category term="cpe:/a:tor:tor:0.0.7"/>
    <category term="cpe:/a:tor:tor:0.0.7.1"/>
    <category term="cpe:/a:tor:tor:0.0.7.2"/>
    <category term="cpe:/a:tor:tor:0.0.7.3"/>
    <category term="cpe:/a:tor:tor:0.0.8"/>
    <category term="cpe:/a:tor:tor:0.0.8.1"/>
    <category term="cpe:/a:tor:tor:0.0.9"/>
    <category term="cpe:/a:tor:tor:0.0.9.1"/>
    <category term="cpe:/a:tor:tor:0.0.9.10"/>
    <category term="cpe:/a:tor:tor:0.0.9.2"/>
    <category term="cpe:/a:tor:tor:0.0.9.3"/>
    <category term="cpe:/a:tor:tor:0.0.9.4"/>
    <category term="cpe:/a:tor:tor:0.0.9.5"/>
    <category term="cpe:/a:tor:tor:0.0.9.6"/>
    <category term="cpe:/a:tor:tor:0.0.9.7"/>
    <category term="cpe:/a:tor:tor:0.0.9.8"/>
    <category term="cpe:/a:tor:tor:0.0.9.9"/>
    <category term="cpe:/a:tor:tor:0.1.0.1"/>
    <category term="cpe:/a:tor:tor:0.1.0.10"/>
    <category term="cpe:/a:tor:tor:0.1.0.11"/>
    <category term="cpe:/a:tor:tor:0.1.0.12"/>
    <category term="cpe:/a:tor:tor:0.1.0.13"/>
    <category term="cpe:/a:tor:tor:0.1.0.14"/>
    <category term="cpe:/a:tor:tor:0.1.0.15"/>
    <category term="cpe:/a:tor:tor:0.1.0.16"/>
    <category term="cpe:/a:tor:tor:0.1.0.17"/>
    <category term="cpe:/a:tor:tor:0.1.0.18"/>
    <category term="cpe:/a:tor:tor:0.1.0.19"/>
    <category term="cpe:/a:tor:tor:0.1.0.2"/>
    <category term="cpe:/a:tor:tor:0.1.0.3"/>
    <category term="cpe:/a:tor:tor:0.1.0.4"/>
    <category term="cpe:/a:tor:tor:0.1.0.5"/>
    <category term="cpe:/a:tor:tor:0.1.0.6"/>
    <category term="cpe:/a:tor:tor:0.1.0.7"/>
    <category term="cpe:/a:tor:tor:0.1.0.8"/>
    <category term="cpe:/a:tor:tor:0.1.0.9"/>
    <category term="cpe:/a:tor:tor:0.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.1"/>
    <category term="cpe:/a:tor:tor:0.1.1.10"/>
    <category term="cpe:/a:tor:tor:0.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.11"/>
    <category term="cpe:/a:tor:tor:0.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.2"/>
    <category term="cpe:/a:tor:tor:0.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.3"/>
    <category term="cpe:/a:tor:tor:0.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.4"/>
    <category term="cpe:/a:tor:tor:0.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.5"/>
    <category term="cpe:/a:tor:tor:0.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.6"/>
    <category term="cpe:/a:tor:tor:0.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.7"/>
    <category term="cpe:/a:tor:tor:0.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.8"/>
    <category term="cpe:/a:tor:tor:0.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.1.9"/>
    <category term="cpe:/a:tor:tor:0.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.10"/>
    <category term="cpe:/a:tor:tor:0.1.2.11"/>
    <category term="cpe:/a:tor:tor:0.1.2.12"/>
    <category term="cpe:/a:tor:tor:0.1.2.13"/>
    <category term="cpe:/a:tor:tor:0.1.2.14"/>
    <category term="cpe:/a:tor:tor:0.1.2.15"/>
    <category term="cpe:/a:tor:tor:0.1.2.16"/>
    <category term="cpe:/a:tor:tor:0.1.2.17"/>
    <category term="cpe:/a:tor:tor:0.1.2.18"/>
    <category term="cpe:/a:tor:tor:0.1.2.19"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.1:alpha-cvs"/>
    <category term="cpe:/a:tor:tor:0.1.2.2"/>
    <category term="cpe:/a:tor:tor:0.1.2.30"/>
    <category term="cpe:/a:tor:tor:0.1.2.31"/>
    <category term="cpe:/a:tor:tor:0.1.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.4"/>
    <category term="cpe:/a:tor:tor:0.1.2.5"/>
    <category term="cpe:/a:tor:tor:0.1.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.1.2.8:beta"/>
    <category term="cpe:/a:tor:tor:0.1.2.9"/>
    <category term="cpe:/a:tor:tor:0.2.0.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.21:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.22:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.23:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.24:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.25:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.26:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.27:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.28:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.29"/>
    <category term="cpe:/a:tor:tor:0.2.0.29:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.30"/>
    <category term="cpe:/a:tor:tor:0.2.0.30:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.31"/>
    <category term="cpe:/a:tor:tor:0.2.0.31:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.32:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.33"/>
    <category term="cpe:/a:tor:tor:0.2.0.34:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.35"/>
    <category term="cpe:/a:tor:tor:0.2.0.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.0.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.12"/>
    <category term="cpe:/a:tor:tor:0.2.1.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.13"/>
    <category term="cpe:/a:tor:tor:0.2.1.14"/>
    <category term="cpe:/a:tor:tor:0.2.1.15"/>
    <category term="cpe:/a:tor:tor:0.2.1.16"/>
    <category term="cpe:/a:tor:tor:0.2.1.17"/>
    <category term="cpe:/a:tor:tor:0.2.1.18"/>
    <category term="cpe:/a:tor:tor:0.2.1.19"/>
    <category term="cpe:/a:tor:tor:0.2.1.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.20"/>
    <category term="cpe:/a:tor:tor:0.2.1.21"/>
    <category term="cpe:/a:tor:tor:0.2.1.22"/>
    <category term="cpe:/a:tor:tor:0.2.1.23"/>
    <category term="cpe:/a:tor:tor:0.2.1.24"/>
    <category term="cpe:/a:tor:tor:0.2.1.25"/>
    <category term="cpe:/a:tor:tor:0.2.1.26"/>
    <category term="cpe:/a:tor:tor:0.2.1.27"/>
    <category term="cpe:/a:tor:tor:0.2.1.28"/>
    <category term="cpe:/a:tor:tor:0.2.1.29"/>
    <category term="cpe:/a:tor:tor:0.2.1.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.1.9:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1"/>
    <category term="cpe:/a:tor:tor:0.2.2.10:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.11:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.12:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.13:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.14:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.15:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.16:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.17:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.18:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.19:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.1:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.2"/>
    <category term="cpe:/a:tor:tor:0.2.2.20:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.23:alpha and previous versions"/>
    <category term="cpe:/a:tor:tor:0.2.2.2:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.3"/>
    <category term="cpe:/a:tor:tor:0.2.2.3:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.4"/>
    <category term="cpe:/a:tor:tor:0.2.2.4:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.5"/>
    <category term="cpe:/a:tor:tor:0.2.2.5:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.6"/>
    <category term="cpe:/a:tor:tor:0.2.2.6:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.7:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.8:alpha"/>
    <category term="cpe:/a:tor:tor:0.2.2.9:alpha"/>
    <sec:identifier>CVE-2011-4896</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4780:phpmyadmin: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4780_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4780_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4780_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4780_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.0.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.1.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.2.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.1"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.2"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.4.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.5.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.6.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.7.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.8.0"/>
    <sec:identifier>CVE-2011-4780</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4782:phpmyadmin: Cross-site scripting (XSS) vulnerability in librari...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4782_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4782_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4782_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4782_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.0.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.1.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.2.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.1"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.2"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.4.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.5.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.6.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.7.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.8.0"/>
    <sec:identifier>CVE-2011-4782</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4634:phpmyadmin: Multiple cross-site scripting (XSS) vulnerabilities...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4634_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4634_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4634_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-23T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted col...&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4634_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.0.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.1.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.2.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.1"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.3.2"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.4.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.5.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.6.0"/>
    <category term="cpe:/a:phpmyadmin:phpmyadmin:3.4.7.0"/>
    <sec:identifier>CVE-2011-4634</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003503:Mac OS X &#19978;&#12391;&#31292;&#20685;&#12377;&#12427; Mozilla Firefox &#12362;&#12424;&#12403; Thunderbird &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#21046;&#38480;&#12434;&#22238;&#36991;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003503_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003503_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003503_AD_1.html</id>
    <published>2011-12-22T15:43:41+09:00</published>
    <updated>2011-12-22T15:43:41+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Mac OS X 上で稼働する Mozilla Firefox および Thunderbird は、.jar ファイルを実行可能なファイルとして見なさないため、アクセス制限を回避される脆弱性が存在します。 本脆弱性は Mac OS X 上での CVE-2011-2372 の不正確な修正に起因する脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003503_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003503</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003502:&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003502_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003502_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003502_AD_1.html</id>
    <published>2011-12-22T15:43:14+09:00</published>
    <updated>2011-12-22T15:43:14+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Mozilla 製品には、サービス運用妨害 (アプリケーションクラッシュ) 状態となる、またはその他の詳細不明な影響を受ける脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003502_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003502</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003501:Mac OS X &#19978;&#12391;&#31292;&#20685;&#12377;&#12427;&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003501_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003501_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003501_AD_1.html</id>
    <published>2011-12-22T15:42:34+09:00</published>
