<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="1687073.xsl"?>
<?xml-stylesheet type="text/css" href="1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Linux Bulletin - April 2016 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Linux Bulletin Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>OLBulletinApr2016</ID>
      </Identification>
      <Status>Final</Status>
      <Version>3.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2016-04-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
         <Revision>
            <Number>2.0</Number>
            <Date>2016-05-19T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
         <Revision>
            <Number>3.0</Number>
            <Date>2016-06-20T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
      </RevisionHistory>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle Linux security vulnerabilities which have had fixes released for all supported versions and platforms.</Note>
   </DocumentNotes>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Linux" Type="Product Family">
            <Branch Name="Oracle Linux OS" Type="Product Name">
               <Branch Name="5" Type="Product Version">
                  <FullProductName ProductID="P-1309V-5">Oracle Linux 5</FullProductName>
               </Branch>
               <Branch Name="6" Type="Product Version">
                  <FullProductName ProductID="P-1309V-6">Oracle Linux 6</FullProductName>
               </Branch>
               <Branch Name="7" Type="Product Version">
                  <FullProductName ProductID="P-1309V-7">Oracle Linux 7</FullProductName>
               </Branch>
            </Branch>
         </Branch>
     </Branch>
  </ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5370</Title>
         <Notes>
               <Note Audience="All" Ordinal="1" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 8.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5370</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5370</Title>
         <Notes>
               <Note Audience="All" Ordinal="2" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 8.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5370</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0611.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5370</Title>
         <Notes>
               <Note Audience="All" Ordinal="3" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 8.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5370</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0758</Title>
         <Notes>
               <Note Audience="All" Ordinal="4" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0758</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3559.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0758</Title>
         <Notes>
               <Note Audience="All" Ordinal="5" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0758</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1033.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0758</Title>
         <Notes>
               <Note Audience="All" Ordinal="6" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 7.2 CVSS V2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0758</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.2</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3717</Title>
         <Notes>
               <Note Audience="All" Ordinal="7" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1allows remote attackers to read arbitrary files via a crafted image. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3717</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:C/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0726.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8767</Title>
         <Notes>
               <Note Audience="All" Ordinal="8" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does notproperly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8767</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3554.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8767</Title>
         <Notes>
               <Note Audience="All" Ordinal="9" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does notproperly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8767</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0715.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8767</Title>
         <Notes>
               <Note Audience="All" Ordinal="10" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does notproperly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8767</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3551.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8767</Title>
         <Notes>
               <Note Audience="All" Ordinal="11" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does notproperly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8767</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3552.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8767</Title>
         <Notes>
               <Note Audience="All" Ordinal="12" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does notproperly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call. CVSS Base Score: 7.1 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8767</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3553.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="13" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3570.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="14" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3572.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4565</Title>
         <Notes>
               <Note Audience="All" Ordinal="15" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. CVSS Base Score: 6.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3573.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3714</Title>
         <Notes>
               <Note Audience="All" Ordinal="16" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW,(7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka ImageTragick. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3714</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0726.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5118</Title>
         <Notes>
               <Note Audience="All" Ordinal="17" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 andImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5118</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2805</Title>
         <Notes>
               <Note Audience="All" Ordinal="18" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. Unspecified vulnerability in the browser engine in Mozilla Firefox ESR38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2805</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0695.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2806</Title>
         <Notes>
               <Note Audience="All" Ordinal="19" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2806</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0695.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2807</Title>
         <Notes>
               <Note Audience="All" Ordinal="20" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. Multiple unspecified vulnerabilities in the browser engine in MozillaFirefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2807</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0695.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2818</Title>
         <Notes>
               <Note Audience="All" Ordinal="21" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2818</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2819</Title>
         <Notes>
               <Note Audience="All" Ordinal="22" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2819</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2010-5325</Title>
         <Notes>
               <Note Audience="All" Ordinal="23" Title="Details" Type="Details">This is a vulnerability in  foomatic  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2010-5325</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0491.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2315</Title>
         <Notes>
               <Note Audience="All" Ordinal="24" Title="Details" Type="Details">This is a vulnerability in  git  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2315</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0496.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2324</Title>
         <Notes>
               <Note Audience="All" Ordinal="25" Title="Details" Type="Details">This is a vulnerability in  git  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2324</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0496.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1521</Title>
         <Notes>
               <Note Audience="All" Ordinal="26" Title="Details" Type="Details">This is a vulnerability in  graphite2  in Oracle Linux. The directrun function in directmachine.cpp in Libgraphite in Graphite2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1521</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0594.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1522</Title>
         <Notes>