    <updated>2011-12-22T15:42:34+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Mac OS X 上で稼働する複数の Mozilla 製品は、プラグインによる特定の DOM フレームの削除を適切に処理しないため、サービス運用妨害 (不正なポインタデリファレンスおよびアプリケーションクラッシュ) 状態となる、またはその他の詳細不明な影響を受ける脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003501_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003501</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003500:&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12461;&#12540;&#20837;&#21147;&#12434;&#12461;&#12515;&#12503;&#12481;&#12515;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003500_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003500_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003500_AD_1.html</id>
    <published>2011-12-22T15:42:08+09:00</published>
    <updated>2011-12-22T15:42:08+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Mozilla 製品には、Web ページ上でのキー入力をキャプチャされる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003500_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003500</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003499:&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12391;&#20351;&#29992;&#12373;&#12428;&#12427; YARR &#27491;&#35215;&#34920;&#29694;&#12521;&#12452;&#12502;&#12521;&#12522;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003499_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003499_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003499_AD_1.html</id>
    <published>2011-12-22T15:41:36+09:00</published>
    <updated>2011-12-22T15:41:36+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Mozilla 製品で使用される YARR 正規表現ライブラリには、サービス運用妨害 (アプリケーションクラッシュ) 状態となる、または任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003499_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003499</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003498:&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12398;&#12502;&#12521;&#12454;&#12470;&#12456;&#12531;&#12472;&#12531;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003498_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003498_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003498_AD_1.html</id>
    <published>2011-12-22T15:41:11+09:00</published>
    <updated>2011-12-22T15:41:11+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Mozilla 製品のブラウザエンジンには、サービス運用妨害 (メモリ破損およびアプリケーションクラッシュ) 状態となる、または任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003498_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003498</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003497:&#35079;&#25968;&#12398; Mozilla &#35069;&#21697;&#12398; SVG &#23455;&#35013;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003497_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003497_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003497_AD_1.html</id>
    <published>2011-12-22T15:40:43+09:00</published>
    <updated>2011-12-22T15:40:43+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
複数の Mozilla 製品の SVG 実装は、DOMAttrModified イベントハンドラを適切に処理しないため、サービス運用妨害 (領域外メモリアクセス) 状態となる、または詳細不明な影響を受ける脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003497_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:mozilla:seamonkey"/>
    <category term="cpe:/a:mozilla:thunderbird"/>
    <sec:identifier>JVNDB-2011-003497</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2010-002873:RIM BlackBerry Desktop Software &#12395;&#12362;&#12369;&#12427; .ipd &#12501;&#12449;&#12452;&#12523;&#12434;&#24489;&#21495;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002873_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002873_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002873_AD_1.html</id>
    <published>2011-12-22T12:06:04+09:00</published>
    <updated>2011-12-22T12:06:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research In Motion (RIM) BlackBerry Desktop Software のオフラインバックアップメカニズムは、PBKDF2 の単一反復を使用するため、.ipd ファイルを復号される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002873_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_desktop_software"/>
    <sec:identifier>JVNDB-2010-002873</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002701:RIM BlackBerry Enterprise Server &#12362;&#12424;&#12403; BlackBerry Professional Software &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002701_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002701_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002701_AD_1.html</id>
    <published>2011-12-22T12:05:12+09:00</published>
    <updated>2011-12-22T12:05:12+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research In Motion (RIM) BlackBerry Enterprise Server (BES) および BlackBerry Professional Software の Attachment Service コンポーネント内にある PDF Distiller には、サービス運用妨害 (メモリ破損) 状態となる、または任意のコードを実行される脆弱性が存在します。 本脆弱性は、CVE-2008-3246、CVE-2009-0176、CVE-2009-0219、CVE-2009-2643、および CVE-2009-2646 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002701_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_enterprise_server"/>
    <category term="cpe:/a:rim:blackberry_professional_software"/>
    <sec:identifier>JVNDB-2009-002701</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002700:BlackBerry 8800 &#19978;&#12398; RIM BlackBerry Browser &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002700_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002700_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002700_AD_1.html</id>
    <published>2011-12-22T12:04:36+09:00</published>
    <updated>2011-12-22T12:04:36+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
BlackBerry 8800 上の Research In Motion (RIM) BlackBerry Browser には、サービス運用妨害 (アプリケーションハング) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002700_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_browser"/>
    <category term="cpe:/h:rim:blackberry_8800"/>
    <sec:identifier>JVNDB-2009-002700</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-000107:PukiWiki Plus! &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000107_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000107_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000107_AD_1.html</id>
    <published>2011-12-22T12:03:57+09:00</published>
    <updated>2011-12-22T12:03:57+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
PukiWiki Plus! には、クロスサイトスクリプティングの脆弱性が存在します。  PukiWiki Plus! には、フォームに入力された文字列をウェブページに出力する際の処理に問題があり、クロスサイトスクリプティングの脆弱性が存在します。  この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方が IPA に報告し、JPCERT/CC が開発者との調整を行いました。 報告者: 慶應義塾大学武田圭史研究室 中安　恒樹 氏&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000107_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:misc:pukiwiki_plus_pukiwiki_plus"/>
    <sec:identifier>JVNDB-2011-000107</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-000106:Apache Struts &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000106_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000106_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000106_AD_1.html</id>
    <published>2011-12-22T12:01:17+09:00</published>
    <updated>2011-12-22T12:01:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Apache Struts には、クロスサイトスクリプティングの脆弱性が存在するウェブアプリケーションを作り出す問題があります。  Apache Software Foundation が提供する Apache Struts は、Java のウェブアプリケーションを開発するためのソフトウェアフレームワークです。 Apache Struts には、クロスサイトスクリプティングの脆弱性が存在するウェブアプリケーションを作り出す問題があります。  この脆弱性情報は、情報セキュリティ早期警戒パートナーシップに基づき下記の方が IPA に報告し、JPCERT/CC が開発者との調整を行いました。 報告者: 株式会社ユービーセキュア 杉山 俊春 氏&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-000106_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:apache:struts"/>
    <sec:identifier>JVNDB-2011-000106</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002699:RIM BlackBerry Device Software &#12398; Blackberry Browser &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398; SSL &#12469;&#12540;&#12496;&#12395;&#12394;&#12426;&#12377;&#12414;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002699_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002699_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002699_AD_1.html</id>
    <published>2011-12-22T11:59:43+09:00</published>
    <updated>2011-12-22T11:59:43+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
RIM BlackBerry Device Software の Blackberry Browser は、X.509 証明書のサブジェクトの Common Name (CN) フィールド内のドメイン名に '\0' 文字を含む &quot;hidden&quot; 文字を適切に処理しないため、任意の SSL サーバになりすまされる脆弱性が存在します。 本問題は、CVE-2009-2408 と関連する問題です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002699_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_device_software"/>
    <sec:identifier>JVNDB-2009-002699</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002698:BlackBerry Desktop Manager &#29992;&#12398; RIM Lotus Notes &#12467;&#12493;&#12463;&#12479;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002698_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002698_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002698_AD_1.html</id>
    <published>2011-12-22T11:58:38+09:00</published>
    <updated>2011-12-22T11:58:38+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
BlackBerry Desktop Manager 用の Research In Motion (RIM) Lotus Notes コネクタの lnresobject.dll にある特定の ActiveX コントロールには、サービス運用妨害 (Internet Explorer クラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002698_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ibm:lotus_notes_connector"/>
    <category term="cpe:/a:rim:blackberry_desktop_manager"/>
    <sec:identifier>JVNDB-2009-002698</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002697:RIM BlackBerry Enterprise Server &#12362;&#12424;&#12403; BlackBerry Professional Software &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002697_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002697_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002697_AD_1.html</id>
    <published>2011-12-22T11:55:15+09:00</published>
    <updated>2011-12-22T11:55:15+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research In Motion (RIM) BlackBerry Enterprise Server (BES) および BlackBerry Professional Software 内の Attachment Service コンポーネントの PDF Distiller には、サービス運用妨害 (メモリ破損) 状態となる、または任意のコードを実行される脆弱性が存在します。 本脆弱性は、CVE-2008-3246 および CVE-2009-0219 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002697_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_enterprise_server"/>
    <category term="cpe:/a:rim:blackberry_professional_software"/>
    <sec:identifier>JVNDB-2009-002697</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002696:RIM BlackBerry Enterprise Server &#12362;&#12424;&#12403; BlackBerry Professional Software &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002696_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002696_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002696_AD_1.html</id>
    <published>2011-12-22T11:54:04+09:00</published>
    <updated>2011-12-22T11:54:04+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research In Motion (RIM) BlackBerry Enterprise Server (BES) および BlackBerry Professional Software 内の Attachment Service コンポーネントの PDF Distiller には、サービス運用妨害 (メモリ破損) 状態となる、または任意のコードを実行される脆弱性が存在します。 本脆弱性は、CVE-2008-3246 および CVE-2009-0219 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002696_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_enterprise_server"/>
    <category term="cpe:/a:rim:blackberry_professional_software"/>
    <sec:identifier>JVNDB-2009-002696</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002695:RIM BlackBerry 8800 &#12395;&#12362;&#12369;&#12427;&#36939;&#29992;&#22952;&#23475; (&#12513;&#12514;&#12522;&#28040;&#36027;&#12362;&#12424;&#12403;&#12502;&#12521;&#12454;&#12470;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002695_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002695_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002695_AD_1.html</id>
    <published>2011-12-22T11:53:09+09:00</published>
    <updated>2011-12-22T11:53:09+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research In Motion (RIM) BlackBerry 8800 には、サービス運用妨害 (メモリ消費およびブラウザクラッシュ) 状態となる脆弱性が存在します。 本問題は、CVE-2009-1692 に関連する可能性があります。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002695_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:rim:blackberry_8800"/>
    <sec:identifier>JVNDB-2009-002695</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002694:&#35079;&#25968;&#12398; RIM BlackBerry &#35069;&#21697;&#12398; PDF distiller &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002694_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002694_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002694_AD_1.html</id>
    <published>2011-12-22T11:51:19+09:00</published>
    <updated>2011-12-22T11:51:19+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research in Motion (RIM) BlackBerry Enterprise Server (BES)、BlackBerry Professional Software、および BlackBerry Unite! の Attachment Service 内にある PDF distiller は、初期化されていないポインタ上で delete 操作を実行するため、任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002694_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:research_in_motion_limited:blackberry_enterprise_server"/>
    <category term="cpe:/a:research_in_motion_limited:blackberry_professional_software"/>
    <category term="cpe:/a:research_in_motion_limited:blackberry_unite"/>
    <sec:identifier>JVNDB-2009-002694</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2009-002693:&#35079;&#25968;&#12398; RIM BlackBerry &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002693_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002693_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002693_AD_1.html</id>
    <published>2011-12-22T11:50:30+09:00</published>
    <updated>2011-12-22T11:50:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Research in Motion (RIM) BlackBerry Enterprise Server (BES)、BlackBerry Professional Software、および BlackBerry Unite! の Attachment Service 内の PDF Distiller には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2009-002693_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rim:blackberry_enterprise_server"/>
    <category term="cpe:/a:rim:blackberry_professional_software"/>
    <category term="cpe:/a:rim:blackberry_unite"/>
    <sec:identifier>JVNDB-2009-002693</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003496:Control Microsystems ClearSCADA &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003496_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003496_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003496_AD_1.html</id>
    <published>2011-12-22T11:49:33+09:00</published>
    <updated>2011-12-22T11:49:33+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Control Microsystems ClearSCADA および Serck Control SCX にて使用される ClearSCADA には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003496_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:controlmicrosystems:clearscada_2005"/>
    <category term="cpe:/a:controlmicrosystems:clearscada_2007"/>
    <category term="cpe:/a:controlmicrosystems:clearscada_2009"/>
    <category term="cpe:/a:serck-controls:scx"/>
    <sec:identifier>JVNDB-2011-003496</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003495:Control Microsystems ClearSCADA &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003495_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003495_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003495_AD_1.html</id>
    <published>2011-12-22T11:34:27+09:00</published>
    <updated>2011-12-22T11:34:27+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Control Microsystems ClearSCADA および Serck Control SCX にて使用される ClearSCADA には、サービス運用妨害 (クラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003495_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:controlmicrosystems:clearscada_2005"/>
    <category term="cpe:/a:controlmicrosystems:clearscada_2007"/>
    <category term="cpe:/a:controlmicrosystems:clearscada_2009"/>
    <category term="cpe:/a:serck-controls:scx"/>
    <sec:identifier>JVNDB-2011-003495</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003494:WellinTech KingView &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003494_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003494_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003494_AD_1.html</id>
    <published>2011-12-22T11:29:17+09:00</published>
    <updated>2011-12-22T11:29:17+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
WellinTech KingView の KVWebSvr.dll 内にある ActiveX コントロールには、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003494_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:wellintek:kingview"/>
    <sec:identifier>JVNDB-2011-003494</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003493:Invensys Wonderware InBatch &#12398;  ActiveX &#12467;&#12531;&#12488;&#12525;&#12540;&#12523;&#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003493_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003493_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003493_AD_1.html</id>
    <published>2011-12-22T11:25:06+09:00</published>
    <updated>2011-12-22T11:25:06+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Invensys Wonderware InBatch の InBatch BatchField ActiveX コントロールには、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003493_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:invensys:wonderware_inbatch"/>
    <sec:identifier>JVNDB-2011-003493</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003492:Progea Movicon &#12398; TCPUploadServer.exe &#12395;&#12362;&#12369;&#12427;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003492_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003492_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003492_AD_1.html</id>
    <published>2011-12-22T11:22:58+09:00</published>
    <updated>2011-12-22T11:22:58+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Progea Movicon の TCPUploadServer.exe は、重要な関数に対して認証を要求しないため、重要な情報を取得される、ファイルを消去される、任意のプログラムを実行される、またはサービス運用妨害 (クラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003492_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:progea:movicon"/>
    <sec:identifier>JVNDB-2011-003492</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003491:Invensys Wonderware Information Server &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003491_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003491_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003491_AD_1.html</id>
    <published>2011-12-22T11:20:57+09:00</published>
    <updated>2011-12-22T11:20:57+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Invensys Wonderware Information Server には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003491_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:invensys:wonderware_information_server"/>
    <sec:identifier>JVNDB-2011-003491</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003490:Sunway pNetPower &#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003490_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003490_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003490_AD_1.html</id>
    <published>2011-12-22T11:08:08+09:00</published>
    <updated>2011-12-22T11:08:08+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Sunway pNetPower の AngelServer.exe 6.0.11.3 には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003490_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sunwayland:pnetpower"/>
    <sec:identifier>JVNDB-2011-003490</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003489:Sunway ForceControl &#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003489_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003489_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003489_AD_1.html</id>
    <published>2011-12-22T11:07:12+09:00</published>
    <updated>2011-12-22T11:07:12+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Sunway ForceControl の httpsvr.exe 6.0.5.3 には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003489_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sunwayland:forcecontrol"/>
    <sec:identifier>JVNDB-2011-003489</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003488:7-Technologies Interactive Graphical SCADA System &#12395;&#12362;&#12369;&#12427;&#12473;&#12479;&#12483;&#12463;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003488_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003488_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003488_AD_1.html</id>
    <published>2011-12-22T11:02:52+09:00</published>
    <updated>2011-12-22T11:02:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
7-Technologies Interactive Graphical SCADA System (IGSS) の Open Database Connectivity (ODBC) service (Odbcixv9se.exe) には、スタックベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003488_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss"/>
    <sec:identifier>JVNDB-2011-003488</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003487:Ecava IntegraXor &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003487_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003487_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003487_AD_1.html</id>
    <published>2011-12-22T11:02:01+09:00</published>
    <updated>2011-12-22T11:02:01+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Ecava IntegraXor には、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003487_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:ecava:integraxor"/>
    <sec:identifier>JVNDB-2011-003487</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003486:Rockwell Automation FactoryTalk Diagnostics Viewer &#12395;&#12362;&#12369;&#12427;&#20219;&#24847;&#12398;&#12467;&#12540;&#12489;&#12434;&#23455;&#34892;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003486_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003486_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003486_AD_1.html</id>
    <published>2011-12-22T11:01:27+09:00</published>
    <updated>2011-12-22T11:01:27+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Rockwell Automation FactoryTalk Diagnostics Viewer には任意のコードを実行される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003486_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rockwellautomation:factorytalk_diagnostics_viewer"/>
    <sec:identifier>JVNDB-2011-003486</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003485:AzeoTech DAQFactory &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003485_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003485_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003485_AD_1.html</id>
    <published>2011-12-22T11:00:50+09:00</published>
    <updated>2011-12-22T11:00:50+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
AzeoTech DAQFactory は、特定のシグナルに対して認証を実行しないため、サービス運用妨害 (システム再起動またはシャットダウン) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003485_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:azeotech:daqfactory"/>
    <sec:identifier>JVNDB-2011-003485</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003484:Rockwell Automation RSLinx Classic &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003484_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003484_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003484_AD_1.html</id>
    <published>2011-12-22T11:00:11+09:00</published>
    <updated>2011-12-22T11:00:11+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Rockwell Automation RSLinx Classic の EDS Hardware Installation Tool 内の RSHWare.exe における RSEds.dll には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003484_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:rockwellautomation:rslinx_classic"/>
    <category term="cpe:/a:rockwellautomation:rslinx_classic_eds_hardware_installation_tool"/>
    <sec:identifier>JVNDB-2011-003484</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2010-002872:Invensys Wonderware InBatch &#12398; lm_tcp service &#12395;&#12362;&#12369;&#12427;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002872_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002872_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002872_AD_1.html</id>
    <published>2011-12-22T10:54:13+09:00</published>
    <updated>2011-12-22T10:54:13+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Invensys Foxboro の I/A シリーズバッチ､およびその他の製品で使用される Invensys Wonderware InBatch の lm_tcp service には、バッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2010-002872_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:invensys:foxboro_i%2Fa_series_batch"/>
    <category term="cpe:/a:invensys:wonderware_inbatch"/>