               <Note Audience="All" Ordinal="27" Title="Details" Type="Details">This is a vulnerability in  graphite2  in Oracle Linux. Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in MozillaFirefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1522</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0594.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1523</Title>
         <Notes>
               <Note Audience="All" Ordinal="28" Title="Details" Type="Details">This is a vulnerability in  graphite2  in Oracle Linux. The SillMap::readFace function in FeatureMap.cpp in Libgraphite inGraphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1523</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0594.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0686</Title>
         <Notes>
               <Note Audience="All" Ordinal="29" Title="Details" Type="Details">This is a vulnerability in  java-1.6.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0686</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0723.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0687</Title>
         <Notes>
               <Note Audience="All" Ordinal="30" Title="Details" Type="Details">This is a vulnerability in  java-1.6.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0687</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0723.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3427</Title>
         <Notes>
               <Note Audience="All" Ordinal="31" Title="Details" Type="Details">This is a vulnerability in  java-1.6.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0723.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0636</Title>
         <Notes>
               <Note Audience="All" Ordinal="32" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0636</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0511.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0636</Title>
         <Notes>
               <Note Audience="All" Ordinal="33" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0636</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0512.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0686</Title>
         <Notes>
               <Note Audience="All" Ordinal="34" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0686</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0675.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0686</Title>
         <Notes>
               <Note Audience="All" Ordinal="35" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0686</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0676.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0687</Title>
         <Notes>
               <Note Audience="All" Ordinal="36" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0687</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0675.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0687</Title>
         <Notes>
               <Note Audience="All" Ordinal="37" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0687</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0676.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3427</Title>
         <Notes>
               <Note Audience="All" Ordinal="38" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0675.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3427</Title>
         <Notes>
               <Note Audience="All" Ordinal="39" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0676.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0636</Title>
         <Notes>
               <Note Audience="All" Ordinal="40" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0636</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0513.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0636</Title>
         <Notes>
               <Note Audience="All" Ordinal="41" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0636</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0514.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0686</Title>
         <Notes>
               <Note Audience="All" Ordinal="42" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0686</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0686</Title>
         <Notes>
               <Note Audience="All" Ordinal="43" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0686</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0687</Title>
         <Notes>
               <Note Audience="All" Ordinal="44" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0687</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0687</Title>
         <Notes>
               <Note Audience="All" Ordinal="45" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 andJava SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0687</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3427</Title>
         <Notes>
               <Note Audience="All" Ordinal="46" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3427</Title>
         <Notes>
               <Note Audience="All" Ordinal="47" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5156</Title>
         <Notes>
               <Note Audience="All" Ordinal="48" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The virtnet_probe function in drivers/net/virtio_net.c in the Linuxkernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets. CVSS Base Score: 6.8 CVSS V2 Vector: AV:A/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5156</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:A/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3068</Title>
         <Notes>
               <Note Audience="All" Ordinal="49" Title="Details" Type="Details">This is a vulnerability in  mercurial  in Oracle Linux. Mercurial before 3.7.3 allows remote attackers to execute arbitrarycode via a crafted git ext:: URL when cloning a subrepository. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3068</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0706.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8385</Title>
         <Notes>
               <Note Audience="All" Ordinal="50" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern andrelated patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8385</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3191</Title>
         <Notes>
               <Note Audience="All" Ordinal="51" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-3542. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3191</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2118</Title>
         <Notes>
               <Note Audience="All" Ordinal="52" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2118</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2118</Title>
         <Notes>
               <Note Audience="All" Ordinal="53" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2118</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0611.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2118</Title>
         <Notes>
               <Note Audience="All" Ordinal="54" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2118</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0621.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2118</Title>
         <Notes>
               <Note Audience="All" Ordinal="55" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2118</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0749</Title>
         <Notes>
               <Note Audience="All" Ordinal="56" Title="Details" Type="Details">This is a vulnerability in  spice  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0749</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1205.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0749</Title>
         <Notes>
               <Note Audience="All" Ordinal="57" Title="Details" Type="Details">This is a vulnerability in  spice-server  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0749</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1204.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2805</Title>
         <Notes>
               <Note Audience="All" Ordinal="58" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. Unspecified vulnerability in the browser engine in Mozilla Firefox ESR38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2805</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1041.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2807</Title>
         <Notes>
               <Note Audience="All" Ordinal="59" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. Multiple unspecified vulnerabilities in the browser engine in MozillaFirefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. CVSS Base Score: 6.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2807</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1041.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="60" Title="Details" Type="Details">This is a vulnerability in  qemu-kvm  in Oracle Linux. The VGA module in QEMU improperly performs bounds checking on bankedaccess to video memory, which allows local guest OS users to execute arbitrary code on the host by changing access modes after setting the bank register, aka the Dark CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0724.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="61" Title="Details" Type="Details">This is a vulnerability in  qemu-kvm  in Oracle Linux. The VGA module in QEMU improperly performs bounds checking on bankedaccess to video memory, which allows local guest OS users to execute arbitrary code on the host by changing access modes after setting the bank register, aka the Dark CVSS Base Score: 6.5 CVSS V2 Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>AV:A/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0997.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1548</Title>
         <Notes>
               <Note Audience="All" Ordinal="62" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 6.4 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1548</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.4</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1141.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5157</Title>
         <Notes>
               <Note Audience="All" Ordinal="63" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on thex86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI. CVSS Base Score: 6.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5157</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0715.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-6563</Title>
         <Notes>
               <Note Audience="All" Ordinal="64" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSDplatforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c. CVSS Base Score: 6.2 CVSS V2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-6563</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0741.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7509</Title>
         <Notes>
               <Note Audience="All" Ordinal="65" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. fs/ext4/namei.c in the Linux kernel before 3.7 allows physicallyproximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015. CVSS Base Score: 6 CVSS V2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7509</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:L/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7509</Title>
         <Notes>
               <Note Audience="All" Ordinal="66" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. fs/ext4/namei.c in the Linux kernel before 3.7 allows physicallyproximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015. CVSS Base Score: 6 CVSS V2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7509</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:L/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3566.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7509</Title>
         <Notes>
               <Note Audience="All" Ordinal="67" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. fs/ext4/namei.c in the Linux kernel before 3.7 allows physicallyproximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015. CVSS Base Score: 6 CVSS V2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7509</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6</BaseScore>
               <Vector>AV:L/AC:H/Au:S/C:C/I:C/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3567.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1526</Title>
         <Notes>
               <Note Audience="All" Ordinal="68" Title="Details" Type="Details">This is a vulnerability in  graphite2  in Oracle Linux. The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite inGraphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1526</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0594.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7979</Title>
         <Notes>
               <Note Audience="All" Ordinal="69" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1141.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2842</Title>
         <Notes>
               <Note Audience="All" Ordinal="70" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2842</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2842</Title>
         <Notes>
               <Note Audience="All" Ordinal="71" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2842</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2112</Title>
         <Notes>
               <Note Audience="All" Ordinal="72" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2112</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2114</Title>
         <Notes>
               <Note Audience="All" Ordinal="73" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2114</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2115</Title>
         <Notes>
               <Note Audience="All" Ordinal="74" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2112</Title>
         <Notes>
               <Note Audience="All" Ordinal="75" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2112</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0611.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2112</Title>
         <Notes>
               <Note Audience="All" Ordinal="76" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2112</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0621.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2115</Title>
         <Notes>
               <Note Audience="All" Ordinal="77" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0611.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2115</Title>
         <Notes>
               <Note Audience="All" Ordinal="78" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0621.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2112</Title>
         <Notes>
               <Note Audience="All" Ordinal="79" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2112</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2115</Title>
         <Notes>
               <Note Audience="All" Ordinal="80" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-7810</Title>
         <Notes>
               <Note Audience="All" Ordinal="81" Title="Details" Type="Details">This is a vulnerability in  tomcat6  in Oracle Linux. The Expression Language (EL) implementation in Apache Tomcat 6.xbefore 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation. CVSS Base Score: 5.8 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-7810</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.8</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0492.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8895</Title>
         <Notes>
               <Note Audience="All" Ordinal="82" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.5 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8895</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0774</Title>
         <Notes>
               <Note Audience="All" Ordinal="83" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.4 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0774</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0494.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3698</Title>
         <Notes>
               <Note Audience="All" Ordinal="84" Title="Details" Type="Details">This is a vulnerability in  libndp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.4 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3698</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1086.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0774</Title>
         <Notes>
               <Note Audience="All" Ordinal="85" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.4 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0774</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3528.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5239</Title>
         <Notes>
               <Note Audience="All" Ordinal="86" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5239</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2808</Title>
         <Notes>
               <Note Audience="All" Ordinal="87" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2808</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0695.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2814</Title>
         <Notes>
               <Note Audience="All" Ordinal="88" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2814</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0695.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2821</Title>
         <Notes>
               <Note Audience="All" Ordinal="89" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2821</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2828</Title>
         <Notes>
               <Note Audience="All" Ordinal="90" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2828</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8327</Title>
         <Notes>
               <Note Audience="All" Ordinal="91" Title="Details" Type="Details">This is a vulnerability in  foomatic  in Oracle Linux. Incomplete blacklist vulnerability in util.c in foomatic-rip incups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via  (backtick) characters in a print job. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8327</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0491.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8560</Title>
         <Notes>
               <Note Audience="All" Ordinal="92" Title="Details" Type="Details">This is a vulnerability in  foomatic  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8560</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0491.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0546</Title>
         <Notes>