    <sec:identifier>JVNDB-2010-002872</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4453:pmwiki: The PageListSort function in scripts/pagelist.php i...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4453_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4453_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4453_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-22T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4453_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.0"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.1"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.10"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.11"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.12"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.13"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.2"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.3"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.4"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.5"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.6"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.7"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.8"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.0.9"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.0"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.1"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.10"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.11"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.12"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.13"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.14"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.15"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.16"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.17"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.18"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.19"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.2"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.20"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.21"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.22"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.23"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.24"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.25"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.26"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.27"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.3"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.4"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.5"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.6"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.7"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.8"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.1.9"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta1"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta10"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta11"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta12"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta13"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta14"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta15"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta16"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta17"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta18"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta19"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta2"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta20"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta21"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta22"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta23"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta24"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta25"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta26"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta27"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta28"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta29"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta3"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta30"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta31"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta32"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta33"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta34"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta35"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta36"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta37"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta38"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta39"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta4"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta40"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta41"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta42"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta43"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta44"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta45"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta46"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta47"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta48"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta49"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta5"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta50"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta51"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta52"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta53"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta54"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta55"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta56"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta57"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta58"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta59"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta6"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta60"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta61"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta62"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta63"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta64"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta65"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta66"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta67"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta68"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta7"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta8"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.0:beta9"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.1"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.10"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.11"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.12"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.13"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.14"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.15"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.16"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.17"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.18"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.19"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.2"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.20"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.21"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.22"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.23"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.24"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.25"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.26"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.27"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.28"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.29"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.3"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.30"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.32"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.33"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.34"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.4"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.5"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.6"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.7"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.8"/>
    <category term="cpe:/a:pmwiki:pmwiki:2.2.9"/>
    <sec:identifier>CVE-2011-4453</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4037:winlog_lite, winlog_pro: Buffer overflow in Sielco Sistemi Winlog PRO before...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4037_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4037_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4037_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-22T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Buffer overflow in Sielco Sistemi Winlog PRO before 2.07.09 and Winlog Lite before 2.07.09 allows user-assisted remote attackers to execute arbitrary code via invalid data in unspecified fields of a project file.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4037_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.00"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.03"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.04"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.06"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.09"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.10"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.12"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.13"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.14"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.18"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.21"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.24"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.25"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.28"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.40"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.46"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.50"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.60"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.73"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.06.86"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.07.00"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.07.01"/>
    <category term="cpe:/a:sielcosistemi:winlog_lite:2.07.08 and previous versions"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.00"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.03"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.04"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.06"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.09"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.10"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.12"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.13"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.14"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.18"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.21"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.24"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.25"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.28"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.40"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.46"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.50"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.60"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.73"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.06.86"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.07.00"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.07.01"/>
    <category term="cpe:/a:sielcosistemi:winlog_pro:2.07.08 and previous versions"/>
    <sec:identifier>CVE-2011-4037</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-4203:moodle: CRLF injection vulnerability in calendar/set.php in...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4203_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4203_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4203_AD_1.html</id>
    <published>2011-12-22T00:00:00+09:00</published>
    <updated>2011-12-22T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-4203_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:moodle:moodle:1.9"/>
    <category term="cpe:/a:moodle:moodle:1.9.1"/>
    <category term="cpe:/a:moodle:moodle:1.9.10"/>
    <category term="cpe:/a:moodle:moodle:1.9.11"/>
    <category term="cpe:/a:moodle:moodle:1.9.12"/>
    <category term="cpe:/a:moodle:moodle:1.9.13"/>
    <category term="cpe:/a:moodle:moodle:1.9.14"/>
    <category term="cpe:/a:moodle:moodle:1.9.2"/>
    <category term="cpe:/a:moodle:moodle:1.9.3"/>
    <category term="cpe:/a:moodle:moodle:1.9.4"/>
    <category term="cpe:/a:moodle:moodle:1.9.5"/>