               <Note Audience="All" Ordinal="93" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0546</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3069</Title>
         <Notes>
               <Note Audience="All" Ordinal="94" Title="Details" Type="Details">This is a vulnerability in  mercurial  in Oracle Linux. Mercurial before 3.7.3 allows remote attackers to execute arbitrarycode via a crafted name when converting a Git repository. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3069</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0706.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1978</Title>
         <Notes>
               <Note Audience="All" Ordinal="95" Title="Details" Type="Details">This is a vulnerability in  nss and nspr  in Oracle Linux. Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchangefunction in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0684.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1979</Title>
         <Notes>
               <Note Audience="All" Ordinal="96" Title="Details" Type="Details">This is a vulnerability in  nss and nspr  in Oracle Linux. Use-after-free vulnerability in thePK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0684.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1978</Title>
         <Notes>
               <Note Audience="All" Ordinal="97" Title="Details" Type="Details">This is a vulnerability in  nss, nspr, nss-softokn, and nss-util  in Oracle Linux. Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchangefunction in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0685.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1979</Title>
         <Notes>
               <Note Audience="All" Ordinal="98" Title="Details" Type="Details">This is a vulnerability in  nss, nspr, nss-softokn, and nss-util  in Oracle Linux. Use-after-free vulnerability in thePK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0685.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1978</Title>
         <Notes>
               <Note Audience="All" Ordinal="99" Title="Details" Type="Details">This is a vulnerability in  nss, nss-util, and nspr  in Oracle Linux. Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchangefunction in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0591.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1979</Title>
         <Notes>
               <Note Audience="All" Ordinal="100" Title="Details" Type="Details">This is a vulnerability in  nss, nss-util, and nspr  in Oracle Linux. Use-after-free vulnerability in thePK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1979</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0591.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2105</Title>
         <Notes>
               <Note Audience="All" Ordinal="101" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. Integer overflow in the EVP_EncodeUpdate function incrypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2105</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2105</Title>
         <Notes>
               <Note Audience="All" Ordinal="102" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. Integer overflow in the EVP_EncodeUpdate function incrypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2105</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2106</Title>
         <Notes>
               <Note Audience="All" Ordinal="103" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. Integer overflow in the EVP_EncryptUpdate function incrypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2106</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2106</Title>
         <Notes>
               <Note Audience="All" Ordinal="104" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. Integer overflow in the EVP_EncryptUpdate function incrypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2106</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2108</Title>
         <Notes>
               <Note Audience="All" Ordinal="105" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the negative CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2108</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2108</Title>
         <Notes>
               <Note Audience="All" Ordinal="106" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the negative CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2108</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2108</Title>
         <Notes>
               <Note Audience="All" Ordinal="107" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the negative CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2108</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1137.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4051</Title>
         <Notes>
               <Note Audience="All" Ordinal="108" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4051</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4051</Title>
         <Notes>
               <Note Audience="All" Ordinal="109" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4051</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4052</Title>
         <Notes>
               <Note Audience="All" Ordinal="110" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4052</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4052</Title>
         <Notes>
               <Note Audience="All" Ordinal="111" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4052</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4053</Title>
         <Notes>
               <Note Audience="All" Ordinal="112" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers toobtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4053</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4053</Title>
         <Notes>
               <Note Audience="All" Ordinal="113" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers toobtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4053</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4054</Title>
         <Notes>
               <Note Audience="All" Ordinal="114" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allowsremote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4054</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4054</Title>
         <Notes>
               <Note Audience="All" Ordinal="115" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allowsremote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4054</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4051</Title>
         <Notes>
               <Note Audience="All" Ordinal="116" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4051</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4052</Title>
         <Notes>
               <Note Audience="All" Ordinal="117" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4052</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4053</Title>
         <Notes>
               <Note Audience="All" Ordinal="118" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers toobtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4053</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4054</Title>
         <Notes>
               <Note Audience="All" Ordinal="119" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allowsremote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 5.1 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4054</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8215</Title>
         <Notes>
               <Note Audience="All" Ordinal="120" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8215</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8215</Title>
         <Notes>
               <Note Audience="All" Ordinal="121" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8215</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8215</Title>
         <Notes>
               <Note Audience="All" Ordinal="122" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8215</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3566.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8215</Title>
         <Notes>
               <Note Audience="All" Ordinal="123" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product. CVSS Base Score: 5 CVSS V2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8215</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5</BaseScore>
               <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3567.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4312</Title>
         <Notes>
               <Note Audience="All" Ordinal="124" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. The Linux kernel before 4.4.1 allows local users to bypassfile-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4312</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3559.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4312</Title>
         <Notes>
               <Note Audience="All" Ordinal="125" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The Linux kernel before 4.4.1 allows local users to bypassfile-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4312</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8324</Title>
         <Notes>
               <Note Audience="All" Ordinal="126" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The ext4 implementation in the Linux kernel before 2.6.34 does notproperly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8324</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2047</Title>