    <category term="cpe:/a:moodle:moodle:1.9.6"/>
    <category term="cpe:/a:moodle:moodle:1.9.7"/>
    <category term="cpe:/a:moodle:moodle:1.9.8"/>
    <category term="cpe:/a:moodle:moodle:1.9.9"/>
    <category term="cpe:/a:moodle:moodle:2.0"/>
    <category term="cpe:/a:moodle:moodle:2.0.1"/>
    <category term="cpe:/a:moodle:moodle:2.0.2"/>
    <category term="cpe:/a:moodle:moodle:2.0.3"/>
    <category term="cpe:/a:moodle:moodle:2.0.4"/>
    <category term="cpe:/a:moodle:moodle:2.0.5"/>
    <category term="cpe:/a:moodle:moodle:2.1"/>
    <category term="cpe:/a:moodle:moodle:2.1.1"/>
    <category term="cpe:/a:moodle:moodle:2.1.2"/>
    <category term="cpe:/a:moodle:moodle:2.2"/>
    <sec:identifier>CVE-2011-4203</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003483:Unbound &#12398; validator/val_nsec3.c &#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12487;&#12540;&#12514;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003483_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003483_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003483_AD_1.html</id>
    <published>2011-12-21T15:48:03+09:00</published>
    <updated>2011-12-21T15:48:03+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Unbound の validator/val_nsec3.c は、NSEC3-signed ゾーンの検証処理を適切に行わないため、サービス運用妨害 (デーモンクラッシュ) 状態となる脆弱性が存在します。 本脆弱性は、CVE-2011-4528 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003483_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:nlnetlabs:unbound"/>
    <sec:identifier>JVNDB-2011-003483</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003482:Unbound &#12395;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (DoS) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003482_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003482_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003482_AD_1.html</id>
    <published>2011-12-21T15:38:12+09:00</published>
    <updated>2011-12-21T15:38:12+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Unbound には、複数のサービス運用妨害 (DoS) の脆弱性が存在します。  詳しくは、NLnet Labsが提供する情報 をご確認ください。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003482_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:nlnetlabs:unbound"/>
    <sec:identifier>JVNDB-2011-003482</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003481:D-Link DIR-300 &#12523;&#12540;&#12479;&#12395;&#12362;&#12369;&#12427;&#37325;&#35201;&#12394;&#24773;&#22577;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003481_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003481_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003481_AD_1.html</id>
    <published>2011-12-21T15:36:51+09:00</published>
    <updated>2011-12-21T15:36:51+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
D-Link DIR-300 ルータは、パスワードを平文で保存するため、重要な情報を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003481_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:d-link:dir-300"/>
    <sec:identifier>JVNDB-2011-003481</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003480:zFTPServer Suite &#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003480_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003480_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003480_AD_1.html</id>
    <published>2011-12-21T15:32:12+09:00</published>
    <updated>2011-12-21T15:32:12+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
zFTPServer Suite には、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003480_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:zftpserver:zftpserver_suite"/>
    <sec:identifier>JVNDB-2011-003480</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003479:NOE 771 &#12487;&#12496;&#12452;&#12473;&#19978;&#12398; Schneider Electric Quantum Ethernet Module &#12395;&#12362;&#12369;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003479_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003479_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003479_AD_1.html</id>
    <published>2011-12-21T15:30:59+09:00</published>
    <updated>2011-12-21T15:30:59+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
NOE 771 デバイス上で動作する Schneider Electric Quantum Ethernet Module の modbus_125_handler 関数には、任意のファームウェアアップデートをインストールされる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003479_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77100"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77101"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77110"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77111"/>
    <sec:identifier>JVNDB-2011-003479</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003478:NOE 771 &#12487;&#12496;&#12452;&#12473;&#19978;&#12398; Schneider Electric Quantum Ethernet Module &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#27177;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003478_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003478_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003478_AD_1.html</id>
    <published>2011-12-21T15:29:06+09:00</published>
    <updated>2011-12-21T15:29:06+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
NOE 771 デバイス上で動作する Schneider Electric Quantum Ethernet Module の ComputePassword 関数は、MAC アドレスの計算処理により fwupgrade アカウント用のパスワードを作成するため、アクセス権を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003478_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77100"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77101"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77110"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77111"/>
    <sec:identifier>JVNDB-2011-003478</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003477:Schneider Electric Quantum Ethernet Module &#12395;&#12362;&#12369;&#12427;&#12450;&#12463;&#12475;&#12473;&#27177;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003477_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003477_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003477_AD_1.html</id>
    <published>2011-12-21T15:28:15+09:00</published>
    <updated>2011-12-21T15:28:15+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Quantum 140NOE771 および 140CPU65 モジュール、Premium TSXETY および TSXP57 モジュール、M340 BMXNOE01 および BMXP3420 モジュール、STB DIO STBNIC2212 および STBNIP2 モジュール内で利用される Schneider Electric Quantum Ethernet Module は、(1) AUTCSE、(2) AUT_CSE、(3) fdrusers、(4) ftpuser、(5) loader、(6) nic2212、(7) nimrohs2212、(8) nip2212、(9) noe77111_v500、(10) ntpupdate、(11) pcfactory、(12) sysdiag、(13) target、(14) test、 (15) USER、および (16) webserver アカウント用の ハードコードされたパスワードを使用するため、アクセス権を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003477_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:schneider-electric:m340_ethernet_module_bmxnoe0100"/>
    <category term="cpe:/a:schneider-electric:m340_ethernet_module_bmxnoe0110"/>
    <category term="cpe:/a:schneider-electric:m340_ethernet_module_bmxp342020"/>
    <category term="cpe:/a:schneider-electric:m340_ethernet_module_bmxp342030"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxety4103"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxety5103"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp57163m"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp572634m"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp573634m"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp574634m"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp575634m"/>
    <category term="cpe:/a:schneider-electric:premium_ethernet_module_tsxp576634m"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140cpu65150"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140cpu65160"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140cpu65260"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77100"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77101"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77110"/>
    <category term="cpe:/a:schneider-electric:quantum_ethernet_module_140noe77111"/>
    <category term="cpe:/a:schneider-electric:stb_dio_ethernet_module_stbnic2212"/>
    <category term="cpe:/a:schneider-electric:stb_dio_ethernet_module_stbnip2212"/>
    <category term="cpe:/a:schneider-electric:stb_dio_ethernet_module_stbnip2311"/>
    <sec:identifier>JVNDB-2011-003477</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003476:Winamp &#12398; in_mod.dll &#12503;&#12521;&#12464;&#12452;&#12531;&#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003476_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003476_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003476_AD_1.html</id>
    <published>2011-12-21T15:27:07+09:00</published>
    <updated>2011-12-21T15:27:07+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Winamp の in_mod.dll プラグインには、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003476_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:nullsoft:winamp"/>
    <sec:identifier>JVNDB-2011-003476</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003475:HomeSeer HS2 &#12398; Web &#12452;&#12531;&#12479;&#12540;&#12501;&#12455;&#12540;&#12473;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12522;&#12463;&#12456;&#12473;&#12488;&#12501;&#12457;&#12540;&#12472;&#12455;&#12522;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003475_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003475_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003475_AD_1.html</id>
    <published>2011-12-21T15:25:39+09:00</published>
    <updated>2011-12-21T15:25:39+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HomeSeer HS2 の Web インターフェースの /ctrl には、クロスサイトリクエストフォージェリの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003475_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:homeseer:homeseer_hs2"/>
    <sec:identifier>JVNDB-2011-003475</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003474:HomeSeer HS2 &#12398; Web &#12452;&#12531;&#12479;&#12540;&#12501;&#12455;&#12540;&#12473;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003474_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003474_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003474_AD_1.html</id>
    <published>2011-12-21T15:24:56+09:00</published>
    <updated>2011-12-21T15:24:56+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HomeSeer HS2 の Web インターフェースには、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003474_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:homeseer:homeseer_hs2"/>
    <sec:identifier>JVNDB-2011-003474</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003473:HomeSeer HS2 &#12398; Web &#12452;&#12531;&#12479;&#12540;&#12501;&#12455;&#12540;&#12473;&#12395;&#12362;&#12369;&#12427;&#12487;&#12451;&#12524;&#12463;&#12488;&#12522;&#12488;&#12521;&#12496;&#12540;&#12469;&#12523;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003473_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003473_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003473_AD_1.html</id>
    <published>2011-12-21T15:23:42+09:00</published>
    <updated>2011-12-21T15:23:42+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
HomeSeer HS2 の Web インターフェースには、ディレクトリトラバーサルの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003473_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:homeseer:homeseer_hs2"/>
    <sec:identifier>JVNDB-2011-003473</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003472:Pidgin &#12398; silc_channel_message &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003472_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003472_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003472_AD_1.html</id>
    <published>2011-12-21T15:22:30+09:00</published>
    <updated>2011-12-21T15:22:30+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Pidgin の libpurple 内にある SILC プロトコルプラグインの ops.c における silc_channel_message 関数は、メッセージデータにおける UTF-8 の検証を実行しないため、サービス運用妨害 (アプリケーションクラッシュ) 状態となる脆弱性が存在します。 本脆弱性は、CVE-2011-3594 とは異なる脆弱性です。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003472_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pidgin:pidgin"/>
    <sec:identifier>JVNDB-2011-003472</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003471:Pidgin &#12398; XMPP &#12503;&#12525;&#12488;&#12467;&#12523;&#12503;&#12521;&#12464;&#12452;&#12531;&#12395;&#12362;&#12369;&#12427;&#12469;&#12540;&#12499;&#12473;&#36939;&#29992;&#22952;&#23475; (&#12450;&#12503;&#12522;&#12465;&#12540;&#12471;&#12519;&#12531;&#12463;&#12521;&#12483;&#12471;&#12517;) &#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003471_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003471_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003471_AD_1.html</id>