         <Notes>
               <Note Audience="All" Ordinal="127" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. The ssl_verify_server_cert function in sql-common/client.c in MariaDBbefore 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10, Oracle MySQL, and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a /CN= string in a field in a certificate, as demonstrated by /OU=/CN=bar.com/CN=foo.com. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2047</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1908</Title>
         <Notes>
               <Note Audience="All" Ordinal="128" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1908</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0465.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3115</Title>
         <Notes>
               <Note Audience="All" Ordinal="129" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. Multiple CRLF injection vulnerabilities in session.c in sshd inOpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0465.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3115</Title>
         <Notes>
               <Note Audience="All" Ordinal="130" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. Multiple CRLF injection vulnerabilities in session.c in sshd inOpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0466.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3115</Title>
         <Notes>
               <Note Audience="All" Ordinal="131" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. Multiple CRLF injection vulnerabilities in session.c in sshd inOpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3115</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3531.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5352</Title>
         <Notes>
               <Note Audience="All" Ordinal="132" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. The x11_open_helper function in channels.c in ssh in OpenSSH before6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window. CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5352</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0741.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1908</Title>
         <Notes>
               <Note Audience="All" Ordinal="133" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.9 CVSS V2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1908</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0741.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4312</Title>
         <Notes>
               <Note Audience="All" Ordinal="134" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The Linux kernel before 4.4.1 allows local users to bypassfile-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4312</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4312</Title>
         <Notes>
               <Note Audience="All" Ordinal="135" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The Linux kernel before 4.4.1 allows local users to bypassfile-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4312</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3566.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2013-4312</Title>
         <Notes>
               <Note Audience="All" Ordinal="136" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The Linux kernel before 4.4.1 allows local users to bypassfile-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2013-4312</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3567.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8324</Title>
         <Notes>
               <Note Audience="All" Ordinal="137" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The ext4 implementation in the Linux kernel before 2.6.34 does notproperly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function. CVSS Base Score: 4.9 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8324</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.9</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3567.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8896</Title>
         <Notes>
               <Note Audience="All" Ordinal="138" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8896</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8543</Title>
         <Notes>
               <Note Audience="All" Ordinal="139" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The networking implementation in the Linux kernel through 4.3.3, asused in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0617</Title>
         <Notes>
               <Note Audience="All" Ordinal="140" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0617</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3529.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4879</Title>
         <Notes>
               <Note Audience="All" Ordinal="141" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier,and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML. CVSS Base Score: 4.6 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4879</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8543</Title>
         <Notes>
               <Note Audience="All" Ordinal="142" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The networking implementation in the Linux kernel through 4.3.3, asused in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8543</Title>
         <Notes>
               <Note Audience="All" Ordinal="143" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The networking implementation in the Linux kernel through 4.3.3, asused in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3566.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8543</Title>
         <Notes>
               <Note Audience="All" Ordinal="144" Title="Details" Type="Details">This is a vulnerability in Unbreakable Enterprise kernel  in Oracle Linux. The networking implementation in the Linux kernel through 4.3.3, asused in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application. CVSS Base Score: 4.6 CVSS V2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.6</BaseScore>
               <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3567.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3715</Title>
         <Notes>
               <Note Audience="All" Ordinal="145" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3715</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0726.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3716</Title>
         <Notes>
               <Note Audience="All" Ordinal="146" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1allows remote attackers to move arbitrary files via a crafted image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3716</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0726.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3718</Title>
         <Notes>
               <Note Audience="All" Ordinal="147" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.xbefore 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3718</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0726.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-5240</Title>
         <Notes>
               <Note Audience="All" Ordinal="148" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-5240</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3538</Title>
         <Notes>
               <Note Audience="All" Ordinal="149" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. file before 5.19 does not properly restrict the amount of data readduring a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3538</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3587</Title>
         <Notes>
               <Note Audience="All" Ordinal="150" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. Integer overflow in the cdf_read_property_info function in cdf.c infile through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE:\ this vulnerability exists because of an incomplete fix for CVE-2012-1571. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3587</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-3710</Title>
         <Notes>
               <Note Audience="All" Ordinal="151" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. The donote function in readelf.c in file through 5.20, as used in theFileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-3710</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8116</Title>
         <Notes>
               <Note Audience="All" Ordinal="152" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. The ELF parser (readelf.c) in file before 5.21 allows remote attackersto cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8116</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8117</Title>
         <Notes>
               <Note Audience="All" Ordinal="153" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. softmagic.c in file before 5.21 does not properly limit recursion,which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8117</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2822</Title>
         <Notes>
               <Note Audience="All" Ordinal="154" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2822</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2831</Title>
         <Notes>
               <Note Audience="All" Ordinal="155" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2831</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1217.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5234</Title>
         <Notes>
               <Note Audience="All" Ordinal="156" Title="Details" Type="Details">This is a vulnerability in  icedtea-web  in Oracle Linux. IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properlysanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5234</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0778.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5235</Title>
         <Notes>
               <Note Audience="All" Ordinal="157" Title="Details" Type="Details">This is a vulnerability in  icedtea-web  in Oracle Linux. IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properlydetermine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5235</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0778.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3425</Title>
         <Notes>
               <Note Audience="All" Ordinal="158" Title="Details" Type="Details">This is a vulnerability in  java-1.6.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3425</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0723.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3425</Title>
         <Notes>
               <Note Audience="All" Ordinal="159" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3425</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0675.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3425</Title>
         <Notes>
               <Note Audience="All" Ordinal="160" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3425</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0676.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3425</Title>
         <Notes>
               <Note Audience="All" Ordinal="161" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3425</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3425</Title>
         <Notes>
               <Note Audience="All" Ordinal="162" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect availability via vectors related to JAXP. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3425</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7701</Title>
         <Notes>
               <Note Audience="All" Ordinal="163" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7701</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7852</Title>
         <Notes>
               <Note Audience="All" Ordinal="164" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7852</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7977</Title>
         <Notes>
               <Note Audience="All" Ordinal="165" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7977</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7978</Title>
         <Notes>
               <Note Audience="All" Ordinal="166" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7978</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1547</Title>
         <Notes>
               <Note Audience="All" Ordinal="167" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1547</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1141.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5600</Title>
         <Notes>
               <Note Audience="All" Ordinal="168" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. The kbdint_next_device function in auth2-chall.c in sshd in OpenSSHthrough 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5600</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0466.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5600</Title>
         <Notes>
               <Note Audience="All" Ordinal="169" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. The kbdint_next_device function in auth2-chall.c in sshd in OpenSSHthrough 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5600</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3531.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-2328</Title>
         <Notes>
               <Note Audience="All" Ordinal="170" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and relatedpatterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-2328</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-3217</Title>
         <Notes>
               <Note Audience="All" Ordinal="171" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-3217</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5073</Title>
         <Notes>
               <Note Audience="All" Ordinal="172" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5073</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8388</Title>
         <Notes>
               <Note Audience="All" Ordinal="173" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. PCRE before 8.38 mishandles the /(?=di(?&lt;=(?1))|(?=(.))))/ pattern andrelated patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8388</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8391</Title>
         <Notes>
               <Note Audience="All" Ordinal="174" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. The pcre_compile function in pcre_compile.c in PCRE before 8.38mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8391</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2110</Title>
         <Notes>
               <Note Audience="All" Ordinal="175" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2110</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2111</Title>
         <Notes>
               <Note Audience="All" Ordinal="176" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2111</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2113</Title>
         <Notes>
               <Note Audience="All" Ordinal="177" Title="Details" Type="Details">This is a vulnerability in  samba and samba4  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2113</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0612.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2110</Title>
         <Notes>
               <Note Audience="All" Ordinal="178" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2110</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0621.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2111</Title>
         <Notes>
               <Note Audience="All" Ordinal="179" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2111</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0611.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2111</Title>
         <Notes>
               <Note Audience="All" Ordinal="180" Title="Details" Type="Details">This is a vulnerability in  samba  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2111</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0621.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2110</Title>
         <Notes>
               <Note Audience="All" Ordinal="181" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2110</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2111</Title>
         <Notes>
               <Note Audience="All" Ordinal="182" Title="Details" Type="Details">This is a vulnerability in  samba3x  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2111</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0613.html</URL>
                  <ProductID>P-1309V-5</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2150</Title>
         <Notes>
               <Note Audience="All" Ordinal="183" Title="Details" Type="Details">This is a vulnerability in  spice  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2150</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1205.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2150</Title>
         <Notes>
               <Note Audience="All" Ordinal="184" Title="Details" Type="Details">This is a vulnerability in  spice-server  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4.3 CVSS V2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2150</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:A/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1204.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4553</Title>
         <Notes>
               <Note Audience="All" Ordinal="185" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does notproperly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4553</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4555</Title>
         <Notes>
               <Note Audience="All" Ordinal="186" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4555</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4556</Title>
         <Notes>
               <Note Audience="All" Ordinal="187" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.xbefore 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4556</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4556</Title>
         <Notes>
               <Note Audience="All" Ordinal="188" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.xbefore 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4556</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4553</Title>
         <Notes>
               <Note Audience="All" Ordinal="189" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does notproperly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4553</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4555</Title>