    <published>2011-12-21T15:03:33+09:00</published>
    <updated>2011-12-21T15:03:33+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
Pidgin の libpurple 内の XMPP プロトコルプラグインは、(1) voice-chat および (2) video-chat スタンザ内の欠けたフィールドを適切に処理しないため、サービス運用妨害 (アプリケーションクラッシュ) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003471_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:pidgin:pidgin"/>
    <sec:identifier>JVNDB-2011-003471</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003470:JasPer &#12398; jpc_crg_getparms &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003470_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003470_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003470_AD_1.html</id>
    <published>2011-12-21T14:51:20+09:00</published>
    <updated>2011-12-21T14:51:20+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
JasPer の libjasper/jpc/jpc_cs.c 内の jpc_crg_getparms 関数には、特定のサイズ計算時に不適切なデータ型を使用するため、ヒープベースのバッファオーバーフローの誘発、および任意のコードを実行される、またはサービス運用妨害 (ヒープメモリ破損) 状態となる脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003470_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:jasper_project:jasper"/>
    <sec:identifier>JVNDB-2011-003470</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003469:JasPer &#12398; jpc_cox_getcompparms &#38306;&#25968;&#12395;&#12362;&#12369;&#12427;&#12498;&#12540;&#12503;&#12505;&#12540;&#12473;&#12398;&#12496;&#12483;&#12501;&#12449;&#12458;&#12540;&#12496;&#12540;&#12501;&#12525;&#12540;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003469_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003469_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003469_AD_1.html</id>
    <published>2011-12-21T14:37:52+09:00</published>
    <updated>2011-12-21T14:37:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
JasPer の libjasper/jpc/jpc_cs.c 内の jpc_cox_getcompparms 関数には、ヒープベースのバッファオーバーフローの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003469_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:jasper_project:jasper"/>
    <sec:identifier>JVNDB-2011-003469</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003468:EMC RSA SecurID Software Token &#12395;&#12362;&#12369;&#12427;&#27177;&#38480;&#12434;&#21462;&#24471;&#12373;&#12428;&#12427;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003468_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003468_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003468_AD_1.html</id>
    <published>2011-12-21T14:34:52+09:00</published>
    <updated>2011-12-21T14:34:52+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
EMC RSA SecurID Software Token には、検索パスに関する処理に不備があるため、権限を取得される脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003468_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/h:rsa:securid"/>
    <sec:identifier>JVNDB-2011-003468</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>JVNDB-2011-003467:&#35079;&#25968;&#12398; SafeNet &#35069;&#21697;&#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003467_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003467_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003467_AD_1.html</id>
    <published>2011-12-21T14:21:53+09:00</published>
    <updated>2011-12-21T14:21:53+09:00</updated>
    <author>
      <name>JVN iPedia</name>
    </author>
    <content type="html">
7 Technologies IGSS およびその他の製品で使用されている、SafeNet Sentinel HASP run-time installer および SafeNet Sentinel HASP SDK の、Admin Control Center には、Firefox で使用される際に、クロスサイトスクリプティングの脆弱性が存在します。&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/JVNiPedia_JVNDB-2011-003467_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:7t:igss"/>
    <category term="cpe:/a:mozilla:firefox"/>
    <category term="cpe:/a:safenet-inc:sentinel_hasp_run-time"/>
    <category term="cpe:/a:safenet-inc:sentinel_hasp_sdk"/>
    <sec:identifier>JVNDB-2011-003467</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3666:firefox, thunderbird: Mozilla Firefox before 3.6.25 and Thunderbird befor...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3666_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3666_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3666_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3666_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:0.1"/>
    <category term="cpe:/a:mozilla:firefox:0.10"/>
    <category term="cpe:/a:mozilla:firefox:0.10.1"/>
    <category term="cpe:/a:mozilla:firefox:0.2"/>
    <category term="cpe:/a:mozilla:firefox:0.3"/>
    <category term="cpe:/a:mozilla:firefox:0.4"/>
    <category term="cpe:/a:mozilla:firefox:0.5"/>
    <category term="cpe:/a:mozilla:firefox:0.6"/>
    <category term="cpe:/a:mozilla:firefox:0.6.1"/>
    <category term="cpe:/a:mozilla:firefox:0.7"/>
    <category term="cpe:/a:mozilla:firefox:0.7.1"/>
    <category term="cpe:/a:mozilla:firefox:0.8"/>
    <category term="cpe:/a:mozilla:firefox:0.9"/>
    <category term="cpe:/a:mozilla:firefox:0.9.1"/>
    <category term="cpe:/a:mozilla:firefox:0.9.2"/>
    <category term="cpe:/a:mozilla:firefox:0.9.3"/>
    <category term="cpe:/a:mozilla:firefox:0.9:rc"/>
    <category term="cpe:/a:mozilla:firefox:1.0"/>
    <category term="cpe:/a:mozilla:firefox:1.0.1"/>
    <category term="cpe:/a:mozilla:firefox:1.0.2"/>
    <category term="cpe:/a:mozilla:firefox:1.0.3"/>
    <category term="cpe:/a:mozilla:firefox:1.0.4"/>
    <category term="cpe:/a:mozilla:firefox:1.0.5"/>
    <category term="cpe:/a:mozilla:firefox:1.0.6"/>
    <category term="cpe:/a:mozilla:firefox:1.0.7"/>
    <category term="cpe:/a:mozilla:firefox:1.0.8"/>
    <category term="cpe:/a:mozilla:firefox:1.0:preview_release"/>
    <category term="cpe:/a:mozilla:firefox:1.4.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.10"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.11"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.12"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.2"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.3"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.4"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.6"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.7"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.8"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.9"/>
    <category term="cpe:/a:mozilla:firefox:1.5.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5.2"/>
    <category term="cpe:/a:mozilla:firefox:1.5.3"/>
    <category term="cpe:/a:mozilla:firefox:1.5.4"/>
    <category term="cpe:/a:mozilla:firefox:1.5.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.6"/>
    <category term="cpe:/a:mozilla:firefox:1.5.7"/>
    <category term="cpe:/a:mozilla:firefox:1.5.8"/>
    <category term="cpe:/a:mozilla:firefox:1.5:beta1"/>
    <category term="cpe:/a:mozilla:firefox:1.5:beta2"/>
    <category term="cpe:/a:mozilla:firefox:1.8"/>
    <category term="cpe:/a:mozilla:firefox:2.0"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.1"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.10"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.11"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.12"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.13"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.14"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.15"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.16"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.17"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.18"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.19"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.2"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.20"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.3"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.4"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.5"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.6"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.7"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.8"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.9"/>
    <category term="cpe:/a:mozilla:firefox:3.0"/>
    <category term="cpe:/a:mozilla:firefox:3.0.1"/>
    <category term="cpe:/a:mozilla:firefox:3.0.10"/>
    <category term="cpe:/a:mozilla:firefox:3.0.11"/>
    <category term="cpe:/a:mozilla:firefox:3.0.12"/>
    <category term="cpe:/a:mozilla:firefox:3.0.13"/>
    <category term="cpe:/a:mozilla:firefox:3.0.14"/>
    <category term="cpe:/a:mozilla:firefox:3.0.15"/>
    <category term="cpe:/a:mozilla:firefox:3.0.16"/>
    <category term="cpe:/a:mozilla:firefox:3.0.17"/>
    <category term="cpe:/a:mozilla:firefox:3.0.2"/>
    <category term="cpe:/a:mozilla:firefox:3.0.3"/>
    <category term="cpe:/a:mozilla:firefox:3.0.4"/>
    <category term="cpe:/a:mozilla:firefox:3.0.5"/>
    <category term="cpe:/a:mozilla:firefox:3.0.6"/>
    <category term="cpe:/a:mozilla:firefox:3.0.7"/>
    <category term="cpe:/a:mozilla:firefox:3.0.8"/>
    <category term="cpe:/a:mozilla:firefox:3.0.9"/>
    <category term="cpe:/a:mozilla:firefox:3.5"/>
    <category term="cpe:/a:mozilla:firefox:3.5.1"/>
    <category term="cpe:/a:mozilla:firefox:3.5.10"/>
    <category term="cpe:/a:mozilla:firefox:3.5.11"/>
    <category term="cpe:/a:mozilla:firefox:3.5.12"/>
    <category term="cpe:/a:mozilla:firefox:3.5.13"/>
    <category term="cpe:/a:mozilla:firefox:3.5.14"/>
    <category term="cpe:/a:mozilla:firefox:3.5.15"/>
    <category term="cpe:/a:mozilla:firefox:3.5.2"/>
    <category term="cpe:/a:mozilla:firefox:3.5.3"/>
    <category term="cpe:/a:mozilla:firefox:3.5.4"/>
    <category term="cpe:/a:mozilla:firefox:3.5.5"/>
    <category term="cpe:/a:mozilla:firefox:3.5.6"/>
    <category term="cpe:/a:mozilla:firefox:3.5.7"/>
    <category term="cpe:/a:mozilla:firefox:3.5.8"/>
    <category term="cpe:/a:mozilla:firefox:3.5.9"/>
    <category term="cpe:/a:mozilla:firefox:3.6"/>
    <category term="cpe:/a:mozilla:firefox:3.6.10"/>
    <category term="cpe:/a:mozilla:firefox:3.6.11"/>
    <category term="cpe:/a:mozilla:firefox:3.6.12"/>
    <category term="cpe:/a:mozilla:firefox:3.6.13"/>
    <category term="cpe:/a:mozilla:firefox:3.6.14"/>
    <category term="cpe:/a:mozilla:firefox:3.6.15"/>
    <category term="cpe:/a:mozilla:firefox:3.6.16"/>
    <category term="cpe:/a:mozilla:firefox:3.6.17"/>
    <category term="cpe:/a:mozilla:firefox:3.6.18"/>
    <category term="cpe:/a:mozilla:firefox:3.6.19"/>
    <category term="cpe:/a:mozilla:firefox:3.6.2"/>
    <category term="cpe:/a:mozilla:firefox:3.6.20"/>
    <category term="cpe:/a:mozilla:firefox:3.6.21"/>
    <category term="cpe:/a:mozilla:firefox:3.6.22"/>
    <category term="cpe:/a:mozilla:firefox:3.6.23"/>
    <category term="cpe:/a:mozilla:firefox:3.6.24 and previous versions"/>
    <category term="cpe:/a:mozilla:firefox:3.6.3"/>
    <category term="cpe:/a:mozilla:firefox:3.6.4"/>
    <category term="cpe:/a:mozilla:firefox:3.6.6"/>
    <category term="cpe:/a:mozilla:firefox:3.6.7"/>
    <category term="cpe:/a:mozilla:firefox:3.6.8"/>
    <category term="cpe:/a:mozilla:firefox:3.6.9"/>
    <category term="cpe:/a:mozilla:thunderbird:0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.1"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.2"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.3"/>
    <category term="cpe:/a:mozilla:thunderbird:0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.5:beta"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.7.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.7.3"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.13"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.15"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.20"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.10"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.10"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.11"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.12"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.13"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.14"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.15"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.16 and previous versions"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.2"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.3"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.4"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.5"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.6"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.7"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.8"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.9"/>
    <category term="cpe:/o:apple:mac_os_x"/>
    <sec:identifier>CVE-2011-3666</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3658:firefox, seamonkey, thunderbird: The SVG implementation in Mozilla Firefox 8.0, Thun...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3658_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3658_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3658_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3658_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:8.0"/>
    <category term="cpe:/a:mozilla:seamonkey:2.5"/>
    <category term="cpe:/a:mozilla:thunderbird:8.0"/>
    <sec:identifier>CVE-2011-3658</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3663:firefox, seamonkey, thunderbird: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 th...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3663_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3663_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3663_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page by using SVG animation accessKey events within that web page.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3663_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:4.0"/>
    <category term="cpe:/a:mozilla:firefox:4.0.1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta10"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta11"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta12"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta2"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta3"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta4"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta5"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta6"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta7"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta8"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta9"/>
    <category term="cpe:/a:mozilla:firefox:5.0"/>
    <category term="cpe:/a:mozilla:firefox:5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0"/>
    <category term="cpe:/a:mozilla:firefox:6.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0.2"/>
    <category term="cpe:/a:mozilla:firefox:7.0"/>
    <category term="cpe:/a:mozilla:firefox:7.0.1"/>
    <category term="cpe:/a:mozilla:firefox:8.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.99"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::dev"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.11"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.12"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.13"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.14"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.15"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.16"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.17"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.18"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.19"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.11"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.12"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.13"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.14"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1::pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.3.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.5 and previous versions"/>
    <category term="cpe:/a:mozilla:thunderbird:5.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:8.0"/>
    <sec:identifier>CVE-2011-3663</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3661:firefox, seamonkey, thunderbird: YARR, as used in Mozilla Firefox 4.x through 8.0, T...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3661_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3661_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3661_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3661_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:4.0"/>
    <category term="cpe:/a:mozilla:firefox:4.0.1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta10"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta11"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta12"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta2"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta3"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta4"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta5"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta6"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta7"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta8"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta9"/>
    <category term="cpe:/a:mozilla:firefox:5.0"/>
    <category term="cpe:/a:mozilla:firefox:5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0"/>
    <category term="cpe:/a:mozilla:firefox:6.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0.2"/>
    <category term="cpe:/a:mozilla:firefox:7.0"/>
    <category term="cpe:/a:mozilla:firefox:7.0.1"/>
    <category term="cpe:/a:mozilla:firefox:8.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.99"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::dev"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.11"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.12"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.13"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.14"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.15"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.16"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.17"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.18"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.19"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.11"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.12"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.13"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.14"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1::pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.3.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.5 and previous versions"/>
    <category term="cpe:/a:mozilla:thunderbird:5.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:8.0"/>
    <sec:identifier>CVE-2011-3661</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3664:firefox, seamonkey, thunderbird: Mozilla Firefox before 9.0, Thunderbird before 9.0,...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3664_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3664_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3664_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3664_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:0.1"/>
    <category term="cpe:/a:mozilla:firefox:0.10"/>
    <category term="cpe:/a:mozilla:firefox:0.10.1"/>
    <category term="cpe:/a:mozilla:firefox:0.2"/>
    <category term="cpe:/a:mozilla:firefox:0.3"/>
    <category term="cpe:/a:mozilla:firefox:0.4"/>
    <category term="cpe:/a:mozilla:firefox:0.5"/>
    <category term="cpe:/a:mozilla:firefox:0.6"/>
    <category term="cpe:/a:mozilla:firefox:0.6.1"/>
    <category term="cpe:/a:mozilla:firefox:0.7"/>
    <category term="cpe:/a:mozilla:firefox:0.7.1"/>
    <category term="cpe:/a:mozilla:firefox:0.8"/>
    <category term="cpe:/a:mozilla:firefox:0.9"/>
    <category term="cpe:/a:mozilla:firefox:0.9.1"/>
    <category term="cpe:/a:mozilla:firefox:0.9.2"/>
    <category term="cpe:/a:mozilla:firefox:0.9.3"/>
    <category term="cpe:/a:mozilla:firefox:0.9:rc"/>
    <category term="cpe:/a:mozilla:firefox:1.0"/>
    <category term="cpe:/a:mozilla:firefox:1.0.1"/>
    <category term="cpe:/a:mozilla:firefox:1.0.2"/>
    <category term="cpe:/a:mozilla:firefox:1.0.3"/>
    <category term="cpe:/a:mozilla:firefox:1.0.4"/>
    <category term="cpe:/a:mozilla:firefox:1.0.5"/>
    <category term="cpe:/a:mozilla:firefox:1.0.6"/>
    <category term="cpe:/a:mozilla:firefox:1.0.7"/>
    <category term="cpe:/a:mozilla:firefox:1.0.8"/>
    <category term="cpe:/a:mozilla:firefox:1.0:preview_release"/>
    <category term="cpe:/a:mozilla:firefox:1.4.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.10"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.11"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.12"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.2"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.3"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.4"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.6"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.7"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.8"/>
    <category term="cpe:/a:mozilla:firefox:1.5.0.9"/>
    <category term="cpe:/a:mozilla:firefox:1.5.1"/>
    <category term="cpe:/a:mozilla:firefox:1.5.2"/>
    <category term="cpe:/a:mozilla:firefox:1.5.3"/>
    <category term="cpe:/a:mozilla:firefox:1.5.4"/>
    <category term="cpe:/a:mozilla:firefox:1.5.5"/>
    <category term="cpe:/a:mozilla:firefox:1.5.6"/>
    <category term="cpe:/a:mozilla:firefox:1.5.7"/>
    <category term="cpe:/a:mozilla:firefox:1.5.8"/>
    <category term="cpe:/a:mozilla:firefox:1.5:beta1"/>
    <category term="cpe:/a:mozilla:firefox:1.5:beta2"/>
    <category term="cpe:/a:mozilla:firefox:1.8"/>
    <category term="cpe:/a:mozilla:firefox:2.0"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.1"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.10"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.11"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.12"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.13"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.14"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.15"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.16"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.17"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.18"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.19"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.2"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.20"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.3"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.4"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.5"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.6"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.7"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.8"/>
    <category term="cpe:/a:mozilla:firefox:2.0.0.9"/>
    <category term="cpe:/a:mozilla:firefox:3.0"/>
    <category term="cpe:/a:mozilla:firefox:3.0.1"/>
    <category term="cpe:/a:mozilla:firefox:3.0.10"/>
    <category term="cpe:/a:mozilla:firefox:3.0.11"/>
    <category term="cpe:/a:mozilla:firefox:3.0.12"/>
    <category term="cpe:/a:mozilla:firefox:3.0.13"/>
    <category term="cpe:/a:mozilla:firefox:3.0.14"/>
    <category term="cpe:/a:mozilla:firefox:3.0.15"/>
    <category term="cpe:/a:mozilla:firefox:3.0.16"/>
    <category term="cpe:/a:mozilla:firefox:3.0.17"/>
    <category term="cpe:/a:mozilla:firefox:3.0.2"/>
    <category term="cpe:/a:mozilla:firefox:3.0.3"/>
    <category term="cpe:/a:mozilla:firefox:3.0.4"/>
    <category term="cpe:/a:mozilla:firefox:3.0.5"/>
    <category term="cpe:/a:mozilla:firefox:3.0.6"/>
    <category term="cpe:/a:mozilla:firefox:3.0.7"/>
    <category term="cpe:/a:mozilla:firefox:3.0.8"/>
    <category term="cpe:/a:mozilla:firefox:3.0.9"/>
    <category term="cpe:/a:mozilla:firefox:3.5"/>
    <category term="cpe:/a:mozilla:firefox:3.5.1"/>
    <category term="cpe:/a:mozilla:firefox:3.5.10"/>
    <category term="cpe:/a:mozilla:firefox:3.5.11"/>
    <category term="cpe:/a:mozilla:firefox:3.5.12"/>
    <category term="cpe:/a:mozilla:firefox:3.5.13"/>
    <category term="cpe:/a:mozilla:firefox:3.5.14"/>
    <category term="cpe:/a:mozilla:firefox:3.5.15"/>
    <category term="cpe:/a:mozilla:firefox:3.5.2"/>
    <category term="cpe:/a:mozilla:firefox:3.5.3"/>
    <category term="cpe:/a:mozilla:firefox:3.5.4"/>
    <category term="cpe:/a:mozilla:firefox:3.5.5"/>
    <category term="cpe:/a:mozilla:firefox:3.5.6"/>
    <category term="cpe:/a:mozilla:firefox:3.5.7"/>
    <category term="cpe:/a:mozilla:firefox:3.5.8"/>
    <category term="cpe:/a:mozilla:firefox:3.5.9"/>