         <Notes>
               <Note Audience="All" Ordinal="190" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4555</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4556</Title>
         <Notes>
               <Note Audience="All" Ordinal="191" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.xbefore 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. CVSS Base Score: 4.3 CVSS V2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4556</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2010-5313</Title>
         <Notes>
               <Note Audience="All" Ordinal="192" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842. CVSS Base Score: 4 CVSS V2 Vector: AV:L/AC:H/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2010-5313</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-7842</Title>
         <Notes>
               <Note Audience="All" Ordinal="193" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313. CVSS Base Score: 4 CVSS V2 Vector: AV:L/AC:H/Au:N/C:N/I:N/A:C.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-7842</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:C</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8631</Title>
         <Notes>
               <Note Audience="All" Ordinal="194" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. Multiple memory leaks in kadmin/server/server_stubs.c in kadmind inMIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8631</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0493.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8631</Title>
         <Notes>
               <Note Audience="All" Ordinal="195" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. Multiple memory leaks in kadmin/server/server_stubs.c in kadmind inMIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8631</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0532.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4792</Title>
         <Notes>
               <Note Audience="All" Ordinal="196" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4792</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4802</Title>
         <Notes>
               <Note Audience="All" Ordinal="197" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4802</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4815</Title>
         <Notes>
               <Note Audience="All" Ordinal="198" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4815</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4816</Title>
         <Notes>
               <Note Audience="All" Ordinal="199" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlierallows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4816</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4826</Title>
         <Notes>
               <Note Audience="All" Ordinal="200" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4826</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4830</Title>
         <Notes>
               <Note Audience="All" Ordinal="201" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security :\ Privileges. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4830</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4836</Title>
         <Notes>
               <Note Audience="All" Ordinal="202" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4836</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4858</Title>
         <Notes>
               <Note Audience="All" Ordinal="203" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4858</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4861</Title>
         <Notes>
               <Note Audience="All" Ordinal="204" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4861</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4870</Title>
         <Notes>
               <Note Audience="All" Ordinal="205" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier,and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4870</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4913</Title>
         <Notes>
               <Note Audience="All" Ordinal="206" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlierand 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4913</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0505</Title>
         <Notes>
               <Note Audience="All" Ordinal="207" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0505</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0596</Title>
         <Notes>
               <Note Audience="All" Ordinal="208" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0596</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0597</Title>
         <Notes>
               <Note Audience="All" Ordinal="209" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0597</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0616</Title>
         <Notes>
               <Note Audience="All" Ordinal="210" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier andMariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0616</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5194</Title>
         <Notes>
               <Note Audience="All" Ordinal="211" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5194</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5195</Title>
         <Notes>
               <Note Audience="All" Ordinal="212" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7691</Title>
         <Notes>
               <Note Audience="All" Ordinal="213" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7691</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7692</Title>
         <Notes>
               <Note Audience="All" Ordinal="214" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7692</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7702</Title>
         <Notes>
               <Note Audience="All" Ordinal="215" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7702</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-7703</Title>
         <Notes>
               <Note Audience="All" Ordinal="216" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-7703</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-6564</Title>
         <Notes>
               <Note Audience="All" Ordinal="217" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. Use-after-free vulnerability in the mm_answer_pam_free_ctx function inmonitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-6564</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0741.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2107</Title>
         <Notes>
               <Note Audience="All" Ordinal="218" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session, NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2107</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2107</Title>
         <Notes>
               <Note Audience="All" Ordinal="219" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session, NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169. CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2107</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4554</Title>
         <Notes>
               <Note Audience="All" Ordinal="220" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. mime_header.cc in Squid before 3.5.18 allows remote attackers tobypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crated HTTP Host header, aka a header CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4554</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1138.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4554</Title>
         <Notes>
               <Note Audience="All" Ordinal="221" Title="Details" Type="Details">This is a vulnerability in  squid  in Oracle Linux. mime_header.cc in Squid before 3.5.18 allows remote attackers tobypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crated HTTP Host header, aka a header CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4554</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1139.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-4554</Title>
         <Notes>
               <Note Audience="All" Ordinal="222" Title="Details" Type="Details">This is a vulnerability in  squid34  in Oracle Linux. mime_header.cc in Squid before 3.5.18 allows remote attackers tobypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crated HTTP Host header, aka a header CVSS Base Score: 4 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-4554</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1140.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0598</Title>
         <Notes>
               <Note Audience="All" Ordinal="223" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0598</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0600</Title>
         <Notes>
               <Note Audience="All" Ordinal="224" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0600</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0606</Title>
         <Notes>
               <Note Audience="All" Ordinal="225" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0606</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0608</Title>
         <Notes>
               <Note Audience="All" Ordinal="226" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF. CVSS Base Score: 3.5 CVSS V2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0608</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8897</Title>