    <category term="cpe:/a:mozilla:firefox:3.6"/>
    <category term="cpe:/a:mozilla:firefox:3.6.10"/>
    <category term="cpe:/a:mozilla:firefox:3.6.11"/>
    <category term="cpe:/a:mozilla:firefox:3.6.12"/>
    <category term="cpe:/a:mozilla:firefox:3.6.13"/>
    <category term="cpe:/a:mozilla:firefox:3.6.14"/>
    <category term="cpe:/a:mozilla:firefox:3.6.15"/>
    <category term="cpe:/a:mozilla:firefox:3.6.16"/>
    <category term="cpe:/a:mozilla:firefox:3.6.17"/>
    <category term="cpe:/a:mozilla:firefox:3.6.18"/>
    <category term="cpe:/a:mozilla:firefox:3.6.19"/>
    <category term="cpe:/a:mozilla:firefox:3.6.2"/>
    <category term="cpe:/a:mozilla:firefox:3.6.20"/>
    <category term="cpe:/a:mozilla:firefox:3.6.21"/>
    <category term="cpe:/a:mozilla:firefox:3.6.22"/>
    <category term="cpe:/a:mozilla:firefox:3.6.23"/>
    <category term="cpe:/a:mozilla:firefox:3.6.24"/>
    <category term="cpe:/a:mozilla:firefox:3.6.3"/>
    <category term="cpe:/a:mozilla:firefox:3.6.4"/>
    <category term="cpe:/a:mozilla:firefox:3.6.6"/>
    <category term="cpe:/a:mozilla:firefox:3.6.7"/>
    <category term="cpe:/a:mozilla:firefox:3.6.8"/>
    <category term="cpe:/a:mozilla:firefox:3.6.9"/>
    <category term="cpe:/a:mozilla:firefox:4.0"/>
    <category term="cpe:/a:mozilla:firefox:4.0.1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta10"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta11"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta12"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta2"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta3"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta4"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta5"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta6"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta7"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta8"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta9"/>
    <category term="cpe:/a:mozilla:firefox:5.0"/>
    <category term="cpe:/a:mozilla:firefox:5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0"/>
    <category term="cpe:/a:mozilla:firefox:6.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0.2"/>
    <category term="cpe:/a:mozilla:firefox:7.0"/>
    <category term="cpe:/a:mozilla:firefox:7.0.1"/>
    <category term="cpe:/a:mozilla:firefox:8.0 and previous versions"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.99"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::dev"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.11"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.12"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.13"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.14"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.15"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.16"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.17"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.18"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.19"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.11"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.12"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.13"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.14"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1::pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.3.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.5 and previous versions"/>
    <category term="cpe:/a:mozilla:thunderbird:0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.1"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.2"/>
    <category term="cpe:/a:mozilla:thunderbird:0.7.3"/>
    <category term="cpe:/a:mozilla:thunderbird:0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.5:beta"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:1.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.10"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.12"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.13"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.14"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5.2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
    <category term="cpe:/a:mozilla:thunderbird:1.7.1"/>
    <category term="cpe:/a:mozilla:thunderbird:1.7.3"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.0"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.12"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.13"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.14"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.15"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.16"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.17"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.18"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.19"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.20"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.21"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.22"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.23"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:2.0.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.10"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.11"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.3"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.4"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.5"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.6"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.7"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.8"/>
    <category term="cpe:/a:mozilla:thunderbird:3.0.9"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.1"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.10"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.11"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.12"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.13"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.14"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.15"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.16"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.2"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.3"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.4"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.5"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.6"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.7"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.8"/>
    <category term="cpe:/a:mozilla:thunderbird:3.1.9"/>
    <category term="cpe:/a:mozilla:thunderbird:5.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:8.0 and previous versions"/>
    <category term="cpe:/o:apple:mac_os_x"/>
    <sec:identifier>CVE-2011-3664</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3660:firefox, seamonkey, thunderbird: Multiple unspecified vulnerabilities in the browser...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3660_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3660_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3660_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3660_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:4.0"/>
    <category term="cpe:/a:mozilla:firefox:4.0.1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta10"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta11"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta12"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta2"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta3"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta4"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta5"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta6"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta7"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta8"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta9"/>
    <category term="cpe:/a:mozilla:firefox:5.0"/>
    <category term="cpe:/a:mozilla:firefox:5.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0"/>
    <category term="cpe:/a:mozilla:firefox:6.0.1"/>
    <category term="cpe:/a:mozilla:firefox:6.0.2"/>
    <category term="cpe:/a:mozilla:firefox:7.0"/>
    <category term="cpe:/a:mozilla:firefox:7.0.1"/>
    <category term="cpe:/a:mozilla:firefox:8.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0.99"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0::dev"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.0:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.1"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.11"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.12"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.13"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.14"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.15"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.16"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.17"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.18"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.19"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.2"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.3"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.4"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.5:1.1.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.6"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.7"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1.9"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
    <category term="cpe:/a:mozilla:seamonkey:1.1:beta"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:1.5.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.10"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.11"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.12"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.13"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.14"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.4"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.5"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.6"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.7"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.8"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0.9"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:alpha_3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:beta_2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0:rc2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1::pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.0a1pre"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha1"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha2"/>
    <category term="cpe:/a:mozilla:seamonkey:2.1:alpha3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.3.3"/>
    <category term="cpe:/a:mozilla:seamonkey:2.5 and previous versions"/>
    <category term="cpe:/a:mozilla:thunderbird:5.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:6.0.2"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0"/>
    <category term="cpe:/a:mozilla:thunderbird:7.0.1"/>
    <category term="cpe:/a:mozilla:thunderbird:8.0"/>
    <sec:identifier>CVE-2011-3660</sec:identifier>
    <vrda:latestrevisionno>1</vrda:latestrevisionno>
    <vrda:analysisinformationsourcetype>Advisory</vrda:analysisinformationsourcetype>
    <vrda:revisionno>1</vrda:revisionno>
    <vrda:invalidated>false</vrda:invalidated>
  </entry>
  <entry>
    <title>CVE-2011-3665:firefox, seamonkey, thunderbird: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 th...</title>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3665_AD_1.html" rel="alternate" type="text/html"/>
    <link href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3665_AD_1.xml" rel="alternate" type="application/xml"/>
    <id>http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3665_AD_1.html</id>
    <published>2011-12-21T00:00:00+09:00</published>
    <updated>2011-12-21T00:00:00+09:00</updated>
    <author>
      <name>NIST NVD</name>
    </author>
    <content type="html">
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling.&lt;br&gt;&lt;br&gt;&lt;a href="http://vrda.jpcert.or.jp/feed/en/NISTNVD_CVE-2011-3665_AD_1.html" target="_self"&gt;Vulnerability Analysis Summary&lt;/a&gt;&lt;br&gt;Analysis Information Source Type : Advisory, Alert    </content>
    <category term="cpe:/a:mozilla:firefox:4.0"/>
    <category term="cpe:/a:mozilla:firefox:4.0.1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta1"/>
    <category term="cpe:/a:mozilla:firefox:4.0:beta10"/>
    <catego