         <Notes>
               <Note Audience="All" Ordinal="227" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8897</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-9653</Title>
         <Notes>
               <Note Audience="All" Ordinal="228" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. readelf.c in file before 5.22, as used in the Fileinfo component inPHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file. CVSS Base Score: 3.3 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-9653</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-5219</Title>
         <Notes>
               <Note Audience="All" Ordinal="229" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 3.3 CVSS V2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-5219</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>AV:A/AC:L/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0780.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0695</Title>
         <Notes>
               <Note Audience="All" Ordinal="230" Title="Details" Type="Details">This is a vulnerability in  java-1.6.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0695</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0723.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0695</Title>
         <Notes>
               <Note Audience="All" Ordinal="231" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0695</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0675.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0695</Title>
         <Notes>
               <Note Audience="All" Ordinal="232" Title="Details" Type="Details">This is a vulnerability in  java-1.7.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0695</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0676.html</URL>
                  <ProductID>P-1309V-5</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0695</Title>
         <Notes>
               <Note Audience="All" Ordinal="233" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0695</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0695</Title>
         <Notes>
               <Note Audience="All" Ordinal="234" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77;Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0695</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="235" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0650.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="236" Title="Details" Type="Details">This is a vulnerability in  java-1.8.0-openjdk  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0651.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-1550</Title>
         <Notes>
               <Note Audience="All" Ordinal="237" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 2.6 CVSS V2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-1550</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1141.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0799</Title>
         <Notes>
               <Note Audience="All" Ordinal="238" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0799</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0799</Title>
         <Notes>
               <Note Audience="All" Ordinal="239" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0799</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8386</Title>
         <Notes>
               <Note Audience="All" Ordinal="240" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. PCRE before 8.38 mishandles the interaction of lookbehind assertionsand mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. CVSS Base Score: 2.6 CVSS V2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8386</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.6</BaseScore>
               <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1025.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8629</Title>
         <Notes>
               <Note Audience="All" Ordinal="241" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind inMIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string. CVSS Base Score: 2.1 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8629</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0493.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8629</Title>
         <Notes>
               <Note Audience="All" Ordinal="242" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind inMIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string. CVSS Base Score: 2.1 CVSS V2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8629</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0532.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8630</Title>
         <Notes>
               <Note Audience="All" Ordinal="243" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. The (1) kadm5_create_principal_3 and (2) kadm5_modify_principalfunctions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5_POLICY with a NULL policy name. CVSS Base Score: 2.1 CVSS V2 Vector: AV:N/AC:H/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8630</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0532.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2518</Title>
         <Notes>
               <Note Audience="All" Ordinal="244" Title="Details" Type="Details">This is a vulnerability in  ntp  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 2.1 CVSS V2 Vector: AV:N/AC:H/Au:S/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2518</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.1</BaseScore>
               <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1141.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-8898</Title>
         <Notes>
               <Note Audience="All" Ordinal="245" Title="Details" Type="Details">This is a vulnerability in  ImageMagick  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-8898</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-1237.html</URL>
                  <ProductID>P-1309V-6</ProductID>
               <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-9620</Title>
         <Notes>
               <Note Audience="All" Ordinal="246" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. The ELF parser in file 5.08 through 5.21 allows remote attackers tocause a denial of service via a large number of notes. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-9620</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0760.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2014-8134</Title>
         <Notes>
               <Note Audience="All" Ordinal="247" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linuxkernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2014-8134</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0855.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2109</Title>
         <Notes>
               <Note Audience="All" Ordinal="248" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2109</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0722.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-2109</Title>
         <Notes>
               <Note Audience="All" Ordinal="249" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding. CVSS Base Score: 1.9 CVSS V2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-2109</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.9</BaseScore>
               <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0996.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-0609</Title>
         <Notes>
               <Note Audience="All" Ordinal="250" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges. CVSS Base Score: 1.7 CVSS V2 Vector: AV:N/AC:H/Au:M/C:N/I:N/A:P.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-0609</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>1.7</BaseScore>
               <Vector>AV:N/AC:H/Au:M/C:N/I:N/A:P</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-3157</Title>
         <Notes>
               <Note Audience="All" Ordinal="251" Title="Details" Type="Details">This is a vulnerability in  kernel-uek  in Oracle Linux. ** RESERVED **This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.  CVSS Base Score: 0 CVSS V2 Vector: AV:N/AC:N/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-3157</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-6</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:N/AC:N/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-3529.html</URL>
                  <ProductID>P-1309V-6</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2015-4819</Title>
         <Notes>
               <Note Audience="All" Ordinal="252" Title="Details" Type="Details">This is a vulnerability in  mariadb  in Oracle Linux. Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier,and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs. CVSS Base Score: 0 CVSS V2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Fix has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2015-4819</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>0</BaseScore>
               <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Fix">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>http://linux.oracle.com/errata/ELSA-2016-0534.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
</cvrf:cvrfdoc>
